CVE-2026-78860
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext
CVSS
7.8
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 5 oct 2026 · Última mod.: 6 oct 2026 · CWE-311 · CWE-347
Sin historial EPSS suficiente todavía.
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext
- mercusys.comhttp://mercusys.com
- threadpoolx.gitbook.iohttps://threadpoolx.gitbook.io/docs/cve/mercusys-ac12-v2-security-advisory/missing-firmware-encryption-and-secure-boot-mechanisms
- threadpoolx.gitbook.iohttps://threadpoolx.gitbook.io/docs/cve/mercusys-ac12-v2-security-advisory/missing-firmware-encryption-and-secure-boot-mechanisms
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-253027.1 ALT—
———Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed.7hCVE-2026-778057.9 ALT—
——0In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose certificate subject name matches a broad allow list of publisher name fragments, rather than verifying that the file is the specific executable shipped with that version of the product. A local threat actor with low privileges who replaces one of these helper executables with any other validly signed binary from an allow-listed publisher can cause the substituted binary to be executed by the application, including with Administrator privileges for the tools that request elevation, resulting in privilege escalation and execution of unintended code. Successful exploitation requires the user to launch the affected external tool and to approve the elevation prompt without noticing that it refers to a different executable.7hCVE-2026-1051792.7 BAJ3.9%
——1A weakness has been identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file Admin/add_user.php of the component Password Handler. Executing a manipulation of the argument Password can lead to missing encryption of sensitive data. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.7hCVE-2026-1051615.3 MED3.1%
——1A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer.7hCVE-2026-1051184.7 MED0.8%
——0OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.6hCVE-2026-71891—6.2%
——2In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted a public key built on a foreign ECCurve that merely shares BLS12-381's field characteristic. The prime-order subgroup check trusts a point's own curve to name its cofactor, since ECPoint.satisfiesOrder returns true outright when the curve's cofactor is one, so a point on a curve with a different equation and a cofactor forged to one passed keyValidate despite not being a G1 point at all. In BC's pairing implementation such a point contributes the identity in the target group, so an aggregate signature verified against a set of public keys including it is accepted even though it contains no signature for that key and message pair, admitting a phantom signer. keyValidate now first confirms that the point's curve carries exactly the canonical G1 field, equation, order and cofactor before any subgroup check. The issue is reachable only where an application constructs an ECPoint on an explicit, non-canonical curve and accepts it as an authority-bearing key; the standard 48-byte compressed-point decoder always supplies the canonical curve and was never affected.7h