September 2026 (30)
SSRF Vulnerability in Nango via Configuration Interpolation
1 TTP 1 CVENango versions through 0.70.4 are vulnerable to Server-Side Request Forgery due to improper validation of user-supplied configuration values in token and proxy URL templates.
Authorization Bypass in cc-connect via Interactive Card Callbacks
2 TTPs 1 CVEThe cc-connect application through version 1.5.0 contains an authorization bypass vulnerability in the onCardAction handler, allowing unprivileged users to execute unauthorized agent commands.
Authentication Bypass Vulnerability in GoAdmin
1 TTP 1 CVEGoAdmin versions through 1.2.26 are vulnerable to an authentication bypass where attackers can manipulate URL pathing to access restricted administrative endpoints.
Authentication Bypass in OpenNHP via Attestation Verification Manipulation
1 TTP 1 CVEOpenNHP versions up to 1.0.2 contain an authentication bypass vulnerability allowing attackers to force the use of a fallback attestation verifier via malicious input.
Path Traversal in Uber Kraken
1 rule 1 TTP 1 CVEUber Kraken versions 0.1.29 and earlier contain a path traversal vulnerability in the /tags/{tag} endpoint, allowing unauthenticated attackers to read arbitrary files from the filesystem.
Insufficient Validation in Coze Studio Workflow SQL Nodes
1 TTP 1 CVECoze Studio versions up to 0.5.1 contain an input validation vulnerability in workflow SQL customization nodes allowing authenticated attackers to bypass workspace isolation and execute unauthorized SQL queries.
Remote Code Execution and DoS in Angel via Kryo Deserialization
1 CVEAngel versions 3.3.0 and earlier are vulnerable to a deserialization flaw allowing unauthenticated remote attackers to trigger arbitrary code execution or denial-of-service via the master RPC endpoint.
Cross-Site Scripting via @refinedev/inferencer
1 TTP 1 CVEThe @refinedev/inferencer package versions through 7.0.0 are vulnerable to an injection attack where malicious JSON property names are improperly escaped during JSX code generation, leading to arbitrary JavaScript execution in the developer's browser.
Authorization Bypass in Yeti RBAC API
1 rule 1 TTP 1 CVEYeti versions 2.11.0 and earlier contain an authorization vulnerability in the DELETE /api/v2/rbac/{id} endpoint that allows unauthorized users to delete access control relationships, causing permanent lockout of legitimate object owners.
Authorization Bypass in Chroma via Tenant Isolation Failure
1 TTP 1 CVEChroma versions 1.5.9 and earlier are vulnerable to an authorization bypass allowing authenticated users to access, modify, and delete cross-tenant data by manipulating collection identifiers.
KnowStreaming RBAC Bypass Vulnerability
1 rule 1 TTP 1 CVEKnowStreaming versions 3.4.1 and earlier contain an improper access control vulnerability in REST API endpoints that allows authenticated users to perform unauthorized privilege escalation.
Prototype Pollution in Builder.io Gen2 SDKs
1 CVEBuilder.io Gen2 SDKs are vulnerable to prototype pollution in the deep-set helper function, allowing attackers to manipulate Object.prototype via unvalidated content block bindings.
Authentication Bypass in Trigger.dev via GitHub App Installation Binding
1 TTP 1 CVETrigger.dev versions before 4.6.0 contain an authentication bypass vulnerability allowing attackers to hijack GitHub App installations and gain unauthorized repository access by manipulating state cookies and installation identifiers.
Authorization Bypass in Leantime HTMX Plugin Installation
1 rule 1 CVELeantime versions prior to 3.9.6 contain an authorization bypass vulnerability in the HTMX plugin installation endpoint, allowing low-privileged authenticated users to deploy arbitrary plugins.
Authorization Bypass in Rundeck Project Archive Import
1 TTP 1 CVERundeck versions through 6.2.1 contain an authorization vulnerability in the project archive import endpoint allowing low-privileged users to overwrite sensitive project configuration files.
Authorization Bypass in Pelican Panel via Livewire State Manipulation
2 TTPs 1 CVEPelican Panel versions before 1.0.0-beta35 fail to enforce server-side write permissions, allowing attackers with read-only access to achieve arbitrary command execution via manipulated Livewire state updates.
Authorization Bypass in PatrowlManager API
1 TTP 1 CVEPatrowlManager versions up to 1.8.4 contain an authorization bypass vulnerability in events and alerts API endpoints, allowing authenticated attackers to modify or delete data across different user contexts.
Authorization Bypass in metasfresh DocumentAttachmentsRestController and CommentsRestController
1 TTPAuthenticated attackers can exploit improper record-level authorization checks in metasfresh ERP to perform unauthorized read, write, and delete operations on attachments and comments.
CVE-2026-92749 - Insecure Session Signing Secret Generation in SafeLine
2 TTPsSafeLine versions up to 9.4.1 are vulnerable to unauthorized administrative access due to the derivation of session-signing secrets using a weak time-seeded PRNG.
Path Traversal in BC Security Empire Upload Endpoint
1 TTPBC Security Empire versions prior to 6.7.1 are vulnerable to path traversal via the multipart filename parameter, allowing an authenticated operator to achieve arbitrary file write and potential code execution.
Cisco Security Updates - September 2026
33 CVEsRoundup of Cisco security advisories published in September 2026.
JWT Authentication Bypass in Feast
1 TTPFeast versions 0.66.0 and earlier fail to verify JWT signatures, allowing attackers to bypass RBAC and gain unauthorized read and write access.
SSRF Vulnerability in Quickwit SQS File Source
1 TTP 1 CVEQuickwit versions through 0.9.0 contain a Server-Side Request Forgery vulnerability allowing unauthenticated attackers to perform internal network scanning and service fingerprinting via the create-source API.
Nuclei Template Signature Verification Bypass
1 TTP 1 CVENuclei versions before 3.11.1 are vulnerable to template signature bypass due to reliance on file modification timestamps for cache validation, allowing attackers to inject malicious templates.
Arbitrary File Write in Scirius PCAP Filestore Upload
1 rule 1 TTP 1 CVEScirius versions 3.8.0 and earlier are vulnerable to an arbitrary file write attack via the PCAP filestore upload endpoint, allowing authenticated users to perform path traversal to write files to arbitrary locations.
IDOR Vulnerability in SIMAC MyPHR
2 TTPs 1 CVESIMAC MyPHR version 1.1 contains an IDOR vulnerability allowing authenticated attackers to modify arbitrary employee records and hijack user accounts.
Unauthenticated Form Submission Exfiltration in TDuck
1 TTP 1 CVETDuck survey form through version 5.3 contains a vulnerability allowing authenticated attackers to attach unauthorized webhooks to arbitrary forms for data exfiltration.
BIND 9 Denial of Service via Malformed DNS64 Response
1 TTP 1 CVEA vulnerability in BIND 9 resolvers configured with DNS64 allows an authoritative server to cause a process crash through malformed responses, resulting in a denial of service.
Authentication Bypass in Kubero Notifications API
1 TTP 1 CVEKubero versions 3.1.1 and earlier contain an authentication bypass vulnerability in the notifications API, allowing unauthenticated attackers to exfiltrate webhook secrets and manipulate pipeline alerting configurations.
CVE-2026-92717 Authentication Bypass in Covenant
1 TTP 1 CVECovenant versions 0.6 and earlier contain an authentication bypass vulnerability allowing unauthenticated remote actors to gain full operator API access via the CovenantHub SignalR hub.