September 2026 (30)
Command Injection in PLANET IGS-5225 Industrial Switches
2 TTPs 1 CVEAn OS command injection vulnerability in the web interface of PLANET IGS-5225-8P2T4S switches allows authenticated remote attackers to execute arbitrary commands with root privileges.
IBM MQ Improper Validation Vulnerability (CVE-2026-11381)
1 CVEIBM MQ contains a vulnerability in the validation of message distribution list structures that allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.
XML External Entity Injection in IBM MQ Classes for Java
1 TTP 1 CVEAn XML external entity injection vulnerability (CVE-2026-12666) in IBM MQ Classes for Java allows authenticated attackers to perform denial-of-service attacks or disclose sensitive host information by manipulating MQRFH2 headers.
Stack Buffer Overflow in IBM MQ XA Transaction Processing
1 CVEIBM MQ is vulnerable to a stack buffer overflow triggered by malicious XA transaction identifiers, allowing an authenticated attacker to cause a denial of service or achieve arbitrary code execution.
Vulnerability in IBM MQ Cluster Command Message Validation
1 CVEIBM MQ contains a vulnerability (CVE-2026-10853) where improper cluster command message length validation allows authenticated attackers to cause a denial of service or remote code execution.
IBM MQ Java and JMS Client Deserialization Vulnerability
1 TTP 1 CVEAn authenticated attacker can execute arbitrary code on client applications by exploiting a deserialization filter bypass in IBM MQ Java and JMS client libraries.
Buffer Overflow Vulnerability in IBM MQ
2 TTPs 1 CVEIBM MQ is vulnerable to a buffer overflow during the processing of malformed compressed data, which can be leveraged by a remote attacker for denial of service or arbitrary code execution.
Path Traversal Vulnerability in IBM Cloud Pak for Data
1 TTP 1 CVEIBM Cloud Pak for Data 5.1.2 is vulnerable to a path traversal vulnerability via crafted URL requests that allow unauthenticated remote attackers to access arbitrary files on the system.
Improper Translation of HTTP/1 CONNECT to HTTP/2 Headers
1 CVEA vulnerability exists where HTTP/1 authority-form CONNECT requests are incorrectly translated into malformed HTTP/2 CONNECT requests, allowing for attacker control over the :authority header and potential request smuggling.
SSRF Vulnerability in ArcadeDB via IPv6 Transition Addressing
2 TTPs 1 CVEAuthenticated attackers can exploit a validation flaw in ArcadeDB's SSRF guard to reach internal services or cloud metadata endpoints by using specifically crafted IPv6 transition addresses.
Heap Buffer Underflow in IBM MQ for HPE NonStop
1 TTP 1 CVEIBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.
CSRF Vulnerability in IBM Common Licensing Agent and ART
1 CVEIBM Common Licensing Agent and ART versions 9.0 through 9.0.0.2 contain a cross-site request forgery (CSRF) vulnerability that enables unauthenticated attackers to perform unauthorized actions on behalf of an authenticated user.
Sandbox Escape in vm2 via NodeVM Configuration Misvalidation
6 TTPs 1 CVEAn improper validation of the 'require' configuration in the vm2 Node.js sandbox allows attackers to bypass nesting restrictions and achieve arbitrary code execution by spawning an inner NodeVM with elevated privileges.
Privilege Escalation in uutils coreutils via Incorrect File Ownership Handling
1 TTP 1 CVEuutils coreutils versions before 0.10.0 are vulnerable to local privilege escalation due to an race condition in the install utility that preserves setuid/setgid bits when ownership changes fail.
DNSSEC Validation Bypass in hickory-resolver
1 TTP 1 CVEA vulnerability in hickory-resolver versions prior to 0.26.2 causes the library to ignore bogus DNSSEC proof states, allowing attackers to inject forged DNS records as validated data.
Improper CRLF Validation in Netty netty-codec-smtp
2 CVEsThe netty-codec-smtp component in Netty suffers from insufficient CRLF validation in the SMTP command-name field, representing an incomplete remediation for CVE-2025-59419 that enables potential SMTP command injection or response splitting.
Improper Protocol Downgrade of Extended CONNECT Requests in HTTP/2 and HTTP/3
1 CVEA vulnerability in HTTP/2 and HTTP/3 protocol handling allows Extended CONNECT requests to be downgraded to regular CONNECT requests, potentially bypassing security policies that rely on Extended CONNECT semantics.
Denial of Service Vulnerability in Netty StompSubframeDecoder
1 TTP 1 CVEA memory leak vulnerability in the Netty StompSubframeDecoder component (CVE-2026-93494) allows remote attackers to cause a Denial of Service by sending malformed STOMP frames.
Denial of Service via Unbounded Queue Growth in WebSocketServerExtensionHandler
1 TTP 1 CVEA vulnerability in WebSocketServerExtensionHandler allows an attacker to trigger unbounded per-connection queue growth, leading to resource exhaustion and denial of service.
Remote Code Execution in ClipBucket via Unrestricted File Upload
1 rule 1 TTP 1 CVEAuthenticated users can exploit a file upload vulnerability in ClipBucket v5 before 5.5.3-#182 to achieve remote code execution by bypassing MIME validation.
Remote Code Execution in vLLM LlavaOnevision2 Processor Loader
1 rule 2 TTPs 1 CVEA vulnerability in vLLM versions prior to 0.28.0 allows remote code execution by bypassing the trust_remote_code parameter during the loading of malicious LlavaOnevision2 processor classes.
Apache ActiveMQ Denial of Service and Data Manipulation Vulnerability
1 TTP 1 CVEA vulnerability in Apache ActiveMQ allows a remote, authenticated attacker to perform a denial-of-service attack and manipulate data.
CVE-2026-93488 Denial of Service in Netty SpdySessionHandler
1 CVEThe Netty SpdySessionHandler component is vulnerable to a denial of service attack via uncontrolled concurrent stream allocation, potentially exhausting JVM heap and direct memory.
Resource Exhaustion in RedisArrayAggregator
1 CVEA vulnerability in RedisArrayAggregator allows remote attackers to trigger memory exhaustion via a crafted RESP payload that forces eager allocation of array capacity.
Local Arbitrary Code Execution and Denial of Service Vulnerability in Red Hat CloudForms
1 TTPRed Hat CloudForms contains a local vulnerability that allows an attacker to execute arbitrary code with user-level privileges or trigger a denial-of-service condition.
Denial of Service Vulnerability in libxml2
1 TTP 1 CVEA vulnerability in the libxml2 library allows a remote, unauthenticated attacker to trigger a denial of service condition through the submission of malformed XML data.
Multiple Vulnerabilities in Red Hat Enterprise Linux Components
1 TTP 1 CVEMultiple vulnerabilities in corosync, libevent, and libsoup within Red Hat Enterprise Linux could allow attackers to execute arbitrary code, bypass security controls, disclose data, or cause denial-of-service.
Multiple Vulnerabilities in HCL BigFix
4 TTPsHCL BigFix is affected by multiple security flaws, including RCE, SQL injection, XSS, SSRF, and privilege escalation, which could allow an unauthenticated attacker to compromise the integrity and confidentiality of the platform.
Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic
1 TTP 6 CVEsSynology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.
Credential Exfiltration in AWS AgentCore Harness via Default Shell Tool
2 TTPsDefault configurations in AWS AgentCore Harness enable a root-privileged shell tool that, when combined with prompt injection, allows attackers to exfiltrate plaintext credentials from the agent runtime.