CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-87931 — A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral ...

·Source: NIST NVD

Updated:

Executive Summary

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any

Analysis

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way. CVSS Score: 9.6. Published: 2026-09-10T00:17:24.737.

Indicators of Compromise (1)

CVE (1)
CVE-2026-87931
Source Attribution

Originally published by NIST NVD on Sep 10, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-78159 — The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut...

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it p

CVE-2026-78159
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-78006 — The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut...

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attri

CVE-2026-78006
NIST NVD
MEDIUMVulnerability

Cylake Gets $245M to Build Cloud-Free Cybersecurity Platform

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cylake-gets-245m-to-build-cloud-free-cybersecurity-platform-image_small-1-a-32807.jpg" align=right hspace=4><b>Nir Zuk's Startup Targets Firms Unable to Send Sensitive Security Data to the Cloud</b><br>Cylake, led by Palo Alto Networks founder Nir Zuk, raised $245 million to build an on-premises cybersecurity system combining hard

Bank Info Security