PULSE
FEED
ransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomlamashtu reclama a GERLON · DE · Not Foundransomrhysida reclama a clicks digital GmbH Information · DE · Technologyransomrhysida reclama a Law Offices of R. David Williams, P.A. · US · Professional Servicesransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomlamashtu reclama a GERLON · DE · Not Foundransomrhysida reclama a clicks digital GmbH Information · DE · Technologyransomrhysida reclama a Law Offices of R. David Williams, P.A. · US · Professional Servicesransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Production
← All CVEs
CVE WatchSep 29, 2026

CVE-2026-101278

A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libo

CVSS

4.3

Medium

EPSS

0.1%

p2

KEV

—

Exploit Today

1

0-100

Published: Sep 29, 2026 · Last modified: Sep 29, 2026 · CWE-345 · CWE-346

EPSS · 30d

Not enough EPSS history yet.

Technical description

A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-137205.4 MED
—
———An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.7h
CVE-2026-1025886.5 MED
—
———A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.9h
CVE-2026-1028788.1 HIG
—
——0mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.21h
CVE-2026-1028318.1 HIG
—
——0JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is active and pasteCodeCellsWithoutOutput is disabled, a pasted code cell can mark HTML output as trusted, bypass output sanitization, and execute script in the authenticated JupyterLab origin without executing the cell. Markdown and raw cells are not affected because their output is sanitized. This issue is fixed in JupyterLab 4.5.11 and 4.6.4, Notebook 7.6.3, and JupyterLite Core 0.8.4.23h
CVE-2026-102711—
—
——0Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in `TXM_MODULE_PREAMBLE` is fully attacker-trusted: (1) a heap OOB **read** (`code_size` trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as `code_start + preamble_offset` with only a `!= 0` check, and the preamble `checksum` never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded).20h
CVE-2026-1026777.8 HIG
—
——0Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.1d