September 2026 (30)
Remote Denial of Service in libp2p-quic via Certificate Expiry Race
1 TTP 1 CVEA malicious peer can trigger an application crash in libp2p-quic (< 0.13.1) by initiating a QUIC handshake and delaying the final TLS fragment until the peer certificate expires, causing an unhandled panic.
Unauthenticated Denial of Service in emp3r0r HTTP Polling Transport
1 TTP 1 CVEAn unauthenticated remote denial-of-service vulnerability in the emp3r0r C2 server (CVE-2026-61554) allows attackers to exhaust server resources by injecting arbitrary request bodies before session authentication.
Multiple Safety-Control Bypasses in @zereight/mcp-gitlab
4 TTPsMultiple vulnerabilities in the @zereight/mcp-gitlab package allow attackers to bypass read-only mode, exfiltrate data, perform unauthorized GitLab operations, and trigger a denial-of-service via unauthenticated session exhaustion.
Oracle Security Updates - September 2026
135 CVEsRoundup of Oracle security advisories published in September 2026.
Flowise Cross-Tenant Authorization Vulnerability
4 TTPs 1 CVEFlowise versions before 3.1.4 contain authorization gaps in Enterprise endpoints that allow authenticated users to perform cross-tenant operations including unauthorized workspace deletion and SSO credential access.
Unauthenticated PHP Object Injection in Cotonti Comments Plugin
1 rule 1 TTP 1 CVECotonti 1.0.0 is vulnerable to unauthenticated remote code execution via a PHP object injection flaw in the Comments plugin's 'ci' GET parameter.
Arbitrary File Write Vulnerability in crawl4ai PDFContentScrapingStrategy
2 TTPs 1 CVEThe PDFContentScrapingStrategy in crawl4ai versions prior to 0.9.3 is vulnerable to arbitrary file write via insufficient input validation in the _filter_untrusted_fields function, allowing attackers to overwrite sensitive files.
Multiple Vulnerabilities in Veeam Backup & Replication
2 rules 1 TTP 2 CVEsMultiple vulnerabilities in Veeam Backup & Replication prior to version 13.0.2.29 allow an attacker to cause privilege escalation and compromise data integrity.
Detection of Fileless Execution via memfd_create on Linux
1 rule 3 TTPsThis brief details a detection strategy for identifying potential fileless execution on Linux platforms by monitoring the memfd_create syscall for anomalous process lineage and execution paths.
Linux Firewall Rule Manipulation for Defense Evasion
1 rule 1 TTPAdversaries manipulate Linux firewall configurations using utilities like iptables, nftables, or ufw to create or modify rules, facilitating unauthorized network access or the disruption of security controls.
Potential Successful SSH Brute Force on macOS
1 rule 2 TTPsAttackers are conducting brute-force or password-spraying attacks against macOS SSH services, identified by a burst of authentication failures followed by a successful login.
Detection of SSH Brute Force Attacks on macOS
1 rule 2 TTPsAdversaries are targeting macOS hosts via SSH brute force or password spraying, which can be identified by analyzing failed authentication logs generated by the sshd-session process.
Suspicious Whoami Command Activity
1 rule 2 TTPsAttackers frequently abuse the native Windows whoami utility for situational awareness, specifically to verify privilege escalation and identify current user contexts, necessitating monitoring of suspicious parent-child process chains.
Remote Command Injection in TOTOLINK X5000R
1 rule 1 TTP 1 CVEA remote OS command injection vulnerability in the TOTOLINK X5000R router allows unauthenticated attackers to execute arbitrary commands via the exportOvpn function.
Path Traversal Vulnerability in atomic-agents-stack
1 rule 1 TTP 1 CVEThe atomic-agents-stack library before version 1.1.0 is vulnerable to path traversal within its dashboard HTTP server, allowing remote attackers to read arbitrary files via crafted requests.
Arbitrary Code Execution in atomic-agents-stack via MCP Registry Injection
2 TTPs 1 CVEThe atomic-agents-stack library before 1.1.0 allows man-in-the-middle attackers to inject malicious subprocess commands by exploiting cleartext HTTP communication in the MCP server-registry backend.
Unauthenticated Rate Limiting Vulnerability in Vikunja Authentication Endpoints
1 rule 1 TTP 1 CVEVikunja versions before 2.6.0 lack rate limiting on public /api/v2 authentication endpoints, enabling credential stuffing, account enumeration, and password-reset flooding.
FreeRDP Protocol Negotiation Bypass via CVE-2026-91949
2 TTPs 1 CVEAn unauthenticated protocol negotiation vulnerability in FreeRDP servers allows attackers to bypass RDSTLS transport security policies.
Authorization Bypass in Flowise openai-realtime Endpoints
1 CVEFlowise versions prior to 3.1.4 contain an authorization flaw in the openai-realtime endpoint, enabling authenticated users to access and execute tools in unauthorized workspaces via cross-workspace ID manipulation.
Unauthenticated SQL Injection in Yonyou U8 CRM (CVE-2024-58385)
1 rule 2 TTPs 1 CVEAn unauthenticated SQL injection vulnerability in Yonyou U8 CRM allows attackers to execute arbitrary SQL commands via the fillbacksettingedit.php endpoint, potentially leading to remote code execution on MS SQL Server instances.
Unauthenticated RCE in Yonyou U8 Cloud via Java Deserialization
1 rule 2 TTPs 1 CVEYonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability (CVE-2023-54398) in the FileManageServlet component, enabling remote attackers to achieve arbitrary OS command execution.
Critical Vulnerabilities in CareCam CM2507 IP Cameras
4 TTPsMultiple high-severity vulnerabilities in CareCam CM2507 firmware v251211.1507 allow unauthenticated remote access, credential theft, and arbitrary code execution due to authentication bypasses and design flaws.
Multiple Vulnerabilities in Siemens Reyrolle 7SR5 Firmware
1 CVESiemens Reyrolle 7SR5 devices running firmware versions earlier than V2.70 are impacted by multiple vulnerabilities within the embedded Mongoose Web Server, potentially leading to denial of service, information disclosure, or authentication bypass.
Hard-coded Cryptographic Keys in Wärtsilä FOS-Onboard
2 TTPsWärtsilä FOS-Onboard version 5.07.0923.01 contains hard-coded cryptographic keys in the Update Controller and robot testing framework that could facilitate unauthorized code execution, update deployment, and credential theft.
Authentication Bypass in Mendix SAML Module
1 CVEAn authentication bypass vulnerability (CVE-2026-80465) in multiple Mendix SAML module versions allows unauthenticated attackers to hijack user sessions via improper SAML response signature validation.
Reflected Cross-Site Scripting Vulnerability in Siemens Teamcenter
1 rule 1 TTP 1 CVEAn unauthenticated remote attacker can exploit a reflected XSS vulnerability in the Teamcenter authentication redirect flow to execute arbitrary JavaScript in the context of an authenticated user session.
Insufficiently Protected Credentials Vulnerability in Schneider Electric SCADAPack x70
1 TTP 1 CVESchneider Electric SCADAPack x70 series RTUs contain a vulnerability (CVE-2026-81861) in the legacy 'Secure Lock' functionality that could lead to unauthorized exposure of authentication information.
Authentication and Authorization Vulnerabilities in mySCADA myPRO Manager
2 TTPsMultiple vulnerabilities in mySCADA myPRO Manager versions 2.1 and earlier allow unauthenticated attackers to execute arbitrary management commands or send unauthorized SMS messages.
Critical Vulnerabilities in Digital Watchdog VMAX DVR and NVR Products
2 TTPsMultiple high-severity vulnerabilities in Digital Watchdog VMAX series devices allow unauthenticated remote attackers to bypass authentication, gain root access via hard-coded credentials, and execute arbitrary system commands.
Stored Cross-Site Scripting in MotoPress Hotel Booking Plugin
1 rule 1 TTP 1 CVEThe MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe webhook listener due to missing signature verification and improper output sanitization.