Skip to content
Threat Feed

September 2026 (30)

medium advisory

Remote Denial of Service in libp2p-quic via Certificate Expiry Race

A malicious peer can trigger an application crash in libp2p-quic (< 0.13.1) by initiating a QUIC handshake and delaying the final TLS fragment until the peer certificate expires, causing an unhandled panic.

libp2p-quic denial-of-service libp2p rust
1t 1c
low advisory

Unauthenticated Denial of Service in emp3r0r HTTP Polling Transport

An unauthenticated remote denial-of-service vulnerability in the emp3r0r C2 server (CVE-2026-61554) allows attackers to exhaust server resources by injecting arbitrary request bodies before session authentication.

emp3r0r
1t 1c
high advisory

Multiple Safety-Control Bypasses in @zereight/mcp-gitlab

Multiple vulnerabilities in the @zereight/mcp-gitlab package allow attackers to bypass read-only mode, exfiltrate data, perform unauthorized GitLab operations, and trigger a denial-of-service via unauthenticated session exhaustion.

@zereight/mcp-gitlab mcp gitlab llm-security supply-chain
4t
high threat

Oracle Security Updates - September 2026

Roundup of Oracle security advisories published in September 2026.

roundup
135c
high advisory

Flowise Cross-Tenant Authorization Vulnerability

Flowise versions before 3.1.4 contain authorization gaps in Enterprise endpoints that allow authenticated users to perform cross-tenant operations including unauthorized workspace deletion and SSO credential access.

Flowise Enterprise +1 path-traversal arbitrary-file-write rce xss vulnerability nosql-injection web-application ssrf +3
4t 1c
critical advisory

Unauthenticated PHP Object Injection in Cotonti Comments Plugin

Cotonti 1.0.0 is vulnerable to unauthenticated remote code execution via a PHP object injection flaw in the Comments plugin's 'ci' GET parameter.

Comments plugin php-object-injection rce web-vulnerability
1r 1t 1c
high advisory

Arbitrary File Write Vulnerability in crawl4ai PDFContentScrapingStrategy

The PDFContentScrapingStrategy in crawl4ai versions prior to 0.9.3 is vulnerable to arbitrary file write via insufficient input validation in the _filter_untrusted_fields function, allowing attackers to overwrite sensitive files.

crawl4ai denial-of-service web-scraping cve-2026-91941
2t 1c
high advisory

Multiple Vulnerabilities in Veeam Backup & Replication

Multiple vulnerabilities in Veeam Backup & Replication prior to version 13.0.2.29 allow an attacker to cause privilege escalation and compromise data integrity.

PoC Veeam Backup & Replication +1 vulnerability privilege-escalation data-integrity
2r 1t 2c updated
medium advisory

Detection of Fileless Execution via memfd_create on Linux

This brief details a detection strategy for identifying potential fileless execution on Linux platforms by monitoring the memfd_create syscall for anomalous process lineage and execution paths.

linux defense-evasion fileless-execution edr process-lineage
1r 3t
low advisory

Linux Firewall Rule Manipulation for Defense Evasion

Adversaries manipulate Linux firewall configurations using utilities like iptables, nftables, or ufw to create or modify rules, facilitating unauthorized network access or the disruption of security controls.

defense-evasion linux firewall
1r 1t
high advisory

Potential Successful SSH Brute Force on macOS

Attackers are conducting brute-force or password-spraying attacks against macOS SSH services, identified by a burst of authentication failures followed by a successful login.

macOS
1r 2t
low advisory

Detection of SSH Brute Force Attacks on macOS

Adversaries are targeting macOS hosts via SSH brute force or password spraying, which can be identified by analyzing failed authentication logs generated by the sshd-session process.

macOS credential-access ssh brute-force
1r 2t
low advisory

Suspicious Whoami Command Activity

Attackers frequently abuse the native Windows whoami utility for situational awareness, specifically to verify privilege escalation and identify current user contexts, necessitating monitoring of suspicious parent-child process chains.

Windows
1r 2t
high advisory

Remote Command Injection in TOTOLINK X5000R

A remote OS command injection vulnerability in the TOTOLINK X5000R router allows unauthenticated attackers to execute arbitrary commands via the exportOvpn function.

X5000R remote-code-execution cve-2026-91853 network-security
1r 1t 1c
high advisory

Path Traversal Vulnerability in atomic-agents-stack

The atomic-agents-stack library before version 1.1.0 is vulnerable to path traversal within its dashboard HTTP server, allowing remote attackers to read arbitrary files via crafted requests.

atomic-agents-stack
1r 1t 1c
high advisory

Arbitrary Code Execution in atomic-agents-stack via MCP Registry Injection

The atomic-agents-stack library before 1.1.0 allows man-in-the-middle attackers to inject malicious subprocess commands by exploiting cleartext HTTP communication in the MCP server-registry backend.

atomic-agents-stack
2t 1c
high advisory

Unauthenticated Rate Limiting Vulnerability in Vikunja Authentication Endpoints

Vikunja versions before 2.6.0 lack rate limiting on public /api/v2 authentication endpoints, enabling credential stuffing, account enumeration, and password-reset flooding.

Vikunja
1r 1t 1c
high advisory

FreeRDP Protocol Negotiation Bypass via CVE-2026-91949

An unauthenticated protocol negotiation vulnerability in FreeRDP servers allows attackers to bypass RDSTLS transport security policies.

FreeRDP memory-corruption rdp vulnerability denial-of-service cve-2026-91955
2t 1c
high advisory

Authorization Bypass in Flowise openai-realtime Endpoints

Flowise versions prior to 3.1.4 contain an authorization flaw in the openai-realtime endpoint, enabling authenticated users to access and execute tools in unauthorized workspaces via cross-workspace ID manipulation.

Flowise vulnerability auth-bypass api-security
1c
critical threat

Unauthenticated SQL Injection in Yonyou U8 CRM (CVE-2024-58385)

An unauthenticated SQL injection vulnerability in Yonyou U8 CRM allows attackers to execute arbitrary SQL commands via the fillbacksettingedit.php endpoint, potentially leading to remote code execution on MS SQL Server instances.

exploited U8 CRM web-application sql-injection remote-code-execution cve-2024-58385
1r 2t 1c
critical threat

Unauthenticated RCE in Yonyou U8 Cloud via Java Deserialization

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability (CVE-2023-54398) in the FileManageServlet component, enabling remote attackers to achieve arbitrary OS command execution.

exploited U8 Cloud
1r 2t 1c
high advisory

Critical Vulnerabilities in CareCam CM2507 IP Cameras

Multiple high-severity vulnerabilities in CareCam CM2507 firmware v251211.1507 allow unauthenticated remote access, credential theft, and arbitrary code execution due to authentication bypasses and design flaws.

CareCam CM2507 ics cve security-advisory
4t
high advisory

Multiple Vulnerabilities in Siemens Reyrolle 7SR5 Firmware

Siemens Reyrolle 7SR5 devices running firmware versions earlier than V2.70 are impacted by multiple vulnerabilities within the embedded Mongoose Web Server, potentially leading to denial of service, information disclosure, or authentication bypass.

Reyrolle 7SR5 ics energy firmware-vulnerability
1c
critical advisory

Hard-coded Cryptographic Keys in Wärtsilä FOS-Onboard

Wärtsilä FOS-Onboard version 5.07.0923.01 contains hard-coded cryptographic keys in the Update Controller and robot testing framework that could facilitate unauthorized code execution, update deployment, and credential theft.

FOS-Onboard ics transportation patch-management cve-2026-78225 cve-2026-81855
2t
high advisory

Authentication Bypass in Mendix SAML Module

An authentication bypass vulnerability (CVE-2026-80465) in multiple Mendix SAML module versions allows unauthenticated attackers to hijack user sessions via improper SAML response signature validation.

Mendix SAML +2 vulnerability authentication-bypass sso mendix
1c updated
low advisory

Reflected Cross-Site Scripting Vulnerability in Siemens Teamcenter

An unauthenticated remote attacker can exploit a reflected XSS vulnerability in the Teamcenter authentication redirect flow to execute arbitrary JavaScript in the context of an authenticated user session.

Teamcenter +3 web-vulnerability xss siemens
1r 1t 1c
medium advisory

Insufficiently Protected Credentials Vulnerability in Schneider Electric SCADAPack x70

Schneider Electric SCADAPack x70 series RTUs contain a vulnerability (CVE-2026-81861) in the legacy 'Secure Lock' functionality that could lead to unauthorized exposure of authentication information.

SCADAPack 47x +6 vulnerability industrial-control-systems critical-infrastructure
1t 1c
high threat

Authentication and Authorization Vulnerabilities in mySCADA myPRO Manager

Multiple vulnerabilities in mySCADA myPRO Manager versions 2.1 and earlier allow unauthenticated attackers to execute arbitrary management commands or send unauthorized SMS messages.

exploited mySCADA myPRO Manager ics scada vulnerability cve
2t
critical advisory

Critical Vulnerabilities in Digital Watchdog VMAX DVR and NVR Products

Multiple high-severity vulnerabilities in Digital Watchdog VMAX series devices allow unauthenticated remote attackers to bypass authentication, gain root access via hard-coded credentials, and execute arbitrary system commands.

VMAX A1 G4 DVRs +4 critical-infrastructure ics authentication-bypass remote-code-execution
2t
high advisory

Stored Cross-Site Scripting in MotoPress Hotel Booking Plugin

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe webhook listener due to missing signature verification and improper output sanitization.

Hotel Booking web-application xss wordpress plugin-vulnerability
1r 1t 1c