PULSE
EN VIVO49señales / 24h
FEED
ransomstorm reclama a NCA Alarms · US · Otherransomstorm reclama a Nelson Manufacturing · US · Manufacturingransomstorm reclama a Southern Indiana Radiological Associates · US · Healthcareransomstorm reclama a Liberty Healthcare Corporation · US · Healthcareransomstorm reclama a EvansPetree · US · Otherransomhelix reclama a Venture Logistics · Transportationransomhelix reclama a Uber · US · Transportationransomhelix reclama a Highwoods Properties · US · Otherransomhelix reclama a Morguard · US · Not Foundransomhelix reclama a Westland Insurance · CA · Financial Servicesransomkrybit reclama a reflet2000.fr · FR · Otherransomkrybit reclama a www.actini.com · FR · Technologyransomkrybit reclama a www.ernat-bureau-etudes.fr · FR · Professional Servicesransomkrybit reclama a www.serengetiestates.co.za · ZA · Not Foundransomstorm reclama a NCA Alarms · US · Otherransomstorm reclama a Nelson Manufacturing · US · Manufacturingransomstorm reclama a Southern Indiana Radiological Associates · US · Healthcareransomstorm reclama a Liberty Healthcare Corporation · US · Healthcareransomstorm reclama a EvansPetree · US · Otherransomhelix reclama a Venture Logistics · Transportationransomhelix reclama a Uber · US · Transportationransomhelix reclama a Highwoods Properties · US · Otherransomhelix reclama a Morguard · US · Not Foundransomhelix reclama a Westland Insurance · CA · Financial Servicesransomkrybit reclama a reflet2000.fr · FR · Otherransomkrybit reclama a www.actini.com · FR · Technologyransomkrybit reclama a www.ernat-bureau-etudes.fr · FR · Professional Servicesransomkrybit reclama a www.serengetiestates.co.za · ZA · Not Found
← Todos los CVEs
CVE Watch7 ago 2026

CVE-2026-19189

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C

CVSS

7.8

Alto

EPSS

KEV

Exploit Today

0-100

Publicado: 7 ago 2026 · Última mod.: 7 ago 2026 · CWE-266 · CWE-269

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-191957.8 ALT
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.3h
CVE-2026-191937.8 ALT
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.3h
CVE-2026-191927.8 ALT
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used.3h
CVE-2026-191917.8 ALT
A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.3h
CVE-2026-191907.8 ALT
A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.4h
CVE-2026-480869.9 CRÍ
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating their own tenant's staff. No policy check enforces that "only an existing GLOBAL_ADMIN may grant GLOBAL_ADMIN", so the schema validation IS the authorization decision. After re-login, the JWT contains the new role and the formerly-tenant-scoped admin reaches every other tenant on the platform. On the hosted OpenReception service this is a scope-changed escalation: a single customer-side tenant administrator gains full platform-wide administrative control over all other tenants' configuration, users, staff records, operational metadata, and tenant lifecycle. Plaintext appointment contents remain subject to the E2E model unless chained with the staff-crypto poisoning issue (V-4) or with staff-passkey hijacking (V-1). On a single-tenant self-hosted deployment it is still a privilege escalation because TENANT_ADMIN should not be able to create new tenants, modify global configuration, or manage other administrators. The same handler also accepts updates targeted at any colleague within the tenant. A tenant admin can promote a separate collaborator account instead of themselves, leaving their own audit trail clean while the platform-wide breach happens through a separate identity. Version 1.0.2 fixes the issue.10h