PULSE
FEED
ransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Servicesransomemperador reclama a Amazon Informatica · BR · Technologyransomqilin reclama a New World Diagnostics · PH · Healthcareransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Servicesransomemperador reclama a Amazon Informatica · BR · Technologyransomqilin reclama a New World Diagnostics · PH · Healthcare
← All CVEs
CVE WatchSep 28, 2026

CVE-2026-49994

Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforc

CVSS

9.1

Critical

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Sep 28, 2026 · Last modified: Sep 28, 2026 · CWE-306 · CWE-862

EPSS · 30d

Not enough EPSS history yet.

Technical description

Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1011392.7 LOW
—
———A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.5h
CVE-2026-91154—
—
———Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.6h
CVE-2026-10107710.0 CRI
—
———A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.8h
CVE-2026-96538—
—
———WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.7h
CVE-2026-935395.4 MED
—
———A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside the namespaces they are authorized for.  This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.7h
CVE-2026-863356.3 MED
—
———Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.7h