Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-84329 Confused deputy in CredentialProvider
Chromium: CVE-2026-84334 Incorrect authorization in Chromoting
A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log.
.NET Elevation of Privilege Vulnerability
.NET Core Remote Code Execution Vulnerability
.NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
.NET Information Disclosure Vulnerability
.NET Denial of Service Vulnerability
.NET Information Disclosure Vulnerability
.NET Security Feature Bypass Vulnerability
.NET Framework Remote Code Execution Vulnerability
Golang Go could provide weaker than expected security, caused by the failure to correctly detect reserved device names in some cases by the IsLocal function in the filepath package. An attacker could exploit this vulnerability to report "COM1", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3 as local.
Insecure parsing of Windows paths with a \??\ prefix in path/filepath
Golang Go is vulnerable to a denial of service, caused by improper input validation. By sending a specially-crafted request using large buffers, a remote attacker could exploit this vulnerability to cause rand.Read to hang,a and results in a denial of service condition.
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
.NET Denial of Service Vulnerability
.NET Spoofing Vulnerability
.NET Denial of Service Vulnerability
.NET Remote Code Execution Vulnerability
.NET Framework Elevation of Privilege Vulnerability
.NET Framework Denial of Service Vulnerability
.NET Framework Remote Code Execution Vulnerability
.NET Security Feature Bypass Vulnerability
.NET Framework Denial of Service Vulnerability
.NET Denial of Service Vulnerability
.NET Tampering Vulnerability