在一群初创公司之后,科技巨头如微软、英伟达、思科、戴尔、IBM、甚至 OpenAI 等数十家公司和组织联署发表公开信,呼吁美国政府不要过早限制开放权重模型,认为此举会扼杀竞争或导致本土创新放缓。公开信称,开放权重模型能促进竞争,确保 AI 技术的好处能广泛共享,避免其掌握在少数人手中,而闭源模型并不意味着绝对安全。没有署名的知名 AI 公司包括了 Google、Anthropic 以及 xAI/SpaceX,其中 SpaceX CEO 马斯克通过社交媒体口头表达了对公开信的支持,而 Anthropic 明显是站在支持限制开放权重模型的一边,该公司正投入 4000 万美元游说特朗普政府加强监管 AI 模型。
A vulnerability classified as problematic has been found in Linux Kernel up to 7.1.3. This vulnerability affects unknown code of the component elan_i2c. Performing a manipulation of the argument x_traces/y_traces/width results in divide by zero.
This vulnerability is reported as CVE-2026-64275. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability described as very critical has been identified in Linux Kernel up to 7.1.3. This affects the function rmi_f3a_attention of the component synaptics-rmi4. Such manipulation of the argument gpio_count leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-64277. The attack needs to be performed locally. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as very critical has been reported in Linux Kernel up to 7.1.3. Affected by this issue is the function rmi_f30_map_gpios/rmi_f30_attention of the component synaptics-rmi4/F30 handler. This manipulation of the argument gpioled_count/keycodemax/keycode causes out-of-bounds read.
This vulnerability is registered as CVE-2026-64276. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls.
This vulnerability is cataloged as CVE-2026-17432. The attack may be launched remotely. Furthermore, there is an exploit available.
Applying a patch is advised to resolve this issue.
A vulnerability identified as critical has been detected in Linux Kernel up to 7.1.3. Affected is the function goodix_ts_read_input_report of the component Goodix Touchscreen Driver. The manipulation of the argument max_touch_num leads to out-of-bounds write.
This vulnerability is listed as CVE-2026-64274. The attack must be carried out locally. There is no available exploit.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.144/6.12.95/6.18.38/7.1.3. This impacts the function __mms114_read_reg of the component mms114. Executing a manipulation can lead to improper validation of array index.
This vulnerability is tracked as CVE-2026-64272. The attack is restricted to local execution. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 7.1.3. It has been rated as very critical. This affects the function tw_interrupt of the component Touchwindow Driver. Performing a manipulation of the argument data results in out-of-bounds write.
This vulnerability is identified as CVE-2026-64271. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Linux Kernel up to 6.6.144/6.12.95/6.18.38/7.1.3. It has been declared as critical. The impacted element is the function mms114_interrupt of the component mms114. Such manipulation of the argument packet_size leads to out-of-bounds write.
This vulnerability is referenced as CVE-2026-64270. The attack can only be performed from a local environment. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.18.38/7.1.3. It has been classified as problematic. The affected element is an unknown function of the component imx-lpi2c. This manipulation causes race condition.
The identification of this vulnerability is CVE-2026-64278. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 7.1.3 and classified as very critical. Impacted is the function iforce_process_packet of the component iforce. The manipulation results in out-of-bounds read.
This vulnerability was named CVE-2026-64273. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 7.1.3 and classified as critical. This issue affects the function rdma_write_sg of the component RDMA/rtrs-srv. The manipulation of the argument desc[0].len leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-64269. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability described as problematic has been identified in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials.
This vulnerability is known as CVE-2025-9577. Attacking locally is a requirement. Furthermore, an exploit is available.
A vulnerability described as problematic has been identified in PowerDNS DNSdist up to 1.9.11/2.0.2. This impacts an unknown function. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains.
This vulnerability is tracked as CVE-2026-0397. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, has been found in Cato Socket up to 24. Affected by this issue is some unknown functionality of the component Socket Web Interface. This manipulation causes os command injection.
This vulnerability is registered as CVE-2025-14213. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in OpenClaw up to 2026.3.12. It has been classified as critical. Impacted is an unknown function of the component Attachments Handler. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-32917. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.