CVE-2026-48033
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.
CVSS
—
Sin CVSS
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Publicado: 24 jul 2026 · Última mod.: 24 jul 2026 · CWE-693
0.3%EPSS · 30 días0.3%
2026-07-252026-07-26
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-663916.5 MED—
———Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket.
This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0.
Users are recommended to upgrade to version 10.10.0, which fixes the issue.4hCVE-2026-48037—17.6%
——5Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0.8hCVE-2026-658996.1 MED12.0%
——4DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy.7hCVE-2025-503308.8 ALT28.9%
——9An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.3dCVE-2025-503299.8 CRÍ43.8%
——13An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.3dCVE-2025-503278.8 ALT31.2%
——9An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism3d