CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "we
CVSS
7.1
Alto
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 13 abr 2026 · Última mod.: 13 ago 2026 · CWE-77 · CWE-88
0.3%EPSS · 30 días0.3%
2026-08-102026-09-06
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
- github.comhttps://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53
- github.comhttps://github.com/python/cpython/commit/a4d3edf3a6ecfde504d02126410d2a65a859b744
- github.comhttps://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca
- github.comhttps://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff
- github.comhttps://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4
- github.comhttps://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769
- github.comhttps://github.com/python/cpython/issues/148169
- github.comhttps://github.com/python/cpython/pull/148170
- mail.python.orghttps://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10117
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10140
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10141
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10711
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10745
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10774
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10949
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10950
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:11062
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:11077
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:11768
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-864278.8 ALT—
———LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping. Attackers can inject DEF and LINE arguments to read RRD files from unauthorized devices, or use newline injection to execute arbitrary rrdtool commands, bypassing per-device authorization checks.14hCVE-2026-862999.9 CRÍ—
——0A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.15hCVE-2026-862958.3 ALT—
——0A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.16hCVE-2026-84256——
——0An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject19hCVE-2026-796989.9 CRÍ—
——0A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.20hCVE-2026-796979.9 CRÍ—
——0A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.20h