CISA issues update on CVE-2026-18497 in nothings stb TrueType library
stb TrueType library versions up to 1.26 face CVE-2026-18497 in stbtt_GetGlyphShape, which can cause DoS and possible heap data reads.
Decision Insights Threat Desk • August 23, 2026
stb TrueType library versions up to 1.26 face CVE-2026-18497 in stbtt_GetGlyphShape, which can cause DoS and possible heap data reads.
Decision Insights Threat Desk • August 23, 2026
Logto has multiple OIDC and SAML authentication flaws that can bypass MFA and account linking, replay SSO responses, and skip SAML condition checks.
Decision Insights Threat Desk • August 23, 2026
Pegatron tdeio64.sys contains an unprotected IOCTL dispatch routine enabling arbitrary kernel reads/writes and NT AUTHORITY\SYSTEM escalation.
Decision Insights Threat Desk • August 23, 2026
TCG TPM 2.0 reference code flaws include CVE-2026-6726 key credential leakage and CVE-2026-6727 RSA OAEP timing side-channel.
Decision Insights Threat Desk • August 23, 2026
Adalo database API flaws let authenticated users extract cross-app user records for V1 and V2 via CVE-2026-10706 and reused JWTs in CVE-2026-10708.
Decision Insights Threat Desk • August 23, 2026
HP Deskjet 2800 firmware TBP1CN2612AR has an authorization bypass in webserver APIs tracked as CVE-2026-13753.