Skip to content
Threat Feed

September 2026 (30)

high advisory

Arbitrary File Write in oras-go via Symlink-Chain Bypass

The oras-go library contains a path traversal vulnerability in its OCI layer extraction logic that allows attackers to overwrite arbitrary files on the host filesystem via a symlink-chain bypass.

oras-go arbitrary-file-write path-traversal library-vulnerability supply-chain
2t
medium threat

AsyncHttpClient Unbounded Decompression Denial of Service

AsyncHttpClient is vulnerable to a decompression bomb denial of service attack due to unbounded automatic HTTP/1.1 response decompression, potentially leading to heap exhaustion.

exploited async-http-client +1 denial-of-service vulnerability java
1c
medium advisory

Certified Address Hijacking in libp2p PeerStore

The @libp2p/peer-store package incorrectly validates PeerRecord envelopes, allowing attackers to inject fraudulent, certified addresses into the records of victim peers.

@libp2p/peer-store supply-chain peer-to-peer networking cve-2026-86039
2t 1c
medium advisory

Fulgur HTML-to-PDF Denial of Service via Resource Exhaustion

Fulgur versions prior to 0.26.0 are vulnerable to a denial-of-service attack where an attacker-supplied HTML payload causes CPU and memory exhaustion by forcing the rendering of thousands of blank PDF pages.

fulgur +1 denial-of-service vulnerability rust
1t
critical advisory

Account Takeover Vulnerability in Vendure External Authentication

Vendure is vulnerable to account takeover due to the ExternalAuthenticationService allowing unverified external identity linking to existing user accounts via email matching.

Vendure account-takeover authentication-bypass web-application
2t 1c
critical advisory

SQL Injection in Marten LINQ Provider via Unescaped Literals

Marten versions 7.0.0 through 9.12.0 contain critical SQL injection vulnerabilities in the LINQ provider and tenant-management internals, allowing attackers to perform unauthorized data access, multi-tenant bypass, and data modification via crafted dictionary keys or tenant IDs.

Marten sql-injection cve-2026-75513 dotnet database-security
2t 1c
critical threat

Critical Vulnerabilities in Cisco Identity Services Engine and ISE-PIC

Multiple vulnerabilities, including one actively exploited in the wild (CVE-2026-76460), allow unauthenticated attackers to bypass authentication and gain administrative control over Cisco ISE and ISE-PIC deployments.

exploited Identity Services Engine +1 vulnerability cisco identity-management authentication-bypass
3t 2c
critical advisory

Unauthenticated Administrative Account Creation in UVdesk Community Skeleton

A vulnerability in UVdesk Community Skeleton versions through 1.1.8 allows unauthenticated attackers to reconfigure the database and create super administrator accounts via wizard endpoints.

PoC Community Skeleton web-application authentication-bypass critical-vulnerability
2t 1c updated
medium advisory

Authentication Bypass Vulnerability in Schneider Electric PowerChute Serial Shutdown

Schneider Electric PowerChute Serial Shutdown version 1.5 and prior contains an improper restriction of excessive authentication attempts vulnerability (CVE-2026-13348) that may allow unauthorized account access via brute-force.

PowerChute Serial Shutdown industrial-control-system authentication-bypass cve
1t 1c
high threat

Multiple Vulnerabilities in Bransys ELD Affecting Data Privacy

Bransys ELD versions for Android and iOS contain hard-coded credentials and cleartext transmission flaws, allowing unauthorized read access to real-time telemetry data.

exploited Bransys ELD +1 ics transportation data-privacy cve-2026-86520 cve-2026-86689 cve-2026-77960
1t
high advisory

Remote Code Execution in HortusFox-Web via Import/Export

HortusFox-Web versions prior to 6.1 are vulnerable to remote code execution allowing authenticated administrators to execute arbitrary OS commands via the Import/Export feature.

HortusFox-Web
1t 1c
high advisory

Unauthenticated Remote Code Execution in SolarWinds Access Rights Manager

CVE-2026-28326 is a critical remote code execution vulnerability in SolarWinds Access Rights Manager resulting from the use of a hardcoded static key, allowing unauthenticated attackers to execute arbitrary code.

Access Rights Manager vulnerability rce windows
1t 1c
high advisory

Path Traversal Vulnerability in RosarioSIS

Authenticated users can exploit improper filename validation in RosarioSIS versions prior to 12.9 to perform unauthorized file deletion via directory traversal.

RosarioSIS
1t 1c
high advisory

CVE-2026-89036 Argument Injection in Appwrite

Authenticated users can achieve remote code execution in Appwrite versions before 2.0.0 by exploiting an argument injection vulnerability via the providerRootDirectory parameter in GNU tar commands.

Appwrite vulnerability rce argument-injection
2t 1c
high advisory

Unauthenticated Insecure Deserialization in b2evolution CMS

b2evolution CMS versions 6.7.8 through 7.2.5 are vulnerable to insecure deserialization via improper validation of serialized objects containing negative integer array keys.

b2evolution CMS web-vulnerability deserialization rce
1r 2t 2c
low advisory

Improper Input Validation in Schneider Electric Modicon M340 Modules

An improper input validation vulnerability (CVE-2025-6625) in Schneider Electric Modicon M340 controllers and communication modules allows unauthenticated attackers to cause a denial-of-service via crafted FTP commands.

Modicon M340 +5 ics cve-2025-6625 denial-of-service schneider-electric
1t 1c
high advisory

Multiple Vulnerabilities in Schneider Electric NetBotz 5 750/755

Schneider Electric NetBotz 5 750 and 755 devices are affected by OS command injection and Hibernate SQL injection vulnerabilities, enabling unauthorized code execution and database manipulation.

NetBotz 5 750 +1 vulnerability ics ot cve-2026-13336 cve-2026-13337
2t 2c
critical advisory

Multiple Critical Vulnerabilities in Hitachi Energy FACTS Control Platform

Hitachi Energy FACTS Control Platform (FCP) units equipped with the GWS component are affected by multiple critical vulnerabilities, including path traversal and authentication bypass, potentially leading to unauthorized system access or modification.

FACTS Control Platform ics energy ot vulnerability
2t 5c
high advisory

Authentication Bypass Vulnerability in Mitsubishi Electric GX Works3

An incorrect implementation of the authentication algorithm (CVE-2026-15688) in Mitsubishi Electric GX Works3 and Motion Control Settings allows local attackers to bypass block password protections and manipulate control programs.

GX Works3 +1 industrial-control-systems cve authentication-bypass
1t 1c
medium advisory

Mitsubishi Electric CC-Link IE TSN Communication Protocol Vulnerability

A vulnerability in the Mitsubishi Electric CC-Link IE TSN Communication Protocol (CVE-2026-13584) allows network-adjacent attackers to disrupt control functions or tamper with data via specially crafted packets.

MELSEC MX Controller +27 ics ot vulnerability cve-2026-13584
1t 1c
low advisory

Denial of Service Vulnerability in roxmltree

The roxmltree library is vulnerable to a denial of service attack due to quadratic-time attribute and namespace validation during XML parsing, allowing attackers to cause excessive CPU consumption.

roxmltree
1t 1c
high advisory

Path Traversal Vulnerability in HUBzero CMS

Authenticated users can exploit a path traversal vulnerability in HUBzero CMS project file upload handlers to achieve arbitrary file writes, potentially leading to remote code execution.

HUBzero CMS vulnerability cve-2026-92970 path-traversal web-application session-fixation authentication
2t 1c
low advisory

Denial of Service Vulnerability in InternLM LMDeploy

InternLM LMDeploy version 0.17.0 and earlier is vulnerable to a denial-of-service attack due to improper session management in DistServe mode, allowing unauthenticated attackers to cause an out-of-memory failure on the prefill worker.

LMDeploy
1t 1c
high advisory

Path Traversal in admin3 Upload Handler

The admin3 application through version 3.0.0 is vulnerable to path traversal, allowing authenticated attackers on Windows to overwrite arbitrary files via malicious filenames in the upload handler.

admin3 path-traversal web-vulnerability windows cve-2026-92919
1r 3t 1c
critical advisory

GNU telnetd Buffer Overflow Vulnerability (CVE-2026-32746)

A critical buffer overflow vulnerability exists in GNU telnetd (CVE-2026-32746), potentially allowing remote code execution on affected Linux systems.

inetutils-telnetd cve-2026-32746 telnetd buffer-overflow linux
3r 2t 1c updated
low advisory

BIND 9 Named Denial of Service via Crafted DoH Requests

A vulnerability in BIND 9 allows remote attackers to cause the 'named' process to abort by sending a crafted DNS-over-HTTPS request with an invalid SIG(0) record followed by premature connection closure.

1c updated
high threat

China-Aligned FamousSparrow Deploys SparroWocky Backdoor in Latin America

The state-sponsored threat actor FamousSparrow is deploying the new modular SparroWocky C++ backdoor against government entities in Latin America using advanced anti-analysis techniques.

Salt Typhoon +3 cyber-espionage backdoor windows latam state-sponsored
1r 4t 1i
high advisory

Unauthenticated Information Disclosure in Grav CMS Clockwork Profiler

Grav CMS versions 1.7.0-1.7.53.2 and 2.0.0-2.0.21 suffer from an unauthenticated information disclosure vulnerability in the Clockwork profiler endpoint when the debugger is enabled.

1c
critical advisory

WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding

WWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.

AVideo +7 credential-access web-application authentication-bypass web-application-vulnerability path-traversal reconnaissance web-vulnerability csrf +13
7r 15t 1c updated
high advisory

Authentication Bypass in AVideo LoginControl via PGP Verification

An authentication bypass vulnerability in AVideo LoginControl allows attackers with a victim's password to circumvent PGP two-factor authentication by exploiting loose equality checks.

LoginControl
1r 1t 1c