Vulnerability Alerts
Critical and actively exploited vulnerabilities in the enterprise products our clients run — what happened, who is affected and what to do, checked against the official records.
Latest release roundups
-
BIG-IP APM OAuth vulnerability allows unauthenticated remote code execution (CVE-2026-94127)
BIG-IP APM configured as an OAuth Authorization Server is vulnerable to unauthenticated remote code execution. CISA lists CVE-2026-94127 as exploited in the KEV catalogue. Apply the engineering hotfixes for affected BIG-IP branches.
-
FortiPAM Chrome Extension improper authentication lets malicious sites proxy browser traffic (CVE-2026-84388)
Fortinet advisory FG-IR-26-168 covers CVE-2026-84388, an improper authentication weakness in the FortiPAM Chrome Extension. A malicious website could proxy a user's browser traffic through attacker-controlled servers. No fixed version or workaround has been published.
-
Check Point Quantum Security Management directory traversal and file upload allows unauthenticated script execution (CVE-2026-93616)
Check Point Quantum Security Management is affected by a critical directory traversal and file upload flaw (CVE-2026-93616) that lets unauthenticated attackers run arbitrary scripts. CISA KEV lists active exploitation. Apply vendor instructions in SK1000171.
-
VeloCloud Orchestrator On-Prem Improper Input Validation Allows Remote Access to Privileged Functionality (CVE-2026-93952)
CVE-2026-93952 is a critical improper input validation issue in on-premises VeloCloud Orchestrator. CISA KEV lists it as actively exploited. Fixed builds listed are 5.2.3.16 and 6.4.2.8; apply the relevant build or restrict network exposure.
-
IBM week 38, September 2026: MQ and Verify Access flaws lead 74 CVEs
IBM week 38 covers 74 CVEs: 6 critical, 33 high, 32 medium, 3 low. None is exploited or in CISA KEV. Prioritise MQ Appliance pre-auth CVE-2026-10747, then unauthenticated RCE in MQ and Verify Identity Access, Sterling File Gateway auth bypass, and authenticated MQ code-execution flaws.
-
Cisco week 38 2026: two exploited flaws lead 85 CVEs across ISE, email and firewalls
Cisco's week 38 2026 release covers 85 CVEs: 29 critical, 26 high, 29 medium and 1 low. Two are actively exploited and in CISA KEV: CVE-2026-76461 in Secure Email Gateway and CVE-2026-76460 in Identity Services Engine. Patch these first, then other internet-facing ISE, firewall and email issues.
-
IBM Sterling File Gateway authentication bypass via unvalidated SSO header (CVE-2026-75878)
IBM Sterling File Gateway 6.2.0.0 to 6.2.0.6_1, 6.2.1.0 to 6.2.1.2, and 6.2.2.0 to 6.2.2.1 has a critical authentication bypass via an unvalidated SSO header. A remote attacker can obtain a fully authenticated session. IBM has published an advisory.
-
IBM MQ for HPE NonStop heap buffer underflow lets authenticated attackers cause denial of service or execute code (CVE-2026-10858)
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 has a critical heap buffer underflow (CVE-2026-10858). An authenticated attacker can cause denial of service or potentially execute arbitrary code. IBM has published a fix; apply it.
-
IBM MQ Appliance protocol message heap buffer overflow allows pre-authentication denial of service or code execution (CVE-2026-10747)
IBM MQ Appliance has a critical pre-authentication heap buffer overflow in protocol message processing. A remote attacker can cause denial of service or potentially execute arbitrary code. IBM has a fix; no active exploitation is recorded.
-
Cisco ASA and FTD EIGRP denial of service lets adjacent attackers reload devices (CVE-2026-20222)
Cisco Secure Firewall ASA and FTD Software have a high-severity EIGRP denial-of-service vulnerability (CVSS 7.4). An unauthenticated adjacent attacker can cause repeated device reloads. Apply Cisco's fixed software and enable EIGRP authentication as mitigation.
-
Cisco ASA and FTD logging denial of service lets remote attackers exhaust CPU (CVE-2026-20154)
Unauthenticated remote attackers can cause high CPU and denial of service on Cisco ASA and FTD firewalls by flooding a device with TCP SYN packets. Apply Cisco's logging rate-limit workaround and monitor for fixed releases.
-
Cisco Secure Firewall Threat Defense TLS 1.3 denial of service (CVE-2026-20135)
Cisco Secure Firewall Threat Defense has a high-severity TLS 1.3 denial-of-service flaw. An unauthenticated remote attacker can crash the LINA process and reload a vulnerable device. Fixes are available; patch or temporarily disable TLS 1.3.
-
Cisco ASA and FTD IKEv2 certificate authentication denial of service (CVE-2026-20249)
Unauthenticated remote attackers can crash IKEv2 VPN services on affected Cisco ASA and FTD appliances by sending a crafted certificate during connection setup. Cisco has published a fix; no workaround is available.
-
Cisco Secure Firewall ASA and FTD DTLS denial of service allows unauthenticated remote attackers to reload affected devices (CVE-2026-20250)
Cisco Secure Firewall ASA and FTD software on Firepower 3100 and 4200 series has a network-reachable DTLS denial-of-service flaw. Unauthenticated attackers can send crafted DTLS traffic to reload the device. Cisco indicates a fix is available, and a workaround disables DTLS flow offload.
-
Cisco Secure Firewall sftunnel vulnerabilities allow denial of service and authentication bypass (CVE-2026-20295, CVE-2026-20323)
Cisco Secure Firewall Management Center and Threat Defense software have two high-severity sftunnel vulnerabilities: remote memory exhaustion denial of service (CVE-2026-20295) and adjacent authentication bypass to root (CVE-2026-20323). Fixes are available; no workarounds.
-
Cisco Identity Services Engine authentication bypass lets unauthenticated attackers access the web management interface (CVE-2026-76460)
Cisco Identity Services Engine has a critical API authentication bypass allowing unauthenticated remote access to the web management interface. CISA KEV and Cisco PSIRT confirm active exploitation. Apply Cisco's iACL mitigation, restrict exposure, and upgrade to a fixed software release.
-
Cisco Secure Firewall Management Center flaws allow root command execution, SQL injection and DoS (CVE-2026-20340 to CVE-2026-20344)
Cisco disclosed five Secure Firewall Management Center vulnerabilities: root command execution, SQL injection, arbitrary file download and an unauthenticated API denial-of-service. No workarounds exist. Review Cisco's advisory, restrict management access, and apply the fixed software.
-
Cisco Secure Firewall Management Center Java deserialization allows remote code execution as root (CVE-2026-20242)
Cisco Secure Firewall Management Center has a critical Java deserialization flaw in External Database Access. An unauthenticated attacker who controls a configured database host can run commands as root. Cisco has published fixes; disable External Database Access until you apply the fixed release.
-
Cisco ISE REST API authentication bypass allows unauthenticated administrative access (CVE-2026-76423)
Cisco ISE and ISE-PIC are affected by multiple vulnerabilities, including CVE-2026-76423, an unauthenticated REST API authentication bypass with CVSS 10. Fixes are available; apply Cisco's fixed software and restrict exposure.
-
Cisco Secure Firewall Management Center sftunnel arbitrary code execution lets authenticated attackers run commands as root (CVE-2026-20324)
Cisco Secure Firewall Management Center (FMC) sftunnel flaw allows an authenticated remote attacker to execute commands as root. Affected releases include 7.0.0 through 7.0.3 and 7.2.0. Cisco has a fix, but no workarounds.
-
Cisco Nexus Dashboard September 2026 hardening fixes missing authentication and injection flaws (CVE-2026-20326 and others)
Cisco Nexus Dashboard releases are affected by multiple critical missing authentication and injection flaws. Cisco's September 2026 security hardening release fixes them; no workaround is listed.
-
Oracle Critical Security Patch Update Advisory, September 2026: unauthenticated Fusion Middleware flaws lead 330 fixes
Oracle's September 2026 Critical Patch Update covers 330 CVEs: 69 critical, 234 high, 24 medium and 3 low. No CVEs are recorded as exploited or in CISA KEV. Unauthenticated Fusion Middleware flaws, several scored 10.0, warrant priority.
-
Cisco Identity Services Engine hardening release addresses multiple critical vulnerabilities (CVE-2026-20192 and others)
Cisco Identity Services Engine and ISE-PIC have received a hardening release for several critical vulnerabilities, some reachable over the network without credentials. Apply Cisco's September 2026 release; no workarounds are available.
-
Cisco Secure Firewall ASA, FTD and FMC hardening release fixes critical and high vulnerabilities (CVE-2026-20329 through CVE-2026-20336)
Cisco has released a hardening update for ASA, FTD and FMC software addressing eight critical and high-severity vulnerabilities. No workarounds exist; Cisco reports no known exploitation. Apply the vendor release.
-
Cisco Secure Firewall Management Center root command execution and privilege escalation (CVE-2026-76420, CVE-2026-76412, CVE-2026-76413)
Three vulnerabilities in Cisco Secure Firewall Management Center: unauthenticated root command execution via AJP when sftunnel is down, SSO admin token forgery, and authenticated privilege escalation to root. Fixes are available; see Cisco's advisory for fixed builds.
-
Cisco Identity Services Engine remote code execution vulnerabilities (CVE-2026-20307, CVE-2026-20176, CVE-2026-20211)
Three critical vulnerabilities in Cisco Identity Services Engine allow authenticated administrators to run commands on the underlying operating system. No workarounds exist; Cisco has released fixes. Restrict management access and apply the vendor update.
-
Cisco Identity Services Engine command injection allows authenticated attackers to gain root (CVE-2026-20305, CVE-2026-20306)
Two critical command injection flaws in Cisco Identity Services Engine and ISE-PIC allow an authenticated administrator to execute code as root. In single-node ISE deployments, an exploited node can become unavailable and block new network access. Cisco has released fixes; no workaround exists.
-
Check Point Quantum Security Management stack overflow allows unauthenticated remote code execution (CVE-2026-91843)
Check Point Quantum Security Management has a critical pre-authentication stack overflow in the login process. No fixed release or vendor workaround is listed yet, so restrict access to management and log servers and monitor for unusual activity.
-
Apple security updates, September 2026: four high-severity macOS flaws lead eight fixes
Apple's September 2026 security updates cover eight macOS CVEs: four high, four medium. None is listed in CISA KEV or marked exploited. The standout is a remote afpfs handling flaw that can cause kernel memory corruption; two local privilege escalation issues also need prompt patching.
-
Apple security updates, September 2026: nine CVEs led by network privacy and memory-handling flaws
Apple's September 2026 release covers 9 CVEs across iOS, iPadOS, macOS, tvOS, watchOS and visionOS. Three high, five medium, one low; none in CISA KEV or exploited. Patch iOS/iPadOS 26.6 first for the network-reachable fingerprinting flaw, then memory-handling fixes.
-
Apple security updates, September 2026: seven high-severity fixes across 34 CVEs
Apple's September 2026 updates address 34 CVEs across Safari, iOS, iPadOS, macOS, tvOS, visionOS and watchOS. No CVE is in CISA KEV. Start with the seven high-severity web-content and kernel issues, then the medium and low items.
-
Apple security updates, September 2026: two critical macOS kernel flaws lead 98 fixes
Apple's September 2026 security updates cover 98 CVEs: 2 critical, 34 high, 61 medium and 1 low. None is listed in CISA KEV or marked exploited. The two critical macOS kernel flaws are reachable over the network without credentials, so patch macOS first.
-
Apple security updates, September 2026: five critical core OS flaws lead 118 fixes
Apple's September 2026 update addresses 118 CVEs across iOS, iPadOS, macOS, tvOS, visionOS, watchOS and Safari. No in-scope CVE is exploited or in CISA KEV. Five critical and 28 high severity flaws, chiefly memory corruption and permission issues, call for prompt broad patching.
-
IBM MQ JNDI injection allows unauthenticated remote code execution (CVE-2026-12351)
IBM MQ in the 9.3.0.0, 9.4.0.0 and 10.0.0.0 release lines is vulnerable to unauthenticated remote code execution via unsafe JNDI lookup when the IVT application is deployed. CVSS 9.8 critical. Apply IBM's fix; confirm the correct build for your release.
-
Cisco Secure Email Gateway SQL injection enables unauthenticated remote command execution (CVE-2026-76461)
Cisco Secure Email Gateway's AsyncOS email parsing has a critical SQL injection flaw (CVE-2026-76461). A remote, unauthenticated attacker can send a crafted email to execute commands with root privileges. CISA KEV and Cisco PSIRT confirm active exploitation; upgrade to a fixed release.
-
Cisco Secure Email Gateway hardening release addresses critical and high-severity flaws (CVE-2026-76440 and others)
Cisco has issued a hardening release for Cisco Secure Email and Cisco Secure Email and Web Manager. Multiple flaws, four critical and one high, are reachable over the network without credentials. Cisco reports no known exploitation. No workarounds exist; apply the Cisco hardening release.
-
IBM vulnerabilities, week 37 of 2026: two high-severity Db2 flaws and five WebSphere CVEs
IBM's week 37 2026 release covers eight CVEs across Db2 and WebSphere Application Server: two high and six medium. None is exploited or in CISA KEV. Patch Db2 first, then move WebSphere to 9.0.5.29 or 8.5.5.31.
-
Palo Alto Networks week 37 2026: PAN-OS XML buffer overflow leads nine fixes
Palo Alto Networks published 9 CVEs for 7–13 September 2026: 1 high, 5 medium, 3 low. None is in CISA KEV or reported exploited. CVE-2026-0310, an unauthenticated PAN-OS XML buffer overflow, can cause DoS or root code execution. Patch PAN-OS/Prisma Access first, then agents and Checkov.
-
Fortinet week 37 2026: critical FortiMonitorOnSight authentication bypass leads 10 CVEs
Fortinet's week 37 2026 release covers 10 CVEs: one critical, two high, five medium and two low. The standout is CVE-2026-84390, an unauthenticated authentication bypass in FortiMonitorOnSight. No CVEs are listed as exploited or in CISA KEV, and no fixed versions are listed.
-
GitLab path traversal in repository commits API allows unauthenticated file read (CVE-2026-85706)
Unauthenticated path traversal in the GitLab CE/EE repository commits API can expose files from the server. Upgrade to a fixed release for your version line: 18.11.12, 19.0.9, 19.1.8, 19.2.6 or 19.3.2. CISA KEV lists active exploitation.
-
FortiMonitorOnSight JWT authentication bypass allows unauthenticated web portal access (CVE-2026-84390)
Fortinet FortiMonitorOnSight web portal has a critical JWT authentication bypass (CVE-2026-84390) in versions 7.2.0–7.2.2 and 7.2.4–7.2.7. No fixed version or workaround is listed; restrict network exposure and monitor access.
-
PAN-OS XML processing buffer overflow allows unauthenticated code execution or denial of service (CVE-2026-0310)
An unauthenticated attacker with network access to PAN-OS management or dataplane interfaces can crash VM-Series firewalls or gain root code execution on PA-Series. Fixed releases are available; no workaround exists.
-
Quantum Security Gateway and Management heap-based buffer overflow in VPN certificate ASN.1 decoding (CVE-2026-85103)
Check Point Quantum Security Gateway and Security Management are affected by a critical heap-based buffer overflow in VPN certificate ASN.1 decoding. An unauthenticated remote attacker could execute code. No fixed release is listed yet; restrict network exposure and monitor the vendor advisory.
-
Check Point Quantum Security Gateway improper certificate validation allows unauthenticated code execution (CVE-2026-85102)
Check Point Quantum Security Gateway has a critical certificate validation flaw (CVE-2026-85102) that lets unauthenticated attackers run code over the network. CISA KEV lists it as actively exploited. Apply Check Point's SK1000117 mitigation immediately.
-
FortiOS and FortiProxy ZTNA portal improper certificate validation allows man-in-the-middle (CVE-2026-84393)
FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6 are affected by an improper certificate validation flaw in the Agentless ZTNA portal that may allow a remote unauthenticated attacker to perform a man-in-the-middle attack. No fixed release is listed yet.
-
ScreenConnect client guest-to-host file execution allows unauthorized code execution (CVE-2026-84869)
ScreenConnect clients before 26.6.5 are affected by a critical guest-to-host file execution vulnerability rated 9.9. CISA lists it as exploited. Update clients to 26.6.5.9742; ScreenConnect servers are not impacted.
-
Skype for Business Server remote code execution lets unauthenticated attackers run code (CVE-2026-66302)
Critical remote code execution in Skype for Business Server can be exploited over the network without authentication. Microsoft has published fixed builds for Skype for Business Server 2015 CU13, 2019 CU8 and Subscription Edition CU1.
-
Windows ALPC heap-based buffer overflow allows local privilege escalation (CVE-2026-85880)
CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC. An authenticated local attacker can exploit it to elevate privileges, and it is recorded as actively exploited by CISA KEV and Microsoft. Patched Windows builds are available.
-
Windows Update Stack link following lets local attackers elevate privileges (CVE-2026-81963)
Microsoft's Windows Update Stack has a high-severity local elevation-of-privilege flaw, listed as exploited by CISA KEV and Microsoft. Apply the September 2026 updates for Windows 11 and Windows Server 2025.
-
Windows Hyper-V stack-based buffer overflow enables remote code execution (CVE-2026-69910)
A stack-based buffer overflow in Windows Hyper-V can be exploited over the network without authentication or user interaction. Microsoft has released fixed builds; apply the September 2026 update.
-
Windows DHCP Server heap-based buffer overflow allows remote code execution (CVE-2026-69845)
CVE-2026-69845: Critical heap-based buffer overflow in Windows DHCP Server allows unauthenticated remote code execution without user interaction. Affects Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 and Windows 10 1607/1809. Apply Microsoft's September 2026 security updates.
-
Microsoft SQL Server Management Studio 22 injection lets unauthenticated attackers elevate privileges over the network (CVE-2026-65669)
Microsoft SQL Server Management Studio 22 before 22.8.2 has a critical injection flaw (CVSS 9.6) that allows an unauthenticated attacker to elevate privileges over the network with user interaction. Update to 22.8.2.
-
SAP Security Patch Day, September 2026: four critical vulnerabilities among 19 fixes
SAP Security Patch Day, September 2026 covers 19 CVEs: 4 critical, 4 high, 8 medium, 3 low. None exploited or in CISA KEV. Prioritise unauthenticated network-facing issues in SAP Extended Passport, NetWeaver Message Server and SAP CAP, then the remaining SAP Notes.
-
Microsoft SQL Server heap-based buffer overflow lets unauthenticated attackers execute code over a network (CVE-2026-67643)
A critical heap-based buffer overflow in Microsoft SQL Server allows unauthenticated attackers to execute code over a network. Fixed builds for SQL Server 2022 and 2025 CU and GDR branches are available now.
-
Microsoft Patch Tuesday, September 2026: two exploited Windows flaws lead 938 fixes
Microsoft’s September 2026 Patch Tuesday brings 938 CVEs, including two exploited Windows privilege-escalation flaws now in CISA KEV and 41 critical-rated issues. Prioritise the Windows ALPC and Update Stack fixes, then network-accessible SQL Server, Skype for Business and Windows component updates.
-
Microsoft SQL Server out-of-bounds read allows unauthenticated remote code execution (CVE-2026-67636)
Microsoft SQL Server 2019, 2022 and 2025 have a critical out-of-bounds read vulnerability. An unauthenticated attacker on the network can execute code; fixed builds are available.
-
Microsoft Office Outlook heap-based buffer overflow allows unauthenticated remote code execution (CVE-2026-78509)
Microsoft Office Outlook has a critical heap-based buffer overflow (CVE-2026-78509) allowing an unauthenticated attacker to execute code over a network. Apply Microsoft's September 2026 security updates for your Office release.
-
Microsoft SQL Server remote code execution lets unauthenticated attackers run code over the network (CVE-2026-67378)
A critical, unauthenticated remote code execution vulnerability affects Microsoft SQL Server 2019, 2022 and 2025. Apply Microsoft's September 2026 security update.
-
Windows Message Queuing use-after-free allows remote code execution (CVE-2026-69579)
Use-after-free in Windows Message Queuing lets an unauthenticated attacker execute code over the network (CVSS 9.8). Microsoft has published fixed builds in the September 2026 update. Apply them to affected Windows 10, Windows 11 and Windows Server systems.
-
Windows Netlogon stack-based buffer overflow lets unauthorised attackers execute code over a network (CVE-2026-72982)
Microsoft Windows Netlogon has a critical stack-based buffer overflow (CVE-2026-72982). An unauthorised attacker can execute code over a network without user interaction. The September 2026 security update provides fixed builds; apply them to affected Windows clients and servers.
-
Windows DHCP Server use-after-free vulnerability allows remote code execution (CVE-2026-72979)
Use-after-free in Windows DHCP Server allows an unauthenticated attacker to execute code over the network. Microsoft rates the flaw critical and has released fixed builds for affected Windows Server and Windows 10 versions. Apply the September 2026 updates promptly.
-
Microsoft Exchange Server missing authorization allows privilege elevation (CVE-2026-69641)
Microsoft Exchange Server has a missing authorization vulnerability (CVE-2026-69641). An authenticated attacker with high privileges can elevate over the network. Fixed security updates are available; apply the builds listed. CVSS 9.1.
-
Microsoft Exchange Server cross-site scripting allows spoofing over a network (CVE-2026-69356)
Microsoft Exchange Server 2016 CU23, 2019 CU14/CU15 and Subscription Edition RTM are affected by a cross-site scripting flaw with a CVSS 9.3 critical rating. Microsoft has released fixed builds in the September 2026 security updates.
-
Windows DNS Server use-after-free lets unauthenticated attackers execute code remotely (CVE-2026-69730)
Use-after-free in Windows DNS Server (CVE-2026-69730) allows network-based code execution without privileges or user interaction. Microsoft has released fixes for affected Windows 10 and Windows Server builds; apply the September 2026 update.
-
Windows Remote Desktop Services use-after-free allows unauthenticated remote code execution (CVE-2026-69525)
Windows Remote Desktop Services use-after-free (CVE-2026-69525) allows unauthorised remote code execution over the network. CVSS 9.8 Critical; Microsoft rates it Important. No exploitation or public disclosure is recorded. Apply the September 2026 security update.
-
Microsoft SQL Server heap-based buffer overflow allows unauthenticated remote code execution (CVE-2026-67631)
Microsoft SQL Server 2017 through 2025 is affected by a critical heap-based buffer overflow (CVE-2026-67631) that lets an unauthenticated attacker execute code over the network. Apply the September 2026 security update for your branch; fixed builds are listed below.
-
SAP Cloud Application Programming Model credential disclosure allows unauthenticated tenant data replacement or deletion (CVE-2026-76969)
SAP Cloud Application Programming Model (CAP) multitenant applications using @sap/cds-mtxs at or below 1.18.3, 2.7.6, 3.9.6 and 4.0.2 allow unauthenticated credential disclosure leading to tenant data replacement or deletion. Apply SAP Note 3798315.
-
SAP GUI for Java improper access control allows arbitrary command execution (CVE-2026-66768)
SAP GUI for Java (BC-FES-JAV 8.10) does not correctly enforce trust-level policy for functions invoked by a connected backend system, allowing a low-privileged attacker to run arbitrary commands on a victim's machine (CVSS 9). Apply SAP Note 3781729.
-
SAP NetWeaver Message Server missing authentication check lets unauthenticated attackers register components (CVE-2026-58240)
SAP NetWeaver Message Server KERNEL 9.16, 9.18, 9.19 and 9.20 lacks an authentication check. An unauthenticated attacker with network access could register an unauthorised component, with high impact on confidentiality, integrity and availability. Apply SAP Note 3759472.
-
SAP Extended Passport (EPP) memory corruption allows unauthenticated network compromise (CVE-2026-44756)
SAP Extended Passport (EPP) Processing in SAP kernel and Web Dispatcher lines has a critical memory corruption flaw (CVE-2026-44756). An unauthenticated attacker can send a crafted EPP header to cause undefined behaviour and process termination. Apply SAP Note 3747649.
-
Adobe Commerce and Magento Open Source template engine flaw enables unauthenticated code execution (CVE-2026-75650)
CISA KEV lists CVE-2026-75650 as exploited. Adobe Commerce, Adobe Commerce B2B and Magento Open Source have a template engine flaw allowing unauthenticated remote code execution. Apply the relevant hotfix and treat internet-facing instances as exposed.
-
IBM week 36 2026: six CVEs led by a high-severity Verify Identity Access disclosure
IBM's week 36 2026 set covers six CVEs: one high, five medium, with no CVEs in CISA KEV or confirmed exploitation. The priority is CVE-2026-13297, an unauthenticated information disclosure in Verify Identity Access and Security Verify Access. Patch it first, then Db2 Mirror and MQ Agent.
-
Cisco Week 36 of 2026: three critical IOS XR and NX-OS flaws lead 11 CVEs
Cisco week 36 of 2026 covers 11 CVEs: 3 critical, 6 high and 2 medium. No exploited or CISA KEV entries. Prioritise the NX-OS Silicon One remote code execution flaw and the IOS XR hardening release, then SIP and Secure Email fixes.
-
N-central pre-authentication remote code execution enables unauthorised code execution (CVE-2026-86218)
N-central before 2026.3.1.14 has a pre-authentication remote code execution vulnerability, CVE-2026-86218, rated CVSS 4.0 critical (10). CISA KEV lists it as actively exploited. Apply the fixed release N-central 2026.3.1.14 immediately.
-
MikroTik RouterOS SSH username flaw enables privilege escalation (CVE-2026-86060)
MikroTik RouterOS has a critical SSH login flaw, CVE-2026-86060, that allows an unauthenticated attacker to escalate privileges. CISA KEV lists the flaw as exploited. Upgrade to RouterOS 6.49.21, 7.23.4 or 7.24.2 and restrict SSH exposure.
-
IBM Verify Identity Access and Security Verify Access buffer overflow among multiple addressed issues (CVE-2026-11928)
IBM has addressed multiple vulnerabilities in Verify Identity Access and Security Verify Access, including a network-reachable buffer overflow scored CVSS 9.8. Apply IBM's update and review exposed instances.
-
Cisco IOS XR Software security hardening release addresses multiple internally discovered vulnerabilities (September 2026)
Cisco IOS XR Software is affected by multiple internally discovered vulnerabilities fixed in the September 2026 security hardening release. Two are critical and reachable without credentials; no workarounds exist. Apply the release and restrict exposure.
-
Cisco Nexus 3000 and 9000 Series Switches Silicon One HAL remote code execution (CVE-2026-20212)
Cisco NX-OS for Nexus 3000/9000 exposes TCP ports 43210 and 43211 in the default L3 VRF, allowing unauthenticated remote code execution with root privileges. CVSS 9.8 critical. Apply Cisco's fix and use iACLs as a workaround.
-
SMA1000 Work Place pre-authentication SSRF exposes sensitive functionality (CVE-2026-83548)
SMA1000 has a pre-authentication SSRF in the Work Place interface (CVE-2026-83548). CVSS 3.1 score 10 critical; remote unauthenticated attackers can reach sensitive functionality. CISA KEV lists active exploitation. Apply the fixed builds listed below.
-
JFrog Artifactory authentication bypass can grant unauthenticated admin access (CVE-2026-82329)
JFrog Artifactory has an authentication weakness that, under default configuration, may let an unauthenticated network attacker gain administrative privileges. CISA records active exploitation. Fixed releases are 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20.
-
PaperCut MF/NG unsafe dynamic class loading may allow arbitrary code execution (CVE-2026-82078)
PaperCut MF/NG has an unsafe dynamic class loading flaw in database connection utilities. High-privileged attackers who can alter configuration may run arbitrary Java bytecode. CISA KEV and SSVC report active exploitation; fixed releases are available. Upgrade promptly.
-
Gitea diffpatch API remote code execution through Git hook installation (CVE-2026-60004)
Gitea before 1.27.1 allows unauthenticated remote code execution through the diffpatch API via Git hook installation. CISA KEV lists the vulnerability as exploited. Upgrade to Gitea 1.27.1.
-
Apple security updates, August 2026: high-severity Safari CSP bypass among five CVEs
Apple's August 2026 security updates cover five CVEs: one high, three medium, one low. None are exploited or in CISA KEV. Prioritise the high-severity Safari Content Security Policy bypass, then the network denial-of-service, then update iOS, iPadOS, Safari and related Apple systems.
-
Cisco vulnerabilities, week 34 of 2026: critical Splunk, Crosswork and Secure Workload fixes lead 125 CVEs
Cisco week 34 of 2026 covers 125 CVEs: 12 critical, 42 high, 66 medium and 5 low. No CVE is listed in CISA KEV or marked exploited. Prioritise Crosswork Planning, Secure Workload, Splunk Enterprise embedded reports and Splunk MCP Server, then move through the remaining high-severity Splunk items.
-
IBM AIX week 34 2026: 32 critical flaws include unauthenticated command execution
IBM's week 34 2026 release covers 144 AIX CVEs, some also affecting PowerVM VIOS: 32 critical, 79 high. No CVE is in CISA KEV or reported exploited. Unauthenticated command execution and memory-corruption flaws in AIX and VIOS should be patched first on exposed systems.
-
Splunk MCP Server app deserialization flaw lets admin users run OS commands (CVE-2026-76404)
Splunk MCP Server app versions 1.2 through before 1.2.1 contain a critical deserialization vulnerability (CVSS 9.1). An attacker with the admin Splunk role can execute arbitrary OS commands. Install version 1.2.1 to fix the issue.
-
Splunk Enterprise embedded reports improper access control lets unauthenticated users access data (CVE-2026-76312)
Splunk Enterprise 9.4, 10.0, 10.2 and 10.4 before the patched builds has improper access control in embedded reports. An unauthenticated user who can read the HTML source of an embedding page could reuse exposed session material to access data and affect integrity. Apply the fixed releases.
-
Splunk Enterprise embedded report access control lets unauthenticated users download dispatch archives (CVE-2026-76311)
Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, and 9.4.14 has an improper access control flaw in embedded report dispatch archives. An unauthenticated user with an embedded report token can download an archive and use exposed session material to access data and affect integrity. Upgrade now.
-
Splunk Enterprise embedded report access control flaw lets unauthenticated users take administrative actions (CVE-2026-76310)
Splunk Enterprise 9.4, 10.0, 10.2 and 10.4 before fixed builds have a critical access control flaw. An unauthenticated user with an embedded report token can recover session material and act with the report owner's privileges, including admin. Update to 9.4.14, 10.0.9, 10.2.6 or 10.4.2.
-
Oracle Critical Patch Update, August 2026: one exploited Identity Manager flaw in 390 fixes
Oracle's August 2026 Critical Patch Update covers 390 CVEs: 84 critical and 247 high. CVE-2025-61757 in Oracle Identity Manager is actively exploited and in CISA KEV. Apply that first, then unauthenticated OID and WebCenter flaws, then the wider update.
-
TrueConf Server isolated environment breakout enables unauthenticated remote code execution (CVE-2026-72530)
TrueConf Server before 5.3.9 (5.3.x), before 5.4.9 (5.4.x) and before 5.5.5 (5.5.x) can be exploited over TCP 4307 by an unauthenticated attacker to escape an isolated environment and run code on the host. CISA KEV lists active exploitation. Apply the fixed builds.
-
TrueConf Server missing authentication allows unauthenticated script execution via port 4307/TCP (CVE-2026-72529)
CVE-2026-72529 is a critical (CVSS 9.3) missing authentication flaw in TrueConf Server. A remote attacker with network access to port 4307/TCP can execute an arbitrary script without credentials. CISA KEV records active exploitation; fixed releases are 5.3.9, 5.4.9 and 5.5.5.
-
Cisco Secure Workload August 2026 hardening release fixes improper authentication and access control (CVE-2026-20317 et al.)
Cisco's August 2026 Secure Workload hardening release fixes several internally discovered improper authentication and access control vulnerabilities. Cisco reports no public disclosure or malicious use. Apply the hardening release; no workarounds exist.
-
Cisco Crosswork Planning hardening release fixes SQL injection, missing authentication and more (CVE-2026-20030, CVE-2026-20357)
Cisco's August 2026 hardening release for Crosswork Planning fixes four critical, network-reachable flaws including SQL injection and missing authentication. No workarounds; Cisco reports no malicious use. Apply the hardening release.
-
IBM AIX and PowerVM VIOS critical vulnerabilities allow remote code execution (CVE-2026-17040, CVE-2026-15068, and eight more)
IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 have critical vulnerabilities allowing remote unauthenticated code execution, command injection and privilege escalation. IBM has fixed VIOS builds 4.1.0.50, 4.1.1.30 and 4.1.2.20; apply them promptly.
-
NetScaler ADC and NetScaler Gateway authentication bypass (CVE-2026-19490)
NetScaler ADC and Gateway are affected by a critical network-reachable authentication bypass, and CISA records active exploitation. Fixed builds are listed for some ADC editions; confirm your branch and restrict exposure now.
-
MLflow webhook test SSRF allows unauthenticated access to internal and cloud metadata (CVE-2026-64849)
MLflow before 3.15.0 has an unauthenticated server-side request forgery (SSRF) flaw in webhook testing. Attackers can use redirects to reach internal or cloud metadata services and read response data. CISA KEV records active exploitation. Upgrade to MLflow 3.15.0.
-
Microsoft Patch Tuesday, August 2026: two exploited flaws headline 375 CVEs
Microsoft Patch Tuesday, August 2026 covers 375 CVEs — 5 critical, 246 high, 124 medium. Two are exploited and in CISA KEV: a SharePoint Server RCE and a Windows AFD WinSock elevation of privilege. Patch those first, then exposed network-facing critical services.
-
Adobe Commerce incorrect authorization allows unauthenticated privilege escalation (CVE-2026-71362)
Adobe Commerce, Adobe Commerce B2B and Magento Open Source are affected by an incorrect authorization vulnerability (CVE-2026-71362) with a critical CVSS 9.1 score. CISA lists it as actively exploited. Apply the August 2026 security updates before 27 September 2026.
-
WSO2 JWT authentication bypass allows unauthenticated account takeover (CVE-2026-5430)
Several WSO2 API products accept JWTs signed with unapproved algorithms, allowing unauthenticated attackers to take over accounts. CISA KEV lists CVE-2026-5430 as actively exploited with a 2026-09-27 due date; patched builds are available.
No advisory matches these filters.