Threats Tagged 'cve-2026-88859'
View all threats tagged with 'cve-2026-88859'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-88859'
Click on any threat for detailed analysis and mitigation recommendations
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard… (CVE-2026-88859)CVE-2026-88859 0 A vulnerability in Evolution allows remote attackers to execute arbitrary JavaScript by sending a crafted HTML email with a spoofed vCard control. When the recipient clicks the control, Evolution's JavaScript handler assigns an attacker-controlled URL to an iframe, bypassing script execution restrictions in email content. This leads to potential arbitrary script execution in the mail-viewing context. The vulnerability requires user interaction and has a medium severity rating with a CVSS score of 5.4. Mitigation involves disabling JavaScript execution in HTML emails via Evolution preferences or gsettings. Join the discussion | GCVE Database | 09/10/2026, 12:31:20 UTC Added: 09/10/2026, 13:23:21 UTC |
CVE-2026-88859: Improper Neutralization of Encoded URI Schemes in a Web Page in Red Hat Red Hat Enterprise Linux 6CVE-2026-88859 0 A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content. Join the discussion | CVE Database V5 | 09/10/2026, 11:24:54 UTC Added: 09/10/2026, 11:37:54 UTC |
Showing 1 to 2 of 2 results