Skip to content
Threat Feed

September 2026 (30)

high threat

Google Security Updates - September 2026

Roundup of Google security advisories published in September 2026.

roundup
2c updated
low advisory

Denial of Service in go-openapi/swag via Stack Overflow

The go-openapi/swag library is vulnerable to a stack overflow in its jsonutils component, allowing remote unauthenticated attackers to cause a denial-of-service by submitting deeply nested JSON documents.

swag
1c
critical advisory

CVE-2026-87796 - Arbitrary File Upload in Multi Uploader for Gravity Forms

The Multi Uploader for Gravity Forms WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to improper validation in the move_file function, enabling potential remote code execution.

PoC Multi Uploader for Gravity Forms
1t 1c updated
high threat

Microsoft Security Updates - September 2026

Roundup of Microsoft security advisories published in September 2026.

roundup
71c updated
high advisory

Path Traversal Vulnerability in Grav CMS ImageMedium Class

Grav CMS 2.0.10 is vulnerable to path traversal in the ImageMedium::watermark() method, allowing unauthenticated attackers to disclose arbitrary image files by traversing outside the media sandbox.

Grav CMS +1 web-vulnerability twig information-disclosure
1r 2t 1c updated
high advisory

Grav CMS Twig Sandbox Bypass via Configuration Exposure

CVE-2026-92917 allows an authenticated user with page-edit privileges in Grav CMS 2.0.0-rc.1 through 2.0.21 to bypass Twig sandboxing and exfiltrate the full application configuration, including API keys and credentials.

Grav +1 cms web-application security-misconfiguration information-disclosure
3t 1c updated
high advisory

Grav Privilege Escalation via Group Blueprint ACL Bypass

A missing 'security@' guard in Grav's group blueprint allows an 'admin.users' operator to escalate privileges to 'admin.super' by modifying group access configurations.

Grav +2 privilege-escalation cms vulnerability web-application-vulnerability path-traversal cve-2026-74907 twig security-misconfiguration
1r 3t 1c
high advisory

Grav CMS Path Traversal in MediaUploadTrait Leading to Arbitrary File Deletion

An authenticated path traversal vulnerability in Grav CMS's MediaUploadTrait allows users with media management permissions to delete arbitrary files on the server by providing crafted file paths.

Grav CMS +1 grav cms path-traversal cve-2026-72695 file-disclosure web-application
3t 1c
high advisory

Jupyter Server Authentication Token Leak in Error Logs

Jupyter Server versions prior to 2.21.0 inadvertently expose authentication tokens in plain-text 500 error logs due to improper logging of the Referer header.

jupyter_server credential-exposure logging vulnerability
1t 1c
critical advisory

Multi-tenant Isolation Bypass in djust via WebSocket/SSE

A vulnerability in djust caused multi-tenant isolation to fail open on WebSocket and SSE paths, allowing unauthorized cross-tenant data disclosure due to improper tenant context propagation.

djust +1 web-application mass-assignment cve-2026-61598 remote-code-execution information-disclosure cve-2026-61590 idor broken-access-control +5
6t 1c updated
low advisory

Unbounded DEFLATE Decompression Vulnerability in HAPI FHIR

The HAPI FHIR SHCParser component contains an unbounded DEFLATE decompression flaw (CVE-2026-81875) allowing attackers to trigger memory exhaustion and denial-of-service.

HAPI FHIR +1 denial-of-service vulnerability cve-2026-81875
1t 1c
high advisory

CoreDNS DoH/DoQ/gRPC RFC 2136 UPDATE Bypass

CoreDNS versions up to 1.14.6 fail to validate DNS UPDATE opcodes over DoH, DoH3, DoQ, and gRPC, allowing attackers to relay unauthorized updates to upstream servers.

CoreDNS dns vulnerability rfc-2136 denial-of-service cve-2026-82399 networking
1r 3t 1c
low advisory

Denial of Service via Malformed HTTP Chunked Encoding in react/http

A malformed HTTP chunked body triggers an infinite loop in the react/http ChunkedDecoder, causing 100% CPU usage and service disruption in both server and client implementations.

react/http denial-of-service php vulnerability
1t 1c
low advisory

Denial of Service Vulnerability in redis-parser via RESP Recursion

The redis-parser library up to version 3.0.0 is vulnerable to a denial of service attack where crafted RESP byte streams trigger unbounded recursion, exhausting the V8 call stack and crashing the host Node.js process.

redis-parser denial-of-service vulnerability supply-chain
1c
high advisory

Authorization Bypass in SigNoz Trace-Funnel Analytics

SigNoz versions 0.88.0 through 0.141.0 contain an authorization bypass vulnerability allowing unauthenticated remote attackers to query sensitive trace analytics via the trace-funnel endpoint.

SigNoz +2 authorization-bypass api-security observability sql-injection vulnerability web-application webserver injection
2r 1t 1c updated
high advisory

Local Privilege Escalation in NetworkManager-l2tp via pppd Directive Injection

An improper input validation vulnerability in NetworkManager-l2tp (CVE-2026-93337) allows local users with VPN creation permissions to inject malicious directives into the pppd configuration, leading to arbitrary code execution as root.

NetworkManager-l2tp privilege-escalation linux cve
1t 1c
high advisory

Keycloak Stateless Mode Replay Vulnerability (CVE-2026-90997)

A row-count mismatch in Keycloak when using MySQL or MariaDB in stateless mode allows attackers to bypass replay protection for single-use security artifacts like JWT client assertions, DPoP proofs, or TOTP codes.

Keycloak identity-management authentication-bypass vulnerability
1t 1c
high advisory

Out-of-Bounds Read Vulnerability in Redis Cluster Bus

A vulnerability in the Redis cluster bus packet parser allows remote attackers to trigger an out-of-bounds read via crafted PING, PONG, or MEET packets, resulting in potential information disclosure or denial of service.

Redis vulnerability memory-safety denial-of-service
1c
high advisory

Stored XSS in Vendure Admin Dashboard via Unsafe HTML Stripping

A stored Cross-Site Scripting (XSS) vulnerability in the Vendure Admin Dashboard allows authenticated administrators to execute arbitrary JavaScript in the context of other users viewing entity lists, leading to potential account takeover.

Vendure Dashboard xss web-vulnerability dashboard ecommerce
2t 1c
high advisory

Command Injection in @cyclonedx/cyclonedx-npm via --workspace Argument

A command injection vulnerability in @cyclonedx/cyclonedx-npm on Windows allows attackers to execute arbitrary commands by supplying malicious input to the --workspace argument.

@cyclonedx/cyclonedx-npm command-injection supply-chain windows
1r 1t 1c
medium advisory

RabbitMQ Java Client Out-of-Memory Vulnerability via Frame Negotiation

A logic error in the RabbitMQ Java client's frame size negotiation allows a malicious server to trigger a massive memory allocation and service crash by exploiting an integer comparison flaw in frame handling.

amqp-client vulnerability denial-of-service java rabbitmq
1t 1c
medium advisory

Denial of Service via Unhandled Panics in PocketBase Worker Goroutines

PocketBase is susceptible to a denial-of-service vulnerability (CVE-2026-82410) where unhandled panics in internal worker goroutines trigger unexpected server process termination.

PocketBase
1c
high advisory

Broken Access Control in TinaCMS Authorization

A broken access control vulnerability in @tinacms/auth allows attackers to perform unauthorized actions by supplying their own valid TinaCloud credentials against a victim's TinaCMS deployment.

@tinacms/auth +3
2t 1i
high advisory

Umbraco Delivery API Authorization Bypass via Node Expansion

Umbraco CMS contains an authorization bypass vulnerability (CVE-2026-69197) in the Delivery API where protected content is leaked when referenced by an unprotected node through expansion parameters.

Umbraco CMS authorization-bypass api-security umbraco cve-2026-69197
1t 1c
low advisory

ExifReader Denial of Service via Crafted HEIC/AVIF Files

ExifReader version 4.41.0 is susceptible to a heap exhaustion denial-of-service vulnerability due to an unbounded object allocation loop when parsing malicious ISO-BMFF iloc box structures.

exifreader denial-of-service vulnerability memory-exhaustion
1t 1c
high advisory

RestrictedPython Sandbox Escape via string.Formatter

RestrictedPython versions prior to 8.4 are vulnerable to a sandbox escape (CVE-2026-76825) via the string.Formatter module, which can bypass attribute guards to access sensitive objects and primitives.

RestrictedPython sandbox-escape cve-2026-76825 python
2t 1c
critical advisory

Protocol Desynchronization and Frame Injection in RabbitMQ amqp091-go

A critical integer overflow vulnerability in the amqp091-go parser causes protocol desynchronization, allowing remote attackers to inject arbitrary AMQP frames into the network stream.

amqp091-go data-integrity serialization-vulnerability protocol-corruption denial-of-service memory-exhaustion amqp vulnerability credential-exposure +2
5t 1c
medium advisory

Resource Exhaustion in RabbitMQ amqp091-go via Unsafe Integer Casting

The RabbitMQ amqp091-go library contains a vulnerability in its Qos configuration method where signed integer inputs are implicitly cast to unsigned integers, allowing attackers to trigger message flooding and OOM crashes via integer wrap-around.

amqp091-go denial-of-service vulnerability cve
1t 1c
high advisory

Grav CMS Remote Code Execution Vulnerability (CVE-2026-65608)

An authenticated remote code execution vulnerability (CVE-2026-65608) in Grav CMS versions 1.7.0 through 2.0.8 allows attackers with Flex directory create/update permissions to execute arbitrary shell commands due to improper input validation in `FlexDirectory::dynamicDataField()`.

Grav +1 RCE CMS PHP web-exploitation
2r 1t 1c updated
high advisory

Unauthenticated SSRF in Kestra OSS via Pebble http() Function

An unauthenticated SSRF vulnerability in the Kestra OSS Pebble template engine allows remote attackers to perform arbitrary requests to internal network services and cloud metadata endpoints.

Kestra OSS ssrf vulnerability kestra
1r 3t 1c 1i