PULSE
LIVE76signals / 24h
FEED
ransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Servicesransomdeadlock reclama a West African Resources ltd · AU · Energy & Utilitiesransomdeadlock reclama a Caspian One · AZ · Energy & Utilitiesransomsection9 reclama a *****.com.pt · PT · Educationransomsection9 reclama a ********.com.uy · UY · Agriculture and Food Productionransomsection9 reclama a ****.fr · FR · Retail & E-Commerceransomsection9 reclama a ********.com · US · Otherransomsection9 reclama a ******.com.se · SE · Healthcareransomsection9 reclama a ******.com · US · Technologyransomsection9 reclama a ****.com.mc · MC · Hospitalityransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Servicesransomdeadlock reclama a West African Resources ltd · AU · Energy & Utilitiesransomdeadlock reclama a Caspian One · AZ · Energy & Utilitiesransomsection9 reclama a *****.com.pt · PT · Educationransomsection9 reclama a ********.com.uy · UY · Agriculture and Food Productionransomsection9 reclama a ****.fr · FR · Retail & E-Commerceransomsection9 reclama a ********.com · US · Otherransomsection9 reclama a ******.com.se · SE · Healthcareransomsection9 reclama a ******.com · US · Technologyransomsection9 reclama a ****.com.mc · MC · Hospitality
← All CVEs
CVE WatchJul 24, 2026

CVE-2026-46452

Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application

CVSS

5.3

Medium

EPSS

0.3%

p25

KEV

Exploit Today

8

0-100

Published: Jul 24, 2026 · Last modified: Jul 24, 2026 · CWE-20

EPSS · 30d

Not enough EPSS history yet.

Technical description

Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-541209.9 CRI
49.7%
15Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.2d
CVE-2026-656048.2 HIG
21.2%
6Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.2d
CVE-2026-4766810.0 CRI
90.2%
27DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.3d
CVE-2026-167239.0 CRI
33.9%
10A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.3d
CVE-2026-166327.3 HIG
23.4%
7A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. This manipulation of the argument on_message causes improper input validation. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.3d
CVE-2026-130575.3 MED
17.8%
5An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally populated only by the trusted router during sharded search planning. Due to insufficient input validation, an authenticated client can supply these fields directly.3d