CVE-2025-59697
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physi
CVSS
7.2
High
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Dec 2, 2025 · Last modified: Aug 26, 2026 · CWE-269 · CWE-284
0.3%EPSS · 30 days0.3%
2026-08-132026-09-09
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration to start a root shell upon boot of the host OS. This is called F06.
- github.comhttps://github.com/advisories/GHSA-c2xm-xv33-q796
- github.comhttps://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj
- www.entrust.comhttps://www.entrust.com/knowledgebase/hardware/understanding-nshield-security-advisory-september-2025
- www.entrust.comhttps://www.entrust.com/use-case/why-use-an-hsm
- github.comhttps://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-879588.1 HIG—
———IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.13hCVE-2026-819418.8 HIG—
———IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.13hCVE-2026-797256.5 MED—
———IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.13hCVE-2026-757778.8 HIG—
———IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.13hCVE-2026-93276.3 MED—
———IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.14hCVE-2026-810469.4 CRI—
———Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.7h