September 2026 (30)
ZITADEL Privilege Escalation via OAuth2 Token Exchange
1 TTP 1 CVEA vulnerability in ZITADEL's OAuth2 Token Exchange endpoint (CVE-2026-56668) allows authenticated users to exchange low-privilege tokens for highly privileged tokens by bypassing authorization and scope validation checks.
Active Exploitation of SQL Injection in Cisco Secure Email Gateway
1 CVECisco has confirmed active exploitation of a SQL injection vulnerability (CVE-2026-76461) affecting multiple versions of Cisco Secure Email Gateway and Secure Email and Web Manager products.
Detection of SSRF Attempts Targeting Cloud Metadata Services
1 rule 2 TTPsThis detection rule identifies server-side request forgery (SSRF) attempts targeting cloud instance metadata endpoints (IMDS) across multiple web server platforms to harvest cloud credentials.
Authenticated IDOR Vulnerability in FlowForms
1 rule 1 TTP 1 CVEAn authenticated Insecure Direct Object Reference (IDOR) vulnerability in FlowForms version 1.1.1 and earlier allows attackers with contributor-level access to modify arbitrary forms.
Remote Command Injection in D-Link DSL-3782
1 CVEAn unauthenticated remote command injection vulnerability in the D-Link DSL-3782 router allows attackers to execute arbitrary system commands via the Diagnostics component.
SQL Injection in FilePress Publish Module
1 TTP 1 CVEAn unpatched SQL injection vulnerability in zyx0814 FilePress versions 3.0.1 and earlier allows remote attackers to manipulate the orderby or order arguments within search.php.
SQL Injection in SourceCodester Online Faculty Clearance System
1 rule 1 TTP 1 CVESourceCodester Online Faculty Clearance System 1.0 is vulnerable to remote SQL injection in /delete_requirement.php via the ID argument, allowing unauthorized database access.
SQL Injection Vulnerability in Online Food Ordering System
1 rule 1 TTP 1 CVEOnline Food Ordering System 1.0 contains a SQL injection vulnerability in /web/category-foods.php that allows remote, unauthenticated attackers to execute arbitrary database queries via the ID argument.
Out-of-Bounds Memory Read in zstd-jni
1 TTP 1 CVEThe zstd-jni library versions prior to 1.5.7-14 are vulnerable to an out-of-bounds memory read in the ZstdDictCompress constructor, allowing local or remote attackers to read native heap memory into a compression dictionary.
Path Traversal in Weights & Biases wandb
2 TTPs 1 CVEThe Weights & Biases wandb library before version 0.29.0 is vulnerable to path traversal via the File.download function, allowing an attacker-controlled backend to write files to arbitrary locations.
SQL Injection in SourceCodester College Notes Gallery Management System
1 rule 2 TTPs 1 CVESourceCodester College Notes Gallery Management System version 1.0 contains a SQL injection vulnerability in the login.php file, allowing unauthenticated remote attackers to execute arbitrary database queries.
Stack-Based Buffer Overflow in GNU libextractor
1 TTP 1 CVEGNU libextractor versions prior to 1.15 contain a stack-based buffer overflow in the process_star_office function that can be triggered by malicious OLE2 stream data to cause application crashes.
Path Traversal Vulnerability in Flextype CMS Entries REST API
1 rule 1 TTP 1 CVEFlextype CMS versions through 1.0.0-alpha.3 are vulnerable to path traversal via the Entries REST API, allowing authenticated attackers to read, create, or overwrite arbitrary files on the filesystem.
SQL Injection in PHPGurukul Daily Expense Tracker System
2 rules 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability in the login component of PHPGurukul Daily Expense Tracker System 1.1 allows remote attackers to execute arbitrary database queries.
Remote Command Injection in SabyasachiRana WebMap
1 rule 2 TTPs 1 CVEAn unauthenticated remote OS command injection vulnerability in SabyasachiRana WebMap's nmap_newscan function allows attackers to execute arbitrary commands via the target/params argument.
Authentication Bypass in PHPGurukul Blood Donor Management System
2 TTPs 1 CVEPHPGurukul Blood Donor Management System 1.0 is vulnerable to an authentication bypass in the admin dashboard, allowing remote attackers to gain unauthorized administrative access.
Remote Code Execution in EFM ipTIME C200E via Command Injection
2 TTPs 1 CVEAn unauthenticated remote command injection vulnerability in EFM ipTIME C200E firmware version 1.094 allows remote attackers to execute arbitrary operating system commands via the iux_set.cgi script.
Path Traversal Vulnerability in DevSpace In-Pod Sync
2 TTPs 1 CVEDevSpace versions 6.3.21 and earlier are vulnerable to a path traversal flaw during the in-pod sync process that allows arbitrary file writes on developer workstations.
CVE-2026-91145 Expression Injection in Activiti
1 TTP 1 CVEActiviti through 7.1.0.M6 contains an expression injection vulnerability in process variables that allows unauthenticated method invocation on application beans during mail task execution.
Path Traversal Vulnerability in ZFile Download Endpoint
1 rule 1 CVEZFile versions through 5.0.5 are vulnerable to a path traversal attack allowing unauthenticated attackers to download arbitrary files via manipulated share link query parameters.
Authentication Bypass in goproxy CONNECT Requests (CVE-2026-91143)
1 TTP 1 CVEThe goproxy package through version 15.3 fails to enforce authentication on CONNECT tunnel requests, allowing unauthorized network relay via the proxy.
XML External Entity Injection in IBM Business Automation Workflow
1 TTP 1 CVEIBM Business Automation Workflow contains a vulnerability in default programming artifacts that allows for XML External Entity (XXE) injection attacks, potentially enabling unauthorized file access or server-side request forgery.
Remote Code Execution in IBM Langflow OSS via A2A Endpoint
1 rule 8 TTPs 1 CVEIBM Langflow OSS versions 1.0.0 through 1.11.1 contain an unauthenticated remote code execution vulnerability in the A2A public endpoint.
HTTP Response Splitting Vulnerability in a2aproject a2a-java
1 TTP 1 CVECVE-2026-90819 identifies an HTTP response splitting vulnerability in the Authorization Header Construction component of a2a-java 1.2.0, enabling remote attackers to manipulate HTTP responses.
Information Disclosure Vulnerability in IBM Sterling File Gateway
1 TTP 1 CVEIBM Sterling File Gateway contains an improper access control vulnerability (CVE-2026-19290) that allows remote attackers to obtain sensitive information.
IBM MQ XML External Entity Injection Vulnerability
1 TTP 1 CVEAn XML external entity injection vulnerability in IBM MQ allows authenticated attackers to perform arbitrary file reads or server-side request forgery during reply message processing.
SQL Injection in Magistrala HTTP API
2 TTPs 1 CVEMagistrala versions prior to 1.0.0 contain a SQL injection vulnerability in the timescale-reader and postgres-reader services allowing authenticated users to achieve remote code execution via arbitrary SQL execution.
Command Injection Vulnerability in IBM App Connect Enterprise
1 TTP 1 CVEIBM App Connect Enterprise versions 13.0.x and 12.0.x contain a command injection vulnerability (CVE-2026-17133) that allows local attackers to execute arbitrary OS commands.
Active Exploitation of Cisco Secure Email Gateway SQL Injection
1 CVECISA has added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation of a SQL injection vulnerability in Cisco Secure Email Gateway.
Path Traversal Vulnerability in PyMuPDF Font Processing
1 TTPPyMuPDF versions through 1.28.2 contain a path traversal vulnerability in the extract_objects() function, allowing attackers to perform arbitrary file writes via crafted document font metadata.