VulncastBriefing archive

Daily Brief - 2026-08-14

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-0297

Palo Alto Networks GlobalProtect

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).

  • Buffer Overflow
  • Remote Code Execution
  • vpn client

CVE-2026-12263

high · CVSS 8.8 · Zohocorp ManageEngine Password Manager Pro

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

  • Authentication Bypass
  • identity provider

CVE-2026-14676

high · CVSS 8.8 · PostgreSQL Global Development Group

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

  • Heap Buffer Overflow
  • Remote Code Execution
  • database server

CVE-2026-68454

high · CVSS 8.8 · Linux Foundation Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead of virt_to_phys(page_address(NULL)).

  • Privilege Escalation
  • linux kernel
  • virtualization

CVE-2026-73570

high · CVSS 8.9 · Zimbra Collaboration

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

  • Remote Code Execution
  • web application
  • snmp