September 2026 (30)
Arbitrary File Write in oras-go via Symlink-Chain Bypass
2 TTPsThe oras-go library contains a path traversal vulnerability in its OCI layer extraction logic that allows attackers to overwrite arbitrary files on the host filesystem via a symlink-chain bypass.
AsyncHttpClient Unbounded Decompression Denial of Service
1 CVEAsyncHttpClient is vulnerable to a decompression bomb denial of service attack due to unbounded automatic HTTP/1.1 response decompression, potentially leading to heap exhaustion.
Certified Address Hijacking in libp2p PeerStore
2 TTPs 1 CVEThe @libp2p/peer-store package incorrectly validates PeerRecord envelopes, allowing attackers to inject fraudulent, certified addresses into the records of victim peers.
Fulgur HTML-to-PDF Denial of Service via Resource Exhaustion
1 TTPFulgur versions prior to 0.26.0 are vulnerable to a denial-of-service attack where an attacker-supplied HTML payload causes CPU and memory exhaustion by forcing the rendering of thousands of blank PDF pages.
Account Takeover Vulnerability in Vendure External Authentication
2 TTPs 1 CVEVendure is vulnerable to account takeover due to the ExternalAuthenticationService allowing unverified external identity linking to existing user accounts via email matching.
SQL Injection in Marten LINQ Provider via Unescaped Literals
2 TTPs 1 CVEMarten versions 7.0.0 through 9.12.0 contain critical SQL injection vulnerabilities in the LINQ provider and tenant-management internals, allowing attackers to perform unauthorized data access, multi-tenant bypass, and data modification via crafted dictionary keys or tenant IDs.
Critical Vulnerabilities in Cisco Identity Services Engine and ISE-PIC
3 TTPs 2 CVEsMultiple vulnerabilities, including one actively exploited in the wild (CVE-2026-76460), allow unauthenticated attackers to bypass authentication and gain administrative control over Cisco ISE and ISE-PIC deployments.
Unauthenticated Administrative Account Creation in UVdesk Community Skeleton
2 TTPs 1 CVEA vulnerability in UVdesk Community Skeleton versions through 1.1.8 allows unauthenticated attackers to reconfigure the database and create super administrator accounts via wizard endpoints.
Authentication Bypass Vulnerability in Schneider Electric PowerChute Serial Shutdown
1 TTP 1 CVESchneider Electric PowerChute Serial Shutdown version 1.5 and prior contains an improper restriction of excessive authentication attempts vulnerability (CVE-2026-13348) that may allow unauthorized account access via brute-force.
Multiple Vulnerabilities in Bransys ELD Affecting Data Privacy
1 TTPBransys ELD versions for Android and iOS contain hard-coded credentials and cleartext transmission flaws, allowing unauthorized read access to real-time telemetry data.
Remote Code Execution in HortusFox-Web via Import/Export
1 TTP 1 CVEHortusFox-Web versions prior to 6.1 are vulnerable to remote code execution allowing authenticated administrators to execute arbitrary OS commands via the Import/Export feature.
Unauthenticated Remote Code Execution in SolarWinds Access Rights Manager
1 TTP 1 CVECVE-2026-28326 is a critical remote code execution vulnerability in SolarWinds Access Rights Manager resulting from the use of a hardcoded static key, allowing unauthenticated attackers to execute arbitrary code.
Path Traversal Vulnerability in RosarioSIS
1 TTP 1 CVEAuthenticated users can exploit improper filename validation in RosarioSIS versions prior to 12.9 to perform unauthorized file deletion via directory traversal.
CVE-2026-89036 Argument Injection in Appwrite
2 TTPs 1 CVEAuthenticated users can achieve remote code execution in Appwrite versions before 2.0.0 by exploiting an argument injection vulnerability via the providerRootDirectory parameter in GNU tar commands.
Unauthenticated Insecure Deserialization in b2evolution CMS
1 rule 2 TTPs 2 CVEsb2evolution CMS versions 6.7.8 through 7.2.5 are vulnerable to insecure deserialization via improper validation of serialized objects containing negative integer array keys.
Improper Input Validation in Schneider Electric Modicon M340 Modules
1 TTP 1 CVEAn improper input validation vulnerability (CVE-2025-6625) in Schneider Electric Modicon M340 controllers and communication modules allows unauthenticated attackers to cause a denial-of-service via crafted FTP commands.
Multiple Vulnerabilities in Schneider Electric NetBotz 5 750/755
2 TTPs 2 CVEsSchneider Electric NetBotz 5 750 and 755 devices are affected by OS command injection and Hibernate SQL injection vulnerabilities, enabling unauthorized code execution and database manipulation.
Multiple Critical Vulnerabilities in Hitachi Energy FACTS Control Platform
2 TTPs 5 CVEsHitachi Energy FACTS Control Platform (FCP) units equipped with the GWS component are affected by multiple critical vulnerabilities, including path traversal and authentication bypass, potentially leading to unauthorized system access or modification.
Authentication Bypass Vulnerability in Mitsubishi Electric GX Works3
1 TTP 1 CVEAn incorrect implementation of the authentication algorithm (CVE-2026-15688) in Mitsubishi Electric GX Works3 and Motion Control Settings allows local attackers to bypass block password protections and manipulate control programs.
Mitsubishi Electric CC-Link IE TSN Communication Protocol Vulnerability
1 TTP 1 CVEA vulnerability in the Mitsubishi Electric CC-Link IE TSN Communication Protocol (CVE-2026-13584) allows network-adjacent attackers to disrupt control functions or tamper with data via specially crafted packets.
Denial of Service Vulnerability in roxmltree
1 TTP 1 CVEThe roxmltree library is vulnerable to a denial of service attack due to quadratic-time attribute and namespace validation during XML parsing, allowing attackers to cause excessive CPU consumption.
Path Traversal Vulnerability in HUBzero CMS
2 TTPs 1 CVEAuthenticated users can exploit a path traversal vulnerability in HUBzero CMS project file upload handlers to achieve arbitrary file writes, potentially leading to remote code execution.
Denial of Service Vulnerability in InternLM LMDeploy
1 TTP 1 CVEInternLM LMDeploy version 0.17.0 and earlier is vulnerable to a denial-of-service attack due to improper session management in DistServe mode, allowing unauthenticated attackers to cause an out-of-memory failure on the prefill worker.
Path Traversal in admin3 Upload Handler
1 rule 3 TTPs 1 CVEThe admin3 application through version 3.0.0 is vulnerable to path traversal, allowing authenticated attackers on Windows to overwrite arbitrary files via malicious filenames in the upload handler.
GNU telnetd Buffer Overflow Vulnerability (CVE-2026-32746)
3 rules 2 TTPs 1 CVEA critical buffer overflow vulnerability exists in GNU telnetd (CVE-2026-32746), potentially allowing remote code execution on affected Linux systems.
BIND 9 Named Denial of Service via Crafted DoH Requests
1 CVEA vulnerability in BIND 9 allows remote attackers to cause the 'named' process to abort by sending a crafted DNS-over-HTTPS request with an invalid SIG(0) record followed by premature connection closure.
China-Aligned FamousSparrow Deploys SparroWocky Backdoor in Latin America
1 rule 4 TTPs 1 IOCThe state-sponsored threat actor FamousSparrow is deploying the new modular SparroWocky C++ backdoor against government entities in Latin America using advanced anti-analysis techniques.
Unauthenticated Information Disclosure in Grav CMS Clockwork Profiler
1 CVEGrav CMS versions 1.7.0-1.7.53.2 and 2.0.0-2.0.21 suffer from an unauthenticated information disclosure vulnerability in the Clockwork profiler endpoint when the debugger is enabled.
WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding
7 rules 15 TTPs 1 CVEWWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.
Authentication Bypass in AVideo LoginControl via PGP Verification
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability in AVideo LoginControl allows attackers with a victim's password to circumvent PGP two-factor authentication by exploiting loose equality checks.