Vulnerebility SEPTEMBER H  ECV  KB  KEV |  2026()  2025() |
Vulnerebility Calendar  Top Vulnerebility  List of Attack  CWE   Anti-Debug Tricks


2026  January  February  March  April  May  June  July  August  September  October  November  December


DATE

NAME

INFO

CATEGORY

SUBCATE

23.9.26

CVE-2026-87902 Unauthenticated path traversal in page-template resolution leading to conditional RCE

VULNEREBILITY

VULNEREBILITY

23.9.26

CVE-2026-91843

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

VULNEREBILITY

VULNEREBILITY

23.9.26

CVE-2026-93616

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

VULNEREBILITY

VULNEREBILITY

23.9.26

Bifrost AI Gateway

Bifrost is a high-performance AI gateway that unifies access to 23+ providers (OpenAI, Anthropic, AWS Bedrock, Google Vertex, and more) through a single OpenAI-compatible API. Deploy in seconds with zero configuration and get automatic failover, load balancing, semantic caching, and enterprise-grade features.

VULNEREBILITY

VULNEREBILITY

23.9.26

CVE-2026-90898

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image). transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.

VULNEREBILITY

VULNEREBILITY

22.9.26

CVE-2026-32996

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

VULNEREBILITY

VULNEREBILITY

22.9.26

CVE-2026-93952

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

VULNEREBILITY

VULNEREBILITY

22.9.26

CVE-2026-89775

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB.

VULNEREBILITY

VULNEREBILITY

22.9.26

CVE-2026-65660 Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY

22.9.26

CVE-2026-93485 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS VULNEREBILITY VULNEREBILITY

20.9.26

CVE-2026-28326 SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key. VULNEREBILITY VULNEREBILITY

19.9.26

CoSnitch See how meta-hacking got Microsoft Copilot to snitch on itself, exposing CoSnitch, a one-click flaw that silently exfiltrates data. VULNEREBILITY VULNEREBILITY

19.9.26

DirtyAH6 CVE-2026-80844 IPsec’s Authentication Header (AH) checks that packet data has not changed. Linux implements its IPv6 side in AH6, using the kernel’s XFRM code; before calculating or checking authentication data, AH6 changes some IPv6 fields into the expected form, including addresses in a routing header.

VULNEREBILITY

VULNEREBILITY

19.9.26

TUNderflow CVE-2026-81000 TUN and TAP are virtual network devices that move packets between the kernel and userspace through /dev/net/tun. Network devices built on top of other devices can pass down the receive headroom they need through ndo_set_rx_headroom(), and Open vSwitch can carry that value from another port to a TUN or TAP port.

VULNEREBILITY

VULNEREBILITY

19.9.26

PPPoEject CVE-2026-68121 PPPoE carries PPP sessions in Ethernet frames. On send, pppoe_sendmsg() builds an skb, copies in the payload, and asks the lower network device to create its hardware header before filling in the PPPoE header.

VULNEREBILITY

VULNEREBILITY

19.9.26

DiagSpill CVE-2026-74469 An SCTP association can have many peer transports, one for each peer address. sctp_diag reports SCTP socket and peer information through sock_diag, building a Netlink reply with one sockaddr_storage for each transport.

VULNEREBILITY

VULNEREBILITY

19.9.26

Click2Shell One month after XSS2Shell, we returned to WordPress Core looking for another pre-authentication RCE chain. This time there was no preauth XSS in Core. Instead we found a specially crafted preview link made WordPress install an attacker-selected catalog theme and load its PHP before activation.

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco IOS XR Software Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Email Gateway SQL Injection Vulnerability A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.This vulnerability is due to insufficient

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-85885 (CVSS score: 9.9) - A command injection vulnerability in Microsoft 365 Copilot that could allow an authorized attacker to elevate privileges over a network

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-85878 (CVSS score: 9.9) - An improper authorization in Azure Database for PostgreSQL that could allow an authorized attacker to elevate privileges over a network

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-87701 (CVSS score: 9.6) - An improper neutralization vulnerability in Azure Cosmos DB that could allow an authorized attacker to elevate privileges over a network

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-62721 (CVSS score: 7.8) - An insufficient granularity of access control in Windows User-Mode Power Service (UMPS) that could allow an authorized attacker to elevate privileges locally and gain SYSTEM privileges.

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-85921 (CVSS score: 8.2) - A double free vulnerability in Windows Secure Kernel Mode that could allow an authorized attacker to elevate privileges locally and gain Virtual Trust Level 1 (VTL1) privileges.

VULNEREBILITY

VULNEREBILITY

18.9.26

Plugin4Shell Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device.This vulnerability is due to missing authorization checks. An

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated, local attacker to either conduct an authentication bypass or disclose sensitive information.For more information about these vulnerabilities, see the Details

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device.For more information about these vulnerabilities,

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Authentication Bypass Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device.For more

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Authentication Bypass Vulnerability A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Authorization Bypass Vulnerabilities Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device.These vulnerabilities are

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Command Injection Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user. To exploi

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Cross-Site Scripting Vulnerability A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.This vulnerability exists because the web-based

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Information Disclosure Vulnerability A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.This vulnerability is due to

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Multiple Path Traversal Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to conduct path traversal attacks on an affected device.For more information about these vulnerabilities, see the

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine RADIUS Denial of Service Vulnerability A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.This vulnerability is due to improper handling of certain RADIUS requests. An attacker could

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Remote Code Execution Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct SQL or HQL injection attacks on an affected device.These vulnerabilities are due to insufficient validation of

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine SQL Injection Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks on an affected device.For more information about these vulnerabilities, see the Details section of this advisory.Cisco has

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Integrated Management Controller Argument Injection Vulnerabilities Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco IOS XR Software Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Nexus Dashboard Software Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Email Gateway SQL Injection Vulnerability A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.This vulnerability is due to insufficient

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart,

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated attacker to perform an sftunnel authentication bypass or sftunnel denial of service (DoS) attack.For more information

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.This vulnerability is due to insecure

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root.This vulnerability exists because a registered sftunnel peer has

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Static Credential Vulnerability A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.This vulnerability is due

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Vulnerabilities Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access and perform session forgery or session impersonation.For more information about these vulnerabilities, see the

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Vulnerabilities Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial of service (DoS) condition.For more information about these

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart.This vulnerability is due to incomplete validation of

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.This vulnerability is due to

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands.This vulnerability is due to improper validation of user-supplied input to the web-based management

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or 'mce-annotation tox-comment

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-81736

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-81563

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencin ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-80274

If a BIND resolver sends a query for a DNSSEC-signed authoritative zon ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-78301

A malformed zone may contain an NS or DNAME node above its origin, whi ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-77692

An attacker can cause `named` to abort by sending a crafted DNS-over-H ..

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-77119

A validly signed NSEC3 from an unrelated sibling zone may be accepted ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-76163

If BIND is loaded with a "`named.conf`" file that contains no global " ..

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-75029

In a query response, an attacker may send `named` multiple copies of a ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19941

An inapplicable NSEC record may be accepted by a `named` resolver as p ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19668

A BIND recursive resolver may experience excessive resource consumptio ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19667

If an attacker-controlled authoritative server can produce a negative ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19666

On a resolver configured to use ``dns64``, if an applicable answer fro ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19662

An attacker may be able to cause a `named` resolver to abort. The atta ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19033

For a secondary zone with transfers restricted by TSIG, `named` may st ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2025-40777

If a `named` caching resolver is configured with `serve-stale-enable` ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-89026

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens.

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2021-26855

Microsoft Exchange Server Remote Code Execution Vulnerability

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-90894

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials.

VULNEREBILITY

VULNEREBILITY

16.9.26

Pixel Update Bulletin—September 2026 The Pixel Update Bulletin contains details of security vulnerabilities and functional improvements affecting supported Pixel devices (Google devices). For Google devices, security patch levels of 2026-09-05 or later address all issues in this bulletin and all issues in the September 2026 Android Security Bulletin. To learn how to check a device's security patch level, see Check and update your Android version. VULNEREBILITY SOFTWARE PATCH REPORTS

16.9.26

CVE-2026-87886 Local privilege escalation due to insecure file permissions VULNEREBILITY VULNEREBILITY

16.9.26

CVE-2026-58704 In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. VULNEREBILITY VULNEREBILITY

16.9.26

CVE-2026-78159 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). VULNEREBILITY VULNEREBILITY

16.9.26

CVE-2026-78006 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. VULNEREBILITY VULNEREBILITY

16.9.26

CVE-2026-5430 The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. VULNEREBILITY VULNEREBILITY

15.9.26

CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability VULNEREBILITY VULNEREBILITY

15.9.26

CVE-2024-21762 A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests VULNEREBILITY VULNEREBILITY

15.9.26

CVE-2026-60004  Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. VULNEREBILITY VULNEREBILITY

13.9.26

CVE-2025-14733 An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-58231 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-58240 SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-85706 Path Traversal issue in repository commits API impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-87719 Insecure Deserialization issue in GraphQL subscription serializer impacts GitLab EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-88765 Buffer Overflow issue in Unicode conversion wrapper impacts GitLab EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-79708 Scheduled Pipeline Execution Policy test allows Developers to access protected CI/CD variables VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-78252 Cross-site Scripting issue in Markdown JSON table renderer impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-13210 Incorrect Authorization issue in CI/CD environment variable scope matcher impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2025-14871 Denial of Service issue in GraphQL complexity limiter impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-1168 Denial of Service issue in GraphQL complexity limiter impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2024-11222 Race Condition issue in Merge Request Pipelines impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-12910 Improper Authentication issue in SAML SSO sign-in restriction enforcement impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-82837 Insufficiently Protected Credentials issue in Workhorse senddata emitters impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-19619 Cross-site Scripting issue in Content Editor impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-86341 Access Control Implementation issue in protected environment approval rules impacts GitLab EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-86340 Authorization Bypass issue in protected environment approval rules impacts GitLab EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-7514 Missing Authorization issue in Generic Package Registry impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-8030 Improper Input Validation issue in Namespace Transfer impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-16794 Missing Authorization issue in Compliance Framework management impacts GitLab EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-3855 Improper Input Validation issue in Terraform State API impacts GitLab CE/EE VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-85706 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-73693 (CWE-78): a contact-sheet handler runs an attacker-chosen filename through a shell, so a file uploaded with a command in its name executes it. VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-73694 (CWE-78): a superuser settings test endpoint passes an operator-supplied argument straight to a shell and reflects the output, a direct command channel. VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-73698 (CWE-89): a delegated (non-superuser) administrator turns a control-panel field into raw SQL, including stacked statements. VULNEREBILITY VULNEREBILITY

12.9.26

CVE-2026-73699 (CWE-502): a permission blob deserialized on every page load instantiates arbitrary classes, which the SQL injection above weaponizes into a file write. VULNEREBILITY VULNEREBILITY

11.9.26

CVE-2026-82329 JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. VULNEREBILITY VULNEREBILITY

11.9.26

CVE-2026-42016 JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. VULNEREBILITY VULNEREBILITY

11.9.26

CVE-2026-42018

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. VULNEREBILITY VULNEREBILITY

11.9.26

CVE-2021-38003 Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. VULNEREBILITY VULNEREBILITY

10.9.26

CVE-2026-19490 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 VULNEREBILITY VULNEREBILITY

10.9.26

CVE-2026-85102 Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN VULNEREBILITY VULNEREBILITY

10.9.26

CVE-2026-85103 ASN.1 decoding heap overflow leading to a remote code execution VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-87491 Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-67401 Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026 VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2025-53521 When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-44756 A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. VULNEREBILITY VULNEREBILITY

9.9.26

SAP Security Patch Day - September 2026 On 8th of September 2026, SAP security patch day saw the release of 19 new security notes. There is 1 update to previously released security note. VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-55007 (CVSS score: 8.1) - A double free vulnerability in Microsoft Exchange Server that allows an unauthorized attacker to execute code over a network VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-80097 (CVSS score: 8.6) - An improper authentication vulnerability in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-69465 (CVSS score: 8.8) - A missing authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-65669 (CVSS score: 9.6) - An injection vulnerability in SQL Server allows an unauthorized attacker to elevate privileges over a network VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-69525 (CVSS score: 9.8) - A use-after-free vulnerability in Windows Remote Desktop Services that allows an unauthorized attacker to execute code over a network VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-69595 (CVSS score: 9.8) - A use-after-free vulnerability in Windows Services for NFS ONCRPC XDR Driver that allows an unauthorized attacker to execute code over a network VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-69730 (CVSS score: 9.8) - A use-after-free vulnerability in Windows DNS server that allows an unauthorized attacker to execute code over a network VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-69829 (CVSS score: 9.8) - A heap-based buffer overflow vulnerability in Windows Shell that allows an unauthorized attacker to execute code over a network VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-72979 (CVSS score: 9.8) - A use-after-free vulnerability in Windows DHCP Server that allows an unauthorized attacker to execute code over a network VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-85880 (CVSS score: 7.8) - A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-81963 (CVSS score: 7.8) - An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-81963 Microsoft Windows Link Following Vulnerability VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability VULNEREBILITY VULNEREBILITY

9.9.26

CVE-2026-86218 N-able N-central Static Code Injection Vulnerability VULNEREBILITY VULNEREBILITY

8.9.26

CVE-2026-79678 A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. VULNEREBILITY VULNEREBILITY

8.9.26

CVE-2026-76560 A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. VULNEREBILITY VULNEREBILITY

8.9.26

CVE-2026-76578 A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry VULNEREBILITY VULNEREBILITY

8.9.26

CVE-2026-75650 Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-13190 In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution. VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-13186 In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution. VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-13185 In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution. VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-13184 In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains. VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-13183 In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values. VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-13182 In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers. VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-13181 In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments. VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-86218 N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-18577 An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-86206 A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 VULNEREBILITY VULNEREBILITY

7.9.26

CVE-2026-86207 An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs VULNEREBILITY VULNEREBILITY

6.9.26

Vulnerabilities in Mikrotik RouterOS software During its own research, CERT Polska discovered vulnerabilities in MikroTik RouterOS software and participated in coordinating their disclosure. Details on how these vulnerabilities were found, along with other related information, are available in our separate article. VULNEREBILITY VULNEREBILITY

5.9.26

CVE-2026-59347 HGFS stack buffer-overflow vulnerability VULNEREBILITY VULNEREBILITY

5.9.26

CVE-2026-59346 VMXNET3 integer-overflow vulnerability VULNEREBILITY VULNEREBILITY

4.9.26

PostGREShell PostGREShell: The database powering much of the internet had an open door for 12 years VULNEREBILITY VULNEREBILITY

4.9.26

Cisco IOS XR Software Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. VULNEREBILITY VULNEREBILITY

4.9.26

CVE-2025-34158 Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner). VULNEREBILITY VULNEREBILITY

4.9.26

CVE-2026-32475 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. VULNEREBILITY VULNEREBILITY

4.9.26

CVE-2026-14894 CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 6.3.314) VULNEREBILITY VULNEREBILITY

4.9.26

CVE-2026-85046 Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. VULNEREBILITY VULNEREBILITY

2.9.26

CVE-2026-83548 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations. VULNEREBILITY VULNEREBILITY

2.9.26

CVE-2026-83549 Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. VULNEREBILITY VULNEREBILITY

2.9.26

CVE-2026-63219 Unauthenticated file upload via missing authorization on formatter upload endpoint VULNEREBILITY VULNEREBILITY

2.9.26

CVE-2021-31886 A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) VULNEREBILITY VULNEREBILITY

2.9.26

CVE-2026-9586 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. VULNEREBILITY VULNEREBILITY

2.9.26

CVE-2026-82329 JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. VULNEREBILITY VULNEREBILITY

1.9.26

CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. VULNEREBILITY VULNEREBILITY

1.9.26

CVE-2026-66066 aka KindaRails2Shell (CVSS score: 9.5) - A vulnerability that could allow an unauthenticated attacker to read arbitrary files from the server, leak Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens, ultimately leading to remote code execution. VULNEREBILITY VULNEREBILITY