CVE-2026-8932 — CVE-2026-8932: incomplete mTLS config matching in conn reuse
195 L lib CVE-2026-8932: incomplete mTLS config matching in conn reuse 2026-06-24 7.7 8.20.0
VulnWatch اطلاعات آسیبپذیری، امتیازها، نسخههای درگیر، راهکارها و دستورهای منتشرشده را از منابعی که در سامانه معرفی شدهاند گردآوری و برای دسترسی سادهتر نمایش میدهد. VulnWatch تولیدکننده یا مرجع اصلی این اطلاعات نیست.
ممکن است اطلاعات یک منبع ناقص، با تأخیر، تغییرکرده یا متناسب با محیط شما نباشد. VulnWatch صحت، کاملبودن، بهروز بودن یا نتیجه اجرای اطلاعات و دستورهای استخراجشده را تضمین نمیکند و مسئولیتی در قبال تصمیم، تغییر، اختلال یا خسارتی که صرفاً بر پایه این اطلاعات انجام شود نمیپذیرد.
پیش از نصب بهروزرسانی، اجرای دستور، تغییر تنظیمات یا هر اقدام عملیاتی، منبع اصلی را باز کنید، نسخه و محصول خود را تطبیق دهید، از اطلاعات مهم نسخه پشتیبان داشته باشید و تغییر را در محیط مناسب ارزیابی کنید.
آسیبپذیریها را بر اساس دستهبندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.
195 L lib CVE-2026-8932: incomplete mTLS config matching in conn reuse 2026-06-24 7.7 8.20.0
USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update contained an incomplete fix for CVE-2026-8927. This update fixes the problem. Original advisory details: Andrew Nesbitt discovered that curl could reuse an existing live connection during STARTTLS-based connection upgrades even when the TLS configuration did not match. A remote attacker…
197 L lib C CVE-2026-9080: UAF after pause in socket callback 2026-06-24 8.13.0 8.20.0
198 L CVE-2026-9545: exposing HTTP/3 early data 2026-06-24 8.11.0 8.20.0
199 L lib CVE-2026-9546: sending old referer 2026-06-24 8.18.0 8.20.0
200 L lib CVE-2026-9547: SSH improper host validation 2026-06-24 7.69.0 8.20.0
Menu Docs Overview Project Project overview Bug Report Code of conduct Dependencies Donate FAQ Features Governance History Install Known Bugs Known Risks Logo TODO website Info Protocols Protocols overview CA Extract HTTP cookies HTTP/3 MQTT SSL certs SSL libs compared URL syntax WebSocket Releases Releases overview Changelog Release Table Version Numbering…
202 L CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop 2026-06-24 8.18.0 8.20.0
203 L lib CVE-2026-11564: Native CA trust persist 2026-06-24 8.17.0 8.20.0
204 L CVE-2026-11586: WS Auto-PONG memory exhaustion 2026-06-24 8.16.0 8.20.0
205 M lib CVE-2026-11856: cross-origin Digest auth state leak 2026-06-24 7.10.6 8.20.0
Menu Docs Overview Project Project overview Bug Report Code of conduct Dependencies Donate FAQ Features Governance History Install Known Bugs Known Risks Logo TODO website Info Protocols Protocols overview CA Extract HTTP cookies HTTP/3 MQTT SSL certs SSL libs compared URL syntax WebSocket Releases Releases overview Changelog Release Table Version Numbering…
Imunify360 Protects Against Drupal SQL Injection (CVE-2026-9082) May 26, 2026 TL;DR: If you run Imunify360 with the WAF (ModSecurity) enabled, you are already protected against Drupal SQL Injection... Read More
Important Vulnerability on Advanced Custom Fields Plugin for WordPress May 10, 2023 Important Vulnerability on Advanced Custom Fields Plugin for WordPress Read More
The Hidden Risk: When WP Automation Executes Malware as Root July 20, 2026 A single hidden file on one WordPress site can quietly take over an entire server, and the trigger... Read More Inside a Fake WordPress Plugin: How “WP Content Optimizer” Takes Over a Site April 15, 2026 Deep technical analysis of a fake WordPress plugin that creates hidden admin…
May 5, 2023 With Apple’s recent release of a security update for the iPhone, iPad, and Mac, it brings attention to... Read More
sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.