CVE-2025-59698
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a
CVSS
6.8
Medium
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Published: Dec 2, 2025 · Last modified: Aug 26, 2026 · CWE-1270
0.3%EPSS · 30 days0.3%
2026-08-172026-09-14
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader.
- github.comhttps://github.com/advisories/GHSA-cjjw-86jv-h24c
- github.comhttps://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj
- www.entrust.comhttps://www.entrust.com/knowledgebase/hardware/understanding-nshield-security-advisory-september-2025
- www.entrust.comhttps://www.entrust.com/use-case/why-use-an-hsm
- github.comhttps://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-196365.3 MED5.1%
——2An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.27dCVE-2026-158314.3 MED12.7%
——4GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation.43dCVE-2026-545938.1 HIG29.1%
——9Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel issues JWTs carrying those same claims for lower-privilege operations such as WebSocket authentication and file-download links, an authenticated subuser could reuse one of those tokens (for example a WebSocket token obtained with only the websocket.connect permission) by replaying it against /upload/file to write arbitrary files to the same server, despite never being granted the file.create permission. This issue is fixed in Panel version 1.12.3 and Wings version 1.12.2.47dCVE-2026-494998.8 HIG35.2%
——11Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.48d