CVE-2026-84666
Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration th
CVSS
5.4
Medio
EPSS
0.1%
p1
KEV
—
Exploit Today
0
0-100
Publicado: 2 sept 2026 · Última mod.: 4 sept 2026 · CWE-20 · CWE-494
0.1%EPSS · 30 días0.1%
2026-09-032026-09-07
Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-759998.4 ALT—
———ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.10hCVE-2026-759918.6 ALT—
———Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.10hCVE-2026-757263.5 BAJ—
———Adobe Experience Manager is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.10hCVE-2026-589417.8 ALT—
———In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.10hCVE-2026-552737.8 ALT—
———In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.11hCVE-2026-813925.5 MED—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.11h