CVE-2026-76191
Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execut
CVSS
8.2
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-94
Sin historial EPSS suficiente todavía.
Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-784638.8 ALT—
———Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.3hCVE-2026-779088.8 ALT—
———Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.3hCVE-2026-698067.0 ALT—
———Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.3hCVE-2026-546115.5 MED—
———InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.3hCVE-2026-866684.3 MED—
———A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.3hCVE-2026-867328.8 ALT—
———Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header.5h