Skip to content
Threat Feed

September 2026 (30)

high advisory

Command Injection in PLANET IGS-5225 Industrial Switches

An OS command injection vulnerability in the web interface of PLANET IGS-5225-8P2T4S switches allows authenticated remote attackers to execute arbitrary commands with root privileges.

IGS-5225-8P2T4S
2t 1c
high advisory

IBM MQ Improper Validation Vulnerability (CVE-2026-11381)

IBM MQ contains a vulnerability in the validation of message distribution list structures that allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.

MQ vulnerability cve middleware
1c
high advisory

XML External Entity Injection in IBM MQ Classes for Java

An XML external entity injection vulnerability (CVE-2026-12666) in IBM MQ Classes for Java allows authenticated attackers to perform denial-of-service attacks or disclose sensitive host information by manipulating MQRFH2 headers.

IBM MQ +1 vulnerability java middleware cve-2026-12666 rce dos
1t 1c updated
high threat

Stack Buffer Overflow in IBM MQ XA Transaction Processing

IBM MQ is vulnerable to a stack buffer overflow triggered by malicious XA transaction identifiers, allowing an authenticated attacker to cause a denial of service or achieve arbitrary code execution.

exploited MQ vulnerability remote-code-execution denial-of-service
1c
high advisory

Vulnerability in IBM MQ Cluster Command Message Validation

IBM MQ contains a vulnerability (CVE-2026-10853) where improper cluster command message length validation allows authenticated attackers to cause a denial of service or remote code execution.

MQ
1c
high advisory

IBM MQ Java and JMS Client Deserialization Vulnerability

An authenticated attacker can execute arbitrary code on client applications by exploiting a deserialization filter bypass in IBM MQ Java and JMS client libraries.

IBM MQ
1t 1c
high advisory

Buffer Overflow Vulnerability in IBM MQ

IBM MQ is vulnerable to a buffer overflow during the processing of malformed compressed data, which can be leveraged by a remote attacker for denial of service or arbitrary code execution.

MQ
2t 1c
high advisory

Path Traversal Vulnerability in IBM Cloud Pak for Data

IBM Cloud Pak for Data 5.1.2 is vulnerable to a path traversal vulnerability via crafted URL requests that allow unauthenticated remote attackers to access arbitrary files on the system.

Cloud Pak for Data vulnerability webserver path-traversal
1t 1c
high advisory

Improper Translation of HTTP/1 CONNECT to HTTP/2 Headers

A vulnerability exists where HTTP/1 authority-form CONNECT requests are incorrectly translated into malformed HTTP/2 CONNECT requests, allowing for attacker control over the :authority header and potential request smuggling.

cve-2026-93567 request-smuggling proxy vulnerability
1c
high advisory

SSRF Vulnerability in ArcadeDB via IPv6 Transition Addressing

Authenticated attackers can exploit a validation flaw in ArcadeDB's SSRF guard to reach internal services or cloud metadata endpoints by using specifically crafted IPv6 transition addresses.

ArcadeDB ssrf vulnerability database access-control
2t 1c
critical threat

Heap Buffer Underflow in IBM MQ for HPE NonStop

IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.

exploited IBM MQ for HPE NonStop vulnerability remote-code-execution ibm-mq critical
1t 1c
medium advisory

CSRF Vulnerability in IBM Common Licensing Agent and ART

IBM Common Licensing Agent and ART versions 9.0 through 9.0.0.2 contain a cross-site request forgery (CSRF) vulnerability that enables unauthenticated attackers to perform unauthorized actions on behalf of an authenticated user.

Common Licensing Agent +1 vulnerability web-security cve
1c
critical advisory

Sandbox Escape in vm2 via NodeVM Configuration Misvalidation

An improper validation of the 'require' configuration in the vm2 Node.js sandbox allows attackers to bypass nesting restrictions and achieve arbitrary code execution by spawning an inner NodeVM with elevated privileges.

vm2 +10 sandbox-escape nodejs code-execution vulnerability rce javascript cve privilege-escalation
6t 1c updated
high advisory

Privilege Escalation in uutils coreutils via Incorrect File Ownership Handling

uutils coreutils versions before 0.10.0 are vulnerable to local privilege escalation due to an race condition in the install utility that preserves setuid/setgid bits when ownership changes fail.

coreutils vulnerability privilege-escalation linux
1t 1c
high advisory

DNSSEC Validation Bypass in hickory-resolver

A vulnerability in hickory-resolver versions prior to 0.26.2 causes the library to ignore bogus DNSSEC proof states, allowing attackers to inject forged DNS records as validated data.

hickory-resolver dnssec vulnerability network-security
1t 1c
high advisory

Improper CRLF Validation in Netty netty-codec-smtp

The netty-codec-smtp component in Netty suffers from insufficient CRLF validation in the SMTP command-name field, representing an incomplete remediation for CVE-2025-59419 that enables potential SMTP command injection or response splitting.

netty-codec-smtp
2c
high advisory

Improper Protocol Downgrade of Extended CONNECT Requests in HTTP/2 and HTTP/3

A vulnerability in HTTP/2 and HTTP/3 protocol handling allows Extended CONNECT requests to be downgraded to regular CONNECT requests, potentially bypassing security policies that rely on Extended CONNECT semantics.

1c
high advisory

Denial of Service Vulnerability in Netty StompSubframeDecoder

A memory leak vulnerability in the Netty StompSubframeDecoder component (CVE-2026-93494) allows remote attackers to cause a Denial of Service by sending malformed STOMP frames.

Netty +1 denial-of-service vulnerability cve-2026-93565 rtsp input-validation
1t 1c
low advisory

Denial of Service via Unbounded Queue Growth in WebSocketServerExtensionHandler

A vulnerability in WebSocketServerExtensionHandler allows an attacker to trigger unbounded per-connection queue growth, leading to resource exhaustion and denial of service.

WebSocketServerExtensionHandler
1t 1c
high advisory

Remote Code Execution in ClipBucket via Unrestricted File Upload

Authenticated users can exploit a file upload vulnerability in ClipBucket v5 before 5.5.3-#182 to achieve remote code execution by bypassing MIME validation.

ClipBucket cve-2026-77929 remote-code-execution file-upload
1r 1t 1c
high advisory

Remote Code Execution in vLLM LlavaOnevision2 Processor Loader

A vulnerability in vLLM versions prior to 0.28.0 allows remote code execution by bypassing the trust_remote_code parameter during the loading of malicious LlavaOnevision2 processor classes.

vLLM +2 remote-code-execution model-inference supply-chain denial-of-service vulnerability
1r 2t 1c updated
medium advisory

Apache ActiveMQ Denial of Service and Data Manipulation Vulnerability

A vulnerability in Apache ActiveMQ allows a remote, authenticated attacker to perform a denial-of-service attack and manipulate data.

ActiveMQ denial-of-service vulnerability messaging
1t 1c updated
low advisory

CVE-2026-93488 Denial of Service in Netty SpdySessionHandler

The Netty SpdySessionHandler component is vulnerable to a denial of service attack via uncontrolled concurrent stream allocation, potentially exhausting JVM heap and direct memory.

Netty denial-of-service java networking
1c
low advisory

Resource Exhaustion in RedisArrayAggregator

A vulnerability in RedisArrayAggregator allows remote attackers to trigger memory exhaustion via a crafted RESP payload that forces eager allocation of array capacity.

RedisArrayAggregator denial-of-service memory-exhaustion redis
1c
medium advisory

Local Arbitrary Code Execution and Denial of Service Vulnerability in Red Hat CloudForms

Red Hat CloudForms contains a local vulnerability that allows an attacker to execute arbitrary code with user-level privileges or trigger a denial-of-service condition.

CloudForms vulnerability local-access red-hat
1t
medium advisory

Denial of Service Vulnerability in libxml2

A vulnerability in the libxml2 library allows a remote, unauthenticated attacker to trigger a denial of service condition through the submission of malformed XML data.

libxml2 denial-of-service vulnerability
1t 1c
low advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux Components

Multiple vulnerabilities in corosync, libevent, and libsoup within Red Hat Enterprise Linux could allow attackers to execute arbitrary code, bypass security controls, disclose data, or cause denial-of-service.

Enterprise Linux +1 vulnerability rhel linux
1t 1c updated
high advisory

Multiple Vulnerabilities in HCL BigFix

HCL BigFix is affected by multiple security flaws, including RCE, SQL injection, XSS, SSRF, and privilege escalation, which could allow an unauthenticated attacker to compromise the integrity and confidentiality of the platform.

BigFix
4t
critical advisory

Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic

Synology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.

DiskStation Manager +7 vulnerability critical remote-code-execution file-read-write dsm file-access synology cve +4
1t 6c
high advisory

Credential Exfiltration in AWS AgentCore Harness via Default Shell Tool

Default configurations in AWS AgentCore Harness enable a root-privileged shell tool that, when combined with prompt injection, allows attackers to exfiltrate plaintext credentials from the agent runtime.

AWS AgentCore Harness agentic-ai cloud-security exfiltration prompt-injection
2t