Skip to content
Threat Feed

September 2026 (30)

medium advisory

Octopus Deploy File Path Manipulation and Potential RCE

A vulnerability in Octopus Deploy allows remote attackers to perform unauthorized file manipulation and potentially execute arbitrary code due to improper path validation.

Octopus Deploy vulnerability rce ci-cd
1t 1c
high advisory

Arbitrary Code Execution in BusyBox via Heap Buffer Overflow

A heap-based buffer overflow vulnerability (CVE-2022-30065) in BusyBox allows a local attacker to execute arbitrary code and compromise system integrity.

BusyBox
1t 1c
high advisory

Multiple Vulnerabilities in GNU C Library

Multiple vulnerabilities in the GNU C Library (glibc) allow a local attacker to perform privilege escalation or trigger a denial of service condition on affected Linux-based systems.

glibc linux privilege-escalation denial-of-service
1t
high advisory

Remote Code Execution Vulnerability in Netgate pfSense

An authenticated remote attacker can exploit a vulnerability in Netgate pfSense to bypass security controls and execute arbitrary PHP code and shell commands.

pfSense vulnerability rce network-security
1t
high advisory

Domain-Restriction Bypass in n8n OpenAI Chat Model Node

An unauthenticated credential access vulnerability in n8n allows users to bypass domain restrictions in the OpenAI Chat Model node via the model-search endpoint, leading to unauthorized credential exposure.

n8n +5 vulnerability webserver credential-theft cve-2026-86082 denial-of-service web-vulnerability cve-2026-86076 javascript +1
3t 2c updated
high advisory

Multiple Vulnerabilities in Oracle GraalVM

Oracle GraalVM contains multiple vulnerabilities including CVE-2024-21226, CVE-2024-21227, and CVE-2024-21228, which allow remote unauthenticated attackers to compromise system confidentiality, integrity, and availability.

GraalVM vulnerability java oracle
low advisory

Multiple Vulnerabilities in Oracle Hyperion

Oracle Hyperion is affected by multiple security vulnerabilities (CVE-2024-21054, CVE-2024-21055) that allow remote attackers to compromise system confidentiality, integrity, and availability.

Hyperion vulnerability enterprise-application
2c
high advisory

Multiple Vulnerabilities in Aruba EdgeConnect

Multiple vulnerabilities in Aruba EdgeConnect allow for privilege escalation, denial of service, information disclosure, file manipulation, cross-site scripting, security bypass, and arbitrary code execution.

Aruba EdgeConnect vulnerability network-infrastructure remote-code-execution
5c
high advisory

Multiple Vulnerabilities in Apache Airflow Providers

Multiple vulnerabilities in Apache Airflow and its providers (FAB, Keycloak, Kafka, Akeyless) could allow unauthenticated or authenticated attackers to perform remote code execution, privilege escalation, or unauthorized data access.

Airflow vulnerability apache-airflow product-news
2t
medium advisory

Vulnerability in F5 NGINX

A vulnerability in F5 NGINX, tracked as CVE-2026-90439, allows remote attackers to trigger a denial of service and potentially compromise data integrity.

NGINX Open Source +1 vulnerability webserver dos
1c
high advisory

Multiple Vulnerabilities in Docker Sandboxes

Multiple vulnerabilities, including CVE-2026-77179 and CVE-2026-79994, in Docker Sandboxes versions prior to 0.42.0 could allow remote code execution, data confidentiality breaches, and integrity loss.

Docker Sandboxes vulnerability remote-code-execution docker
2c
high advisory

Atomic macOS (AMOS) Stealer Activity

Atomic macOS (AMOS) stealer uses deceptive 'toolkit' websites to trick users into executing terminal commands that deploy credential-harvesting malware and persistent Mach-O binaries.

macos malware stealer information-stealer
1r 3t 4i
high advisory

Iranian State-Sponsored Surveillance Malware: Chosen Brick

Iranian state-sponsored actors are leveraging the 'Chosen Brick' Windows malware to conduct surveillance on global activists and journalists via social engineering and Telegram-based command-and-control.

surveillance nation-state windows espionage
1r 4t
high advisory

Command Injection in /api/datastorage/data Endpoint (CVE-2026-27563)

An authenticated high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint to execute arbitrary code with root privileges.

/api/datastorage/data cve-2026-27563 command-injection webserver vulnerability
1r 1t 1c
high advisory

Command Injection Vulnerability in IODD Devices (CVE-2026-27561)

An authenticated remote attacker with administrative privileges can execute arbitrary commands with root permissions via a crafted GET request to the /api/iodd/config endpoint.

IODD
1r 2t 1c
high advisory

Command Injection in Attached Devices Endpoint

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint to achieve arbitrary code execution with root privileges.

cve-2026-27558 command-injection rce webserver
1r 3t 1c
high advisory

Local File Inclusion and RCE in /index.php/ajax/save_iodd_parameters

A local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint allows a remote attacker with a valid operator cookie to achieve remote code execution.

CVE-2026-27556 lfi rce web-security
1c
medium advisory

Improper Authorization in Device Upload Endpoint (CVE-2026-27552)

An improper authorization vulnerability in the /index.php/attached_devices_tab/do_upload endpoint allows low-privileged remote attackers to upload arbitrary files, potentially leading to unauthorized device behavior or denial-of-service.

attached_devices_tab vulnerability web-application cve-2026-27552
1r 1t 1c
high advisory

Command Injection in /index.php/ajax/parameterManage Endpoint

A low-privileged remote attacker can exploit a command injection vulnerability at the /index.php/ajax/parameterManage endpoint using valid credentials to gain root-level code execution.

web-vulnerability remote-code-execution command-injection cve-2026-27551
1r 1t 1c
high advisory

Command Injection in Field_Shadow_Password

CVE-2026-27550 is a command injection vulnerability allowing low-privileged attackers with operator credentials to execute arbitrary commands with root privileges.

Field_Shadow_Password vulnerability command-injection cve-2026-27550
1t 1c
high advisory

PhantomRaven Information Stealer

A bug bounty hunter is leveraging LLM-generated JavaScript information stealers distributed via malicious npm packages to identify vulnerabilities for bounty submissions.

infostealer supply-chain npm malware
2t 8i
high advisory

IDOR Vulnerability in Bookly WordPress Plugin

An Insecure Direct Object Reference (IDOR) vulnerability in the Bookly WordPress plugin allows unauthenticated attackers to enumerate and exfiltrate private AI booking transcripts via sequential ID incrementation.

Bookly web-application wordpress idor cve-2026-89063
2t 1c
high advisory

Arbitrary File Overwrite in Contest Gallery WordPress Plugin

The Contest Gallery WordPress plugin is vulnerable to unauthenticated arbitrary file overwrite via the 'baseUrlForFacebook' parameter, allowing authenticated attackers to achieve remote code execution.

Contest Gallery wordpress vulnerability rce
2t 1c
high advisory

Stored XSS in WP-Lister Lite for eBay WordPress Plugin

The WP-Lister Lite for eBay plugin for WordPress contains a Stored Cross-Site Scripting vulnerability in its AJAX Cron Handler allowing unauthenticated script injection.

WP-Lister Lite for eBay
1t 1c
critical advisory

Authorization Bypass in TrueBooker WordPress Plugin

The TrueBooker Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass vulnerability allowing unauthenticated attackers to modify arbitrary user email addresses and facilitate account takeover.

TrueBooker – Appointment Booking and Scheduler System wordpress vulnerability authorization-bypass
2t 1c
high advisory

Suspicious Rundll32 Execution Without Command-Line Arguments

The execution of rundll32.exe without command-line arguments is detected via endpoint telemetry, a behavior indicative of potential malicious activity such as Cobalt Strike, leading to arbitrary code execution and system compromise.

PoC Windows Print Spooler defense-evasion windows rundll32
2r 1t 1c updated
high advisory

HTTP Request Smuggling Vulnerability in Tornado

Tornado versions prior to 6.4.1 are vulnerable to HTTP request smuggling via the improper processing of duplicate 'Transfer-Encoding: chunked' headers when deployed behind a proxy.

Tornado +1 web-application http-request-smuggling vulnerability request-smuggling
3t 1c updated
critical advisory

HTTP Request Smuggling Vulnerability in http4s Ember

The http4s Ember HTTP/1.1 parser fails to reject messages containing both 'Transfer-Encoding' and 'Content-Length' headers, enabling CL.TE request smuggling attacks.

http4s-ember-core +5 request-smuggling cve-2026-69204 http-vulnerability denial-of-service vulnerability http2 http4s cve-2026-69202
3t 1c
low advisory

Denial of Service via Heap Exhaustion in http4s DigestAuth

An improper eviction logic in the http4s DigestAuth middleware allows unauthenticated remote attackers to cause heap exhaustion and service failure by triggering unbounded growth of the internal nonce map.

http4s-ember-server
1t 1c
medium advisory

Remote Denial of Service in libp2p-quic via Certificate Expiry Race

A malicious peer can trigger an application crash in libp2p-quic (< 0.13.1) by initiating a QUIC handshake and delaying the final TLS fragment until the peer certificate expires, causing an unhandled panic.

libp2p-quic denial-of-service libp2p rust
1t 1c