PatchSiren

Tencent CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Tencent CVE published 2026-09-20

CVE-2026-94111

CVE-2026-94111 debrief based on the supplied source corpus. The CVE record was published on 2026-09-20T12:17:06.787Z and has not been modified since then. The vulnerability affects Tencent BrowserSkill through version 0.3.0, allowing authentication bypass and potential content manipulation. Defenders should verify and mitigate this vulnerability, particularly in deployments using versions through 0.3.0. T [truncated]

CRITICAL Tencent CVE published 2026-09-15

CVE-2026-89040

CVE-2026-89040 is a critical vulnerability in Tencent Mass Service Engine in Cluster (MSEC) that allows a remote, unauthenticated attacker to gain root access by sending a crafted POST request. The vulnerability has a CVSS score of 9.3 and is considered critical. Defenders and administrators should assess exposure and prioritize remediation efforts. The vulnerability allows for potential remote code execu [truncated]

HIGH Tencent CVE published 2026-09-15

CVE-2026-91750

CVE-2026-91750 is a high-severity vulnerability in WeKnora before version 0.7.0, allowing authenticated attackers to bypass initial SSRF validation by supplying a public URL that redirects to internal network addresses, potentially granting access to internal services and cloud metadata. This vulnerability exists in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents fro [truncated]

HIGH Tencent CVE published 2026-09-02

CVE-2026-84809

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T17:18:05.150Z and has not been modified since then. Tencent AI-Infra-Guard's skill-scan component vulnerability allows attackers to distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import. Operators and administrators should review and updat [truncated]

CRITICAL Tencent CVE published 2026-08-10

CVE-2026-72565

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:28.973Z and has not been modified since then. CVE-2026-72565 is a critical SQL injection vulnerability in Tencent APIJSON through version 8.1.8. The vulnerability allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @ [truncated]

MEDIUM Tencent CVE published 2026-07-13

CVE-2026-15515

A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path. The attack must be carried out locally. The attack is considered to have high complexity. The exploitability is assessed as difficult. This vulnerability has been publicly disclosed.