Skip to content
Threat Feed

September 2026 (30)

high advisory

ZITADEL Privilege Escalation via OAuth2 Token Exchange

A vulnerability in ZITADEL's OAuth2 Token Exchange endpoint (CVE-2026-56668) allows authenticated users to exchange low-privilege tokens for highly privileged tokens by bypassing authorization and scope validation checks.

ZITADEL +1 auth-bypass privilege-escalation oauth2
1t 1c
critical threat

Active Exploitation of SQL Injection in Cisco Secure Email Gateway

Cisco has confirmed active exploitation of a SQL injection vulnerability (CVE-2026-76461) affecting multiple versions of Cisco Secure Email Gateway and Secure Email and Web Manager products.

exploited Cisco AsyncOS for Cisco Secure Email Gateway +2 vulnerability cve network active-exploitation
1c
medium advisory

Detection of SSRF Attempts Targeting Cloud Metadata Services

This detection rule identifies server-side request forgery (SSRF) attempts targeting cloud instance metadata endpoints (IMDS) across multiple web server platforms to harvest cloud credentials.

AWS EC2 Instance Metadata Service +2 ssrf cloud-security credential-access
1r 2t
medium threat

Authenticated IDOR Vulnerability in FlowForms

An authenticated Insecure Direct Object Reference (IDOR) vulnerability in FlowForms version 1.1.1 and earlier allows attackers with contributor-level access to modify arbitrary forms.

exploited FlowForms idor web-vulnerability cve-2026-12400
1r 1t 1c
high advisory

Remote Command Injection in D-Link DSL-3782

An unauthenticated remote command injection vulnerability in the D-Link DSL-3782 router allows attackers to execute arbitrary system commands via the Diagnostics component.

DSL-3782 cve-2026-90880 command-injection network-security
1c
high threat

SQL Injection in FilePress Publish Module

An unpatched SQL injection vulnerability in zyx0814 FilePress versions 3.0.1 and earlier allows remote attackers to manipulate the orderby or order arguments within search.php.

exploited FilePress sqli web-vulnerability
1t 1c
high advisory

SQL Injection in SourceCodester Online Faculty Clearance System

SourceCodester Online Faculty Clearance System 1.0 is vulnerable to remote SQL injection in /delete_requirement.php via the ID argument, allowing unauthorized database access.

Online Faculty Clearance System web-vulnerability sql-injection sourcecodester
1r 1t 1c
high advisory

SQL Injection Vulnerability in Online Food Ordering System

Online Food Ordering System 1.0 contains a SQL injection vulnerability in /web/category-foods.php that allows remote, unauthenticated attackers to execute arbitrary database queries via the ID argument.

Online Food Ordering System web-vulnerability sql-injection cve
1r 1t 1c
high advisory

Out-of-Bounds Memory Read in zstd-jni

The zstd-jni library versions prior to 1.5.7-14 are vulnerable to an out-of-bounds memory read in the ZstdDictCompress constructor, allowing local or remote attackers to read native heap memory into a compression dictionary.

zstd-jni vulnerability memory-safety java
1t 1c updated
high advisory

Path Traversal in Weights & Biases wandb

The Weights & Biases wandb library before version 0.29.0 is vulnerable to path traversal via the File.download function, allowing an attacker-controlled backend to write files to arbitrary locations.

wandb vulnerability path-traversal python
2t 1c
high advisory

SQL Injection in SourceCodester College Notes Gallery Management System

SourceCodester College Notes Gallery Management System version 1.0 contains a SQL injection vulnerability in the login.php file, allowing unauthenticated remote attackers to execute arbitrary database queries.

College Notes Gallery Management System sqli vulnerability web-application
1r 2t 1c
low advisory

Stack-Based Buffer Overflow in GNU libextractor

GNU libextractor versions prior to 1.15 contain a stack-based buffer overflow in the process_star_office function that can be triggered by malicious OLE2 stream data to cause application crashes.

libextractor
1t 1c
high advisory

Path Traversal Vulnerability in Flextype CMS Entries REST API

Flextype CMS versions through 1.0.0-alpha.3 are vulnerable to path traversal via the Entries REST API, allowing authenticated attackers to read, create, or overwrite arbitrary files on the filesystem.

Flextype CMS path-traversal web-vulnerability cve-2026-91751
1r 1t 1c
high advisory

SQL Injection in PHPGurukul Daily Expense Tracker System

An unauthenticated SQL injection vulnerability in the login component of PHPGurukul Daily Expense Tracker System 1.1 allows remote attackers to execute arbitrary database queries.

Daily Expense Tracker System web-vulnerability sql-injection cve-2026-90844
2r 1t 1c
high threat

Remote Command Injection in SabyasachiRana WebMap

An unauthenticated remote OS command injection vulnerability in SabyasachiRana WebMap's nmap_newscan function allows attackers to execute arbitrary commands via the target/params argument.

exploited WebMap
1r 2t 1c
high advisory

Authentication Bypass in PHPGurukul Blood Donor Management System

PHPGurukul Blood Donor Management System 1.0 is vulnerable to an authentication bypass in the admin dashboard, allowing remote attackers to gain unauthorized administrative access.

Blood Donor Management System web-application authentication-bypass vulnerability
2t 1c
critical advisory

Remote Code Execution in EFM ipTIME C200E via Command Injection

An unauthenticated remote command injection vulnerability in EFM ipTIME C200E firmware version 1.094 allows remote attackers to execute arbitrary operating system commands via the iux_set.cgi script.

ipTIME C200E remote-code-execution cve-2026-90847 networking command-injection
2t 1c
high advisory

Path Traversal Vulnerability in DevSpace In-Pod Sync

DevSpace versions 6.3.21 and earlier are vulnerable to a path traversal flaw during the in-pod sync process that allows arbitrary file writes on developer workstations.

DevSpace supply-chain path-traversal
2t 1c
high advisory

CVE-2026-91145 Expression Injection in Activiti

Activiti through 7.1.0.M6 contains an expression injection vulnerability in process variables that allows unauthenticated method invocation on application beans during mail task execution.

Activiti expression-injection vulnerability
1t 1c
high advisory

Path Traversal Vulnerability in ZFile Download Endpoint

ZFile versions through 5.0.5 are vulnerable to a path traversal attack allowing unauthenticated attackers to download arbitrary files via manipulated share link query parameters.

ZFile path-traversal web-vulnerability information-disclosure
1r 1c
high advisory

Authentication Bypass in goproxy CONNECT Requests (CVE-2026-91143)

The goproxy package through version 15.3 fails to enforce authentication on CONNECT tunnel requests, allowing unauthorized network relay via the proxy.

goproxy proxy authentication-bypass cve-2026-91143
1t 1c
high advisory

XML External Entity Injection in IBM Business Automation Workflow

IBM Business Automation Workflow contains a vulnerability in default programming artifacts that allows for XML External Entity (XXE) injection attacks, potentially enabling unauthorized file access or server-side request forgery.

Business Automation Workflow web-vulnerability xxe ibm
1t 1c
critical advisory

Remote Code Execution in IBM Langflow OSS via A2A Endpoint

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an unauthenticated remote code execution vulnerability in the A2A public endpoint.

Langflow OSS +4 remote-code-execution vulnerability webserver web-application security-scanner-bypass cve-2026-76059 rce cloud-security +2
1r 8t 1c updated
high advisory

HTTP Response Splitting Vulnerability in a2aproject a2a-java

CVE-2026-90819 identifies an HTTP response splitting vulnerability in the Authorization Header Construction component of a2a-java 1.2.0, enabling remote attackers to manipulate HTTP responses.

a2a-java
1t 1c
high advisory

Information Disclosure Vulnerability in IBM Sterling File Gateway

IBM Sterling File Gateway contains an improper access control vulnerability (CVE-2026-19290) that allows remote attackers to obtain sensitive information.

Sterling File Gateway vulnerability information-disclosure ibm
1t 1c
high advisory

IBM MQ XML External Entity Injection Vulnerability

An XML external entity injection vulnerability in IBM MQ allows authenticated attackers to perform arbitrary file reads or server-side request forgery during reply message processing.

MQ
1t 1c
high advisory

SQL Injection in Magistrala HTTP API

Magistrala versions prior to 1.0.0 contain a SQL injection vulnerability in the timescale-reader and postgres-reader services allowing authenticated users to achieve remote code execution via arbitrary SQL execution.

Magistrala sql-injection vulnerability rce
2t 1c
high advisory

Command Injection Vulnerability in IBM App Connect Enterprise

IBM App Connect Enterprise versions 13.0.x and 12.0.x contain a command injection vulnerability (CVE-2026-17133) that allows local attackers to execute arbitrary OS commands.

App Connect Enterprise vulnerability command-injection cve
1t 1c
critical threat

Active Exploitation of Cisco Secure Email Gateway SQL Injection

CISA has added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation of a SQL injection vulnerability in Cisco Secure Email Gateway.

exploited Secure Email Gateway vulnerability cve sql-injection cisa-kev
1c
high threat

Path Traversal Vulnerability in PyMuPDF Font Processing

PyMuPDF versions through 1.28.2 contain a path traversal vulnerability in the extract_objects() function, allowing attackers to perform arbitrary file writes via crafted document font metadata.

exploited PyMuPDF vulnerability path-traversal software-library
1t