CVE-2026-0274
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unaut
CVSS
9.1
Critical
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Jun 10, 2026 · Last modified: Jul 23, 2026 · CWE-1390
0.3%EPSS · 30 days0.3%
2026-08-092026-09-05
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-738199.8 CRI42.7%
——13The affected Ebyte
product's vendor configuration utility permits access to administrative
functions without verifying the operator's identity under certain
credential conditions. An unauthenticated attacker on the adjacent
network could modify critical settings or change access credentials,
potentially preventing legitimate administrators from managing the
device.6dCVE-2026-650988.1 HIG49.3%
——15NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.5dCVE-2026-680679.8 CRI23.9%
——7The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.5dCVE-2026-591355.5 MED24.5%
——7Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.21dCVE-2026-595547.5 HIG35.7%
——11Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.46dCVE-2026-507567.5 HIG41.3%
——12An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component47d