VulncastBriefing archive

Daily Brief - 2026-09-04

· 4 vulnerabilities · 5 min listen

▶ Listen to this briefing

CVE-2026-70352

critical · CVSS 10 · Microsoft Azure AI Language

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

  • Privilege Escalation
  • cloud platform
  • artificial intelligence

CVE-2026-82302

high · CVSS 8.1 · Elastic Kibana

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • Incorrect Authorization
  • web application
  • dashboard

CVE-2026-85050

critical · CVSS 9.6 · Google Chrome

Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • Out Of Bounds Write
  • Remote Code Execution
  • web browser
  • mobile application

CVE-2026-8862

high · CVSS 7.5 · IBM Netezza

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.

  • Hardcoded Credentials
  • containerization