MITRE ATT&CK CVE list for this attack path. Use risk scores and timeline to decide what to patch first and what to track next.
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2026-50130 | Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3. | 8.8 | 0.22% | 2026-07-14 | 2026-07-16 |
| CVE-2026-48287 | CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed. | 7.4 | 0.14% | 2026-07-14 | 2026-07-16 |
| CVE-2026-48275 | Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | 8.6 | 0.16% | 2026-07-14 | 2026-07-16 |
| CVE-2026-53486 | The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/ | 9.1 | 0.59% | 2026-07-14 | 2026-07-15 |
| CVE-2026-48344 | Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. | 7.8 | 0.10% | 2026-07-14 | 2026-07-16 |
| CVE-2026-48340 | Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 7.8 | 0.17% | 2026-07-14 | 2026-07-16 |
| CVE-2026-48272 | Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. | 7.8 | 0.13% | 2026-07-14 | 2026-07-16 |
| CVE-2026-46644 | Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels contain at least one non-ASCII code point. Originally unequal domain names can be regarded as equal, which can lead to blacklist bypassing, inconsistent UR | 6.9 | 0.39% | 2026-07-14 | 2026-07-15 |
| CVE-2026-50526 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. | 7.0 | 0.16% | 2026-07-14 | 2026-07-15 |
| CVE-2026-48346 | Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | 7.9 | 0.19% | 2026-07-14 | 2026-07-16 |
| CVE-2026-47767 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0. | 8.3 | 0.39% | 2026-07-14 | 2026-07-16 |
| CVE-2026-45133 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4. | 8.2 | 0.69% | 2026-07-14 | 2026-07-15 |
| CVE-2026-58628 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally. | 7.8 | 0.19% | 2026-07-14 | 2026-07-17 |
| CVE-2026-58546 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 6.5 | 0.51% | 2026-07-14 | 2026-07-16 |
| CVE-2026-58543 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack. | 6.3 | 0.17% | 2026-07-14 | 2026-07-16 |
| CVE-2026-58535 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 6.5 | 0.89% | 2026-07-14 | 2026-07-14 |
| CVE-2026-58533 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 6.5 | 0.89% | 2026-07-14 | 2026-07-14 |
| CVE-2026-58531 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. | 7.5 | 0.50% | 2026-07-14 | 2026-07-15 |
| CVE-2026-58527 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 7.8 | 0.24% | 2026-07-14 | 2026-07-15 |
| CVE-2026-57982 | Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. | 6.5 | 0.95% | 2026-07-14 | 2026-07-16 |