CVE-2026-92839 is a medium-severity vulnerability in Canva Desktop before v1.125.0. The vulnerability is caused by double decoding in the deeplink handler, which could allow a threat actor to load arbitrary same-origin content under the user's session. Defenders should prioritize verifying the vulnerability status of Canva Desktop installations and ensuring they are updated to a fixed version. This vulner [truncated]
CVE-2026-81546 is a high-severity vulnerability in the Affinity by Canva application, allowing arbitrary code execution via crafted Affinity documents due to inadequate bounds checking, leading to a stack-based buffer overflow. The vulnerability affects users who open Affinity documents from untrusted sources. Defenders should prioritize verifying and updating to version 3.3.0 or later, assessing exposure [truncated]