PULSE
FEED
ransomrhysida reclama a Law Offices of R. David Williams, P.A. · US · Professional Servicesransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcareransomrhysida reclama a Law Offices of R. David Williams, P.A. · US · Professional Servicesransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcare
← Todos los CVEs
CVE Watch21 jul 2026

CVE-2026-49316

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-networ

CVSS

4.6

Medio

EPSS

0.3%

p17

KEV

—

Exploit Today

5

0-100

Publicado: 29 may 2026 · Última mod.: 21 jul 2026 · CWE-440 · CWE-693 · CWE-754

EPSS · 30d
0.2%EPSS · 30 días0.3%
2026-09-012026-09-29
Descripción técnica

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection technique against a periodic WCM transmission, the attacker drives the WCM CAN controller's transmit error counter past the bus-off threshold, after which the WCM stops transmitting all messages, including the shutdown command. Peer ECUs do not interpret WCM silence as a security event and continue normal operation, allowing the motorcycle to be operated despite the immobilizer never having been unlocked. Specific protocol details have been withheld pending vendor remediation.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1002968.1 ALT
—
——0In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it.18h
CVE-2026-95330—
—
——0Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)21h
CVE-2026-1026748.2 ALT
—
——0Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level document that was permitted to open popups could therefore create a window with the Electron application's full origin instead of the restricted origin intended by the sandbox. Applications that deny such popups with setWindowOpenHandler are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.22h
CVE-2026-1026738.2 ALT
—
——0Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.23h
CVE-2026-97687—
—
——0urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.1d
CVE-2026-35191—
—
——0Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.19h