PULSE
EN VIVO76señales / 24h
FEED
ransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Servicesransomdeadlock reclama a West African Resources ltd · AU · Energy & Utilitiesransomdeadlock reclama a Caspian One · AZ · Energy & Utilitiesransomsection9 reclama a *****.com.pt · PT · Educationransomsection9 reclama a ********.com.uy · UY · Agriculture and Food Productionransomsection9 reclama a ****.fr · FR · Retail & E-Commerceransomsection9 reclama a ********.com · US · Otherransomsection9 reclama a ******.com.se · SE · Healthcareransomsection9 reclama a ******.com · US · Technologyransomsection9 reclama a ****.com.mc · MC · Hospitalityransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Servicesransomdeadlock reclama a West African Resources ltd · AU · Energy & Utilitiesransomdeadlock reclama a Caspian One · AZ · Energy & Utilitiesransomsection9 reclama a *****.com.pt · PT · Educationransomsection9 reclama a ********.com.uy · UY · Agriculture and Food Productionransomsection9 reclama a ****.fr · FR · Retail & E-Commerceransomsection9 reclama a ********.com · US · Otherransomsection9 reclama a ******.com.se · SE · Healthcareransomsection9 reclama a ******.com · US · Technologyransomsection9 reclama a ****.com.mc · MC · Hospitality
← Todos los CVEs
CVE Watch24 jul 2026

CVE-2026-12191

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/

CVSS

7.8

Alto

EPSS

0.1%

p3

KEV

Exploit Today

1

0-100

Publicado: 14 jun 2026 · Última mod.: 24 jul 2026 · CWE-20 · CWE-502

EPSS · 30d
0.1%EPSS · 30 días0.1%
2026-06-302026-07-25
Descripción técnica

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The vendor was contacted early about this disclosure but did not respond in any way.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-159628.8 ALT
0The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.22h
CVE-2026-464525.3 MED
25.1%
8Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.2d
CVE-2026-541209.9 CRÍ
49.7%
15Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.2d
CVE-2026-505179.9 CRÍ
66.4%
20Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.2d
CVE-2026-656048.2 ALT
21.2%
6Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.2d
CVE-2026-21655
6.1%
2Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.2d