Database/Control plane, storage & DevOps
Proxmox VE (libpve-storage-perl XXE): XML external entity injection in the Proxmox storage library, reachable
CVSS 9.8CVE-2026-51080Control plane, storage & DevOpscurated
Impact
XML external entity injection in the Proxmox storage library, reachable unauthenticated, leading to full compromise. Proxmox is increasingly used as the hypervisor for smaller GPU clouds where vSphere licensing does not pencil out.
Who can reach it
Unauthenticated network access to the affected Proxmox service.
What to do
Upgrade libpve-storage-perl past v9.1.1 / v8.3.7 via the Proxmox enterprise or no-subscription repo. Package update plus service restart; no VM downtime required.
References
Related entries
- Linux NFS server (nfsd, SECINFO_NO_NAME decode): A truncated SECINFO_NO_NAME operation leaves sin_exp uninitialized andCVE-2026-53398 · Linux NFS server (nfsd, SECINFO_NO_NAME decode)Critical
- Airflow FAB provider: Azure AD login accepted unsigned ID tokens, allowing login as AdminCVE-2026-59243 · Apache Airflow FAB auth manager (Azure AD OAuth ID token validation)Critical
- VMware vCenter (VMware Directory Service authentication bypass): An unauthenticated attacker with network accessCVE-2026-59309 · VMware vCenter (VMware Directory Service authentication bypass)Critical
- VMware vCenter (Syslog server directory traversal to RCE): Directory traversal in the vCenter syslog server lettingCVE-2026-59310 · VMware vCenter (Syslog server directory traversal to RCE)Critical
- Gitea: unauthenticated remote code execution via the diffpatch API installing Git hooksCVE-2026-60004 · Gitea (diffpatch API / Git hook installation)Critical
- JetBrains TeamCity: Deserialization in the agent polling protocolCVE-2026-63077 · JetBrains TeamCityCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.