CVE-2026-24078
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVSS
6.5
Medium
EPSS
0.1%
p1
KEV
—
Exploit Today
0
0-100
Published: Aug 4, 2026 · Last modified: Aug 6, 2026 · CWE-359
0.1%EPSS · 30 days0.2%
2026-08-052026-08-09
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-480487.5 HIG—
———XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17. As a workaround, the patch can be applied manually to the wiki page `XWiki.LiveTableResultsMacros`.5hCVE-2026-554964.3 MED28.8%
——9Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate email addresses and profile metadata for inactive or banned accounts. The service calls userClient.SearchActive, but despite its name that method filters only by email/nickname keyword and never adds a StatusActive predicate — while the sibling lookups GetActiveByID and GetActiveByDavAccount, defined a few lines above it, do. Search hits are serialized at RedactLevelUser, which includes the email address. This issue is fixed in version 4.17.0.11dCVE-2026-561717.1 HIG38.9%
——12Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.19dCVE-2026-506574.7 MED36.0%
——11Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.19dCVE-2026-623287.5 HIG29.8%
——99Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API endpoints. Attackers can enumerate paginated request logs and retrieve complete AI conversation histories including system prompts, user messages, assistant responses, tool calls, and user email addresses by querying the request-logs and request-details API routes which lack authentication middleware.26dCVE-2026-582977.1 HIG23.2%
——7Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.34d