ECV 2026  H  ECV  KB  KEV  WINDOWS UPDATE  |  2026  2025  2024  2023  2022| CWE

ECV 2026  January(17) February(28) March(23) April(29) May(14) June(29) July(26) August(31) September(44) October(4) November(0) December(0)

DATE

CVE

INFO

NAME

CWE

3.10.26

CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability: Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Zammad GmbH | Zammad CWE-384

3.10.26

CVE-2026-102490 Zammad GmbH Zammad Improper Privilege Management Vulnerability: Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Zammad GmbH | Zammad CWE-269

3.10.26

CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability: Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Fortinet | FortiMail CWE-22| CWE-158

3.10.26

CVE-2026-76504  Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability: Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Cisco | Catalyst SD-WAN Manager CWE-177