CVE-2026-9976
Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a craft
CVSS
8.8
High
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: May 28, 2026 · Last modified: Jul 21, 2026 · CWE-94
0.3%EPSS · 30 days0.3%
2026-08-112026-09-07
Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-784638.8 HIG—
———Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.6hCVE-2026-779088.8 HIG—
———Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.6hCVE-2026-761918.2 HIG—
———Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.6hCVE-2026-698067.0 HIG—
———Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.6hCVE-2026-546115.5 MED—
———InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.6hCVE-2026-866684.3 MED—
———A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.6h