CVE-2026-50510
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
CVSS
7.8
Alto
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 14 jul 2026 · Última mod.: 22 jul 2026 · CWE-641
0.2%EPSS · 30 días0.4%
2026-08-202026-09-17
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-202824.9 MED45.0%
——14A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain write access to the underlying operating system.
To exploit this vulnerability, the attacker must have valid administrative credentials.
Note: For CVE-2026-20282, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.2dCVE-2026-465817.5 ALT37.3%
——11In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.39dCVE-2026-271408.8 ALT49.9%
——15SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.8dCVE-2024-300636.7 MED61.8%
——19Windows Distributed File System (DFS) Remote Code Execution Vulnerability60d