CVE-2024-6858
In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capa
CVSS
6.5
Medio
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 4 jun 2026 · Última mod.: 22 jul 2026 · CWE-1287
0.1%EPSS · 30 días0.1%
2026-06-302026-07-26
In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-47738.1 ALT24.3%
——7Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass.
This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.6dCVE-2026-505247.5 ALT46.7%
——14Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.5dCVE-2026-450699.1 CRÍ14.8%
——4Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.13dCVE-2026-551245.5 MED30.8%
——9Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.12dCVE-2026-449359.9 CRÍ33.8%
——10Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.22dCVE-2026-442498.1 ALT43.9%
——13Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.5d