[{"date":"2026-10-11","title":"Active threat: ProFTPD Improper Access Control Vulnerability","deck":"5 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":27,"criticalCount":7,"activeCount":5,"highCount":5,"items":[{"id":"CVE-2015-3306","type":"CVE","title":"CVE-2015-3306: ProFTPD Improper Access Control Vulnerability","summary":"ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.99497,"epssPercentile":0.99945,"activeExploitation":true,"otRelevance":15,"vendor":"ProFTPD","product":"ProFTPD","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ProFTPD","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2015-3306"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2015-5477","type":"CVE","title":"CVE-2015-5477:  ISC BIND Data Processing Errors Vulnerability","summary":"ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.99409,"epssPercentile":0.99941,"activeExploitation":true,"otRelevance":15,"vendor":"ISC","product":"BIND","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ISC","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2015-5477"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2016-3081","type":"CVE","title":"CVE-2016-3081: Apache Struts Command Injection Vulnerability","summary":"Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.96052,"epssPercentile":0.99877,"activeExploitation":true,"otRelevance":15,"vendor":"Apache","product":"Struts","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Apache","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2016-3081"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2021-3199","type":"CVE","title":"CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability","summary":"ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.19352,"epssPercentile":0.97295,"activeExploitation":true,"otRelevance":15,"vendor":"ONLYOFFICE","product":"Docs","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ONLYOFFICE","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2021-3199"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2023-22894","type":"CVE","title":"CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability","summary":"Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.03609,"epssPercentile":0.89198,"activeExploitation":true,"otRelevance":15,"vendor":"Strapi","product":"Strapi","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Strapi","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2023-22894","CVE-2023-22621"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42696","type":"CVE","title":"CVE-2026-42696: Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.","summary":"Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-42696","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-10T20:16:35.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-42696"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-105892","type":"CVE","title":"CVE-2026-105892: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc","summary":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.7.13.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105892","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-10T19:16:56.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105892"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-106610","type":"CVE","title":"CVE-2026-106610: Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This is","summary":"Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106610","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-10T19:16:57.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-106610"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-108551","type":"CVE","title":"CVE-2026-108551: openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject Java","summary":"openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are imported or service methods called.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108551","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-10T15:16:58.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Transportation"],"cves":["CVE-2026-108551"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-108598","type":"CVE","title":"CVE-2026-108598: Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via un","summary":"Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108598","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-10T19:16:58.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-108598"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-39801","type":"CVE","title":"CVE-2026-39801: Subscriber Privilege Escalation in AIWU <= 1.5.9 versions.","summary":"Subscriber Privilege Escalation in AIWU <= 1.5.9 versions.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-39801","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-10T20:16:33.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-39801"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-104398","type":"CVE","title":"CVE-2026-104398: Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Objec","summary":"Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104398","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-10T17:16:59.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-104398"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-10-10","title":"Active threat: ProFTPD Improper Access Control Vulnerability","deck":"6 confirmed active-exploitation signals, 5 critical items, and 6 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":21,"criticalCount":5,"activeCount":6,"highCount":6,"items":[{"id":"CVE-2015-3306","type":"CVE","title":"CVE-2015-3306: ProFTPD Improper Access Control Vulnerability","summary":"ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.98033,"epssPercentile":0.9991,"activeExploitation":true,"otRelevance":15,"vendor":"ProFTPD","product":"ProFTPD","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ProFTPD","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2015-3306"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2016-3081","type":"CVE","title":"CVE-2016-3081: Apache Struts Command Injection Vulnerability","summary":"Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.94506,"epssPercentile":0.99853,"activeExploitation":true,"otRelevance":15,"vendor":"Apache","product":"Struts","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Apache","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2016-3081"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2015-5477","type":"CVE","title":"CVE-2015-5477:  ISC BIND Data Processing Errors Vulnerability","summary":"ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.91807,"epssPercentile":0.99816,"activeExploitation":true,"otRelevance":15,"vendor":"ISC","product":"BIND","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ISC","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2015-5477"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2021-3199","type":"CVE","title":"CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability","summary":"ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.14548,"epssPercentile":0.96569,"activeExploitation":true,"otRelevance":15,"vendor":"ONLYOFFICE","product":"Docs","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ONLYOFFICE","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2021-3199"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2023-22894","type":"CVE","title":"CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability","summary":"Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.03432,"epssPercentile":0.88629,"activeExploitation":true,"otRelevance":15,"vendor":"Strapi","product":"Strapi","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Strapi","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2023-22894","CVE-2023-22621"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88779","type":"CVE","title":"CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00592,"epssPercentile":0.46673,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-10-04T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88779"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-105278","type":"CVE","title":"CVE-2026-105278: The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use","summary":"The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105278","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-09T15:17:08.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105278"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-100730","type":"CVE","title":"CVE-2026-100730: A service console interface on openPDC and openHistorian deserializes a client-supplied data structure","summary":"A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service ac","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100730","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-09T14:17:09.000Z","tags":["CVE","NVD"],"assetTypes":["Historian"],"purdueLevels":["L3"],"sectors":[],"cves":["CVE-2026-100730"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-108107","type":"CVE","title":"CVE-2026-108107: PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates requ","summary":"PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108107","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-09T15:17:11.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-108107"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-15340","type":"CVE","title":"CVE-2026-15340: lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.","summary":"lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15340","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-09T15:17:13.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-15340"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-108109","type":"CVE","title":"CVE-2026-108109: PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allo","summary":"PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108109","sourceTier":1,"severity":"Critical","cvss":9.1,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-09T15:17:12.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-108109"],"advisoryIds":[],"kevLinked":false},{"id":"cisa-icsa-26-281-03","type":"Vendor Advisory","title":"ICSA-26-281-03: Satel Netco Design","summary":"CISA published an ICS advisory for Satel Netco Design. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-281-03"],"kevLinked":false}]},{"date":"2026-10-09","title":"Active threat: ProFTPD Improper Access Control Vulnerability","deck":"6 confirmed active-exploitation signals, 6 critical items, and 6 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":25,"criticalCount":6,"activeCount":6,"highCount":6,"items":[{"id":"CVE-2015-3306","type":"CVE","title":"CVE-2015-3306: ProFTPD Improper Access Control Vulnerability","summary":"ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.96752,"epssPercentile":0.99887,"activeExploitation":true,"otRelevance":15,"vendor":"ProFTPD","product":"ProFTPD","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ProFTPD","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2015-3306"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2016-3081","type":"CVE","title":"CVE-2016-3081: Apache Struts Command Injection Vulnerability","summary":"Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.93352,"epssPercentile":0.99838,"activeExploitation":true,"otRelevance":15,"vendor":"Apache","product":"Struts","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Apache","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2016-3081"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2015-5477","type":"CVE","title":"CVE-2015-5477:  ISC BIND Data Processing Errors Vulnerability","summary":"ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.91284,"epssPercentile":0.9981,"activeExploitation":true,"otRelevance":15,"vendor":"ISC","product":"BIND","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ISC","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2015-5477"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2021-3199","type":"CVE","title":"CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability","summary":"ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.08215,"epssPercentile":0.9475,"activeExploitation":true,"otRelevance":15,"vendor":"ONLYOFFICE","product":"Docs","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ONLYOFFICE","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2021-3199"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2023-22894","type":"CVE","title":"CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability","summary":"Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01658,"epssPercentile":0.7591,"activeExploitation":true,"otRelevance":15,"vendor":"Strapi","product":"Strapi","region":"Global","publishedAt":"2026-10-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Strapi","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2023-22894","CVE-2023-22621"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88779","type":"CVE","title":"CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00592,"epssPercentile":0.46624,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-10-04T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88779"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93034","type":"CVE","title":"CVE-2026-93034: SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via p","summary":"SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93034","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-08T15:17:57.000Z","tags":["CVE","NVD"],"assetTypes":["Safety instrumented system"],"purdueLevels":["L1"],"sectors":[],"cves":["CVE-2026-93034"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-14269","type":"CVE","title":"CVE-2026-14269: IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a ","summary":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote attacker could overflow the buffer and execute arbitrary code on the system.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14269","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-08T15:17:48.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-14269"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-14502","type":"CVE","title":"CVE-2026-14502: IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remot","summary":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14502","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-08T15:17:49.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-14502"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-14991","type":"CVE","title":"CVE-2026-14991: IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a ","summary":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14991","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-08T14:16:51.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-14991"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-14992","type":"CVE","title":"CVE-2026-14992: IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffe","summary":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14992","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-08T15:17:50.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-14992"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-15762","type":"CVE","title":"CVE-2026-15762: IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remot","summary":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15762","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-08T14:16:51.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-15762"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-10-08","title":"Active threat: Zammad GmbH Zammad Session Fixation Vulnerability","deck":"3 confirmed active-exploitation signals, 9 critical items, and 3 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":21,"criticalCount":9,"activeCount":3,"highCount":3,"items":[{"id":"CVE-2026-102489","type":"CVE","title":"CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability","summary":"Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01396,"epssPercentile":0.71567,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102489","CVE-2026-102490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102490","type":"CVE","title":"CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability","summary":"Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00629,"epssPercentile":0.48517,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102490","CVE-2026-102489"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88779","type":"CVE","title":"CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00592,"epssPercentile":0.46593,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-10-04T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88779"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-70518","type":"CVE","title":"CVE-2025-70518: The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely","summary":"The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-70518","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-07T15:16:53.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Transportation"],"cves":["CVE-2025-70518"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-107204","type":"CVE","title":"CVE-2026-107204: LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting s","summary":"LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107204","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-07T16:17:45.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Transportation"],"cves":["CVE-2026-107204"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2025-70521","type":"CVE","title":"CVE-2025-70521: The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely","summary":"The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-70521","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-07T15:16:55.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Transportation"],"cves":["CVE-2025-70521"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-62252","type":"CVE","title":"CVE-2026-62252: Homer is open source telecom observability software","summary":"Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62252","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-07T17:16:56.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-62252"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-62253","type":"CVE","title":"CVE-2026-62253: Homer is open source telecom observability software","summary":"Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == \"\"`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches the issue.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62253","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-07T17:16:56.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-62253"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-76455","type":"CVE","title":"CVE-2026-76455: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive intern","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76455 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76455","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-07T17:16:57.000Z","tags":["CVE","NVD"],"normalizedVendor":"Cisco","assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-76455"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-107206","type":"CVE","title":"CVE-2026-107206: LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attacker","summary":"LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' cached data.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107206","sourceTier":1,"severity":"Critical","cvss":9.4,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-07T16:17:45.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-107206"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2025-70516","type":"CVE","title":"CVE-2025-70516: The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users","summary":"The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-70516","sourceTier":1,"severity":"Critical","cvss":9.1,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-07T15:16:52.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2025-70516"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-107202","type":"CVE","title":"CVE-2026-107202: A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configura","summary":"A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metacharacters, the application constructs nftables/iptables rule strings using fmt.Sprintf and executes them via bash -c as root. Because the listen field lacks port or format validation, arbitrary OS commands can be injected and executed with root","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107202","sourceTier":1,"severity":"Critical","cvss":9.1,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-07T15:17:20.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-107202"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-10-07","title":"Active threat: Fortinet FortiMail Path Traversal Vulnerability","deck":"4 confirmed active-exploitation signals, 8 critical items, and 4 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":29,"criticalCount":8,"activeCount":4,"highCount":4,"items":[{"id":"CVE-2026-104286","type":"CVE","title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","summary":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02201,"epssPercentile":0.81946,"activeExploitation":true,"otRelevance":15,"vendor":"Fortinet","product":"FortiMail","region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-104286"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102489","type":"CVE","title":"CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability","summary":"Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01396,"epssPercentile":0.71518,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102489","CVE-2026-102490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102490","type":"CVE","title":"CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability","summary":"Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00629,"epssPercentile":0.48437,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102490","CVE-2026-102489"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88779","type":"CVE","title":"CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00592,"epssPercentile":0.4651,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-10-04T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88779"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-63692","type":"CVE","title":"CVE-2026-63692: Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability","summary":"Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63692","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-10-06T15:17:19.000Z","tags":["CVE","NVD"],"assetTypes":["Remote access"],"purdueLevels":["L3","L3.5"],"sectors":[],"cves":["CVE-2026-63692"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-54472","type":"CVE","title":"CVE-2026-54472: Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs","summary":"Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54472","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-10-06T15:17:18.000Z","tags":["CVE","NVD"],"assetTypes":["Remote access"],"purdueLevels":["L3","L3.5"],"sectors":[],"cves":["CVE-2026-54472"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-61421","type":"CVE","title":"CVE-2026-61421: Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization","summary":"Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61421","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-10-06T15:17:18.000Z","tags":["CVE","NVD"],"assetTypes":["Remote access"],"purdueLevels":["L3","L3.5"],"sectors":[],"cves":["CVE-2026-61421"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-67273","type":"CVE","title":"CVE-2026-67273: Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerab","summary":"Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67273","sourceTier":1,"severity":"Critical","cvss":9.6,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-10-06T16:17:09.000Z","tags":["CVE","NVD"],"assetTypes":["Remote access"],"purdueLevels":["L3","L3.5"],"sectors":[],"cves":["CVE-2026-67273"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-105857","type":"CVE","title":"CVE-2026-105857: Payload is a free and open source headless content management system","summary":"Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105857","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-06T17:17:21.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105857"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-63688","type":"CVE","title":"CVE-2026-63688: Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-auth","summary":"Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63688","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-06T15:17:18.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-63688"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-106102","type":"CVE","title":"CVE-2026-106102: Quasar Framework is a framework for building high-performance Vue.js user interfaces","summary":"Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. An attacker who can influence dynamic page metadata, such as a post title, produc","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106102","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-06T17:17:24.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-106102"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-67269","type":"CVE","title":"CVE-2026-67269: Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorag","summary":"Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67269","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-06T15:17:19.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-67269"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-10-06","title":"Active threat: Fortinet FortiMail Path Traversal Vulnerability","deck":"5 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":21,"criticalCount":7,"activeCount":5,"highCount":5,"items":[{"id":"CVE-2026-104286","type":"CVE","title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","summary":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02201,"epssPercentile":0.81917,"activeExploitation":true,"otRelevance":15,"vendor":"Fortinet","product":"FortiMail","region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-104286"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76504","type":"CVE","title":"CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability","summary":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01575,"epssPercentile":0.74601,"activeExploitation":true,"otRelevance":15,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","region":"Global","publishedAt":"2026-09-30T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76504"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102489","type":"CVE","title":"CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability","summary":"Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01396,"epssPercentile":0.71474,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102489","CVE-2026-102490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102490","type":"CVE","title":"CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability","summary":"Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00629,"epssPercentile":0.48354,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102490","CVE-2026-102489"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88779","type":"CVE","title":"CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00534,"epssPercentile":0.43126,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-10-04T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88779"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-105636","type":"CVE","title":"CVE-2026-105636: Plane is an open-source project management tool","summary":"Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105636","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-05T19:17:17.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105636"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-105639","type":"CVE","title":"CVE-2026-105639: Plane is an open-source project management tool","summary":"Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = \"all\", exposing the token that protects the invitation join endpoin","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105639","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-05T19:17:18.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105639"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-105641","type":"CVE","title":"CVE-2026-105641: Plane is an open-source project management tool","summary":"Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET_KEY enables attack","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105641","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-05T19:17:18.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105641"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-88395","type":"CVE","title":"CVE-2026-88395: GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.","summary":"GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88395","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-05T16:17:16.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-88395"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-105640","type":"CVE","title":"CVE-2026-105640: Plane is an open-source project management tool","summary":"Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's ","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105640","sourceTier":1,"severity":"Critical","cvss":9.1,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-10-05T19:17:18.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105640"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-105637","type":"CVE","title":"CVE-2026-105637: Plane is an open-source project management tool","summary":"Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, draft_issue_id, or project_id to an entity the attacker controls. Plane then treat","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105637","sourceTier":1,"severity":"Critical","cvss":9.6,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-05T19:17:17.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105637"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-103352","type":"CVE","title":"CVE-2026-103352: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appoi","summary":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103352","sourceTier":1,"severity":"Critical","cvss":9.3,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-05T19:17:13.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-103352"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-10-05","title":"Active threat: Fortinet FortiMail Path Traversal Vulnerability","deck":"6 confirmed active-exploitation signals, 3 critical items, and 6 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":19,"criticalCount":3,"activeCount":6,"highCount":6,"items":[{"id":"CVE-2026-104286","type":"CVE","title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","summary":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02201,"epssPercentile":0.81912,"activeExploitation":true,"otRelevance":15,"vendor":"Fortinet","product":"FortiMail","region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-104286"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76504","type":"CVE","title":"CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability","summary":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01575,"epssPercentile":0.74593,"activeExploitation":true,"otRelevance":15,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","region":"Global","publishedAt":"2026-09-30T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76504"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102489","type":"CVE","title":"CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability","summary":"Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01396,"epssPercentile":0.71465,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102489","CVE-2026-102490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86950","type":"CVE","title":"CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability","summary":"Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01242,"epssPercentile":0.68153,"activeExploitation":true,"otRelevance":15,"vendor":"Apple","product":"Multiple Products","region":"Global","publishedAt":"2026-09-29T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Apple","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86950"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102490","type":"CVE","title":"CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability","summary":"Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00629,"epssPercentile":0.48333,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102490","CVE-2026-102489"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88779","type":"CVE","title":"CVE-2026-88779: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00276,"epssPercentile":0.18203,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-10-04T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88779"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-105207","type":"CVE","title":"CVE-2026-105207: ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary f","summary":"ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105207","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-10-04T15:16:31.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105207"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-105215","type":"CVE","title":"CVE-2026-105215: ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' regis","summary":"ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105215","sourceTier":1,"severity":"Critical","cvss":9.1,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-10-04T15:16:32.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105215"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-105209","type":"CVE","title":"CVE-2026-105209: ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment code","summary":"ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105209","sourceTier":1,"severity":"Critical","cvss":9.6,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-04T15:16:32.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105209"],"advisoryIds":[],"kevLinked":false},{"id":"cisa-icsa-26-254-01","type":"Vendor Advisory","title":"ICSA-26-254-01: CISA Malcolm","summary":"CISA published an ICS advisory for CISA Malcolm. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-254-01"],"kevLinked":false},{"id":"cisa-icsa-26-274-05","type":"Vendor Advisory","title":"ICSA-26-274-05: Johnson Controls EasyIO Neo Series EC and CW Controllers","summary":"CISA published an ICS advisory for Johnson Controls EasyIO Neo Series EC and CW Controllers. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-274-05"],"kevLinked":false},{"id":"cisa-icsa-26-274-06","type":"Vendor Advisory","title":"ICSA-26-274-06: Meari IoT Cloud Platform OpenAPI Service","summary":"CISA published an ICS advisory for Meari IoT Cloud Platform OpenAPI Service. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-274-06"],"kevLinked":false}]},{"date":"2026-10-04","title":"Active threat: Fortinet FortiMail Path Traversal Vulnerability","deck":"5 confirmed active-exploitation signals, 3 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":18,"criticalCount":3,"activeCount":5,"highCount":5,"items":[{"id":"CVE-2026-104286","type":"CVE","title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","summary":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02201,"epssPercentile":0.81912,"activeExploitation":true,"otRelevance":15,"vendor":"Fortinet","product":"FortiMail","region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-104286"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76504","type":"CVE","title":"CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability","summary":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01575,"epssPercentile":0.74593,"activeExploitation":true,"otRelevance":15,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","region":"Global","publishedAt":"2026-09-30T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76504"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102489","type":"CVE","title":"CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability","summary":"Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01396,"epssPercentile":0.71464,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102489","CVE-2026-102490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86950","type":"CVE","title":"CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability","summary":"Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01242,"epssPercentile":0.68155,"activeExploitation":true,"otRelevance":15,"vendor":"Apple","product":"Multiple Products","region":"Global","publishedAt":"2026-09-29T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Apple","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86950"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102490","type":"CVE","title":"CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability","summary":"Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00629,"epssPercentile":0.48335,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102490","CVE-2026-102489"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-105135","type":"CVE","title":"CVE-2026-105135: A vulnerability has been found in InternLM MindSearch 0.1.0","summary":"A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105135","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-04T07:16:33.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105135"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-105134","type":"CVE","title":"CVE-2026-105134: A flaw has been found in Ahsay AhsayCBS up to 10.3.2","summary":"A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105134","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-04T07:16:33.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-105134"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-103355","type":"CVE","title":"CVE-2026-103355: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elemen","summary":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103355","sourceTier":1,"severity":"Critical","cvss":9.3,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-04T09:16:38.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-103355"],"advisoryIds":[],"kevLinked":false},{"id":"cisa-icsa-26-274-04","type":"Vendor Advisory","title":"ICSA-26-274-04: Johnson Controls EasyIO Neo Series EC and CW Controllers","summary":"CISA published an ICS advisory for Johnson Controls EasyIO Neo Series EC and CW Controllers. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-274-04"],"kevLinked":false},{"id":"cisa-icsa-26-254-01","type":"Vendor Advisory","title":"ICSA-26-254-01: CISA Malcolm","summary":"CISA published an ICS advisory for CISA Malcolm. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-254-01"],"kevLinked":false},{"id":"cisa-icsa-26-274-05","type":"Vendor Advisory","title":"ICSA-26-274-05: Johnson Controls EasyIO Neo Series EC and CW Controllers","summary":"CISA published an ICS advisory for Johnson Controls EasyIO Neo Series EC and CW Controllers. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-274-05"],"kevLinked":false},{"id":"cisa-icsa-26-274-06","type":"Vendor Advisory","title":"ICSA-26-274-06: Meari IoT Cloud Platform OpenAPI Service","summary":"CISA published an ICS advisory for Meari IoT Cloud Platform OpenAPI Service. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-274-06"],"kevLinked":false}]},{"date":"2026-10-03","title":"Active threat: Fortinet FortiMail Path Traversal Vulnerability","deck":"7 confirmed active-exploitation signals, 5 critical items, and 7 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":26,"criticalCount":5,"activeCount":7,"highCount":7,"items":[{"id":"CVE-2026-104286","type":"CVE","title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","summary":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01779,"epssPercentile":0.77459,"activeExploitation":true,"otRelevance":15,"vendor":"Fortinet","product":"FortiMail","region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-104286"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76504","type":"CVE","title":"CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability","summary":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01575,"epssPercentile":0.74572,"activeExploitation":true,"otRelevance":15,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","region":"Global","publishedAt":"2026-09-30T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76504"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88772","type":"CVE","title":"CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01301,"epssPercentile":0.69447,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88772"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86950","type":"CVE","title":"CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability","summary":"Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01242,"epssPercentile":0.6813,"activeExploitation":true,"otRelevance":15,"vendor":"Apple","product":"Multiple Products","region":"Global","publishedAt":"2026-09-29T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Apple","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86950"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88771","type":"CVE","title":"CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01063,"epssPercentile":0.63433,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88771"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102489","type":"CVE","title":"CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability","summary":"Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00582,"epssPercentile":0.45835,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102489","CVE-2026-102490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102490","type":"CVE","title":"CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability","summary":"Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00262,"epssPercentile":0.16336,"activeExploitation":true,"otRelevance":15,"vendor":"Zammad GmbH","product":"Zammad","region":"Global","publishedAt":"2026-10-02T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zammad GmbH","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-102490","CVE-2026-102489"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-103956","type":"CVE","title":"CVE-2026-103956: Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin","summary":"Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured.\n\n\n\nTo remediate this issue, users should upgrad","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103956","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-10-02T19:16:39.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-103956"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-90970","type":"CVE","title":"CVE-2026-90970: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 befo","summary":"GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90970","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-02T15:17:12.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-90970"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-19652","type":"CVE","title":"CVE-2026-19652: The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0","summary":"The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new ","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19652","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-02T14:17:10.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-19652"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-104846","type":"CVE","title":"CVE-2026-104846: Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities","summary":"Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104846","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-02T16:16:47.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-104846"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2023-54405","type":"CVE","title":"CVE-2023-54405: H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability ","summary":"H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token parameter to upload a malicious JSP file into a web-accessible directory and then ","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-54405","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-02T19:16:38.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2023-54405"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-10-02","title":"Active threat: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","deck":"5 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":26,"criticalCount":7,"activeCount":5,"highCount":5,"items":[{"id":"CVE-2026-88772","type":"CVE","title":"CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01301,"epssPercentile":0.69413,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88772"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86950","type":"CVE","title":"CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability","summary":"Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01242,"epssPercentile":0.68097,"activeExploitation":true,"otRelevance":15,"vendor":"Apple","product":"Multiple Products","region":"Global","publishedAt":"2026-09-29T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Apple","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86950"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76504","type":"CVE","title":"CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability","summary":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01096,"epssPercentile":0.64334,"activeExploitation":true,"otRelevance":15,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","region":"Global","publishedAt":"2026-09-30T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76504"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88771","type":"CVE","title":"CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01063,"epssPercentile":0.63393,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88771"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-104286","type":"CVE","title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","summary":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Fortinet","product":"FortiMail","region":"Global","publishedAt":"2026-10-01T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-104286"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-79901","type":"CVE","title":"CVE-2026-79901: In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable","summary":"In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79901","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-10-01T14:17:30.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-79901"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-96658","type":"CVE","title":"CVE-2026-96658: A flaw was found in Foreman","summary":"A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96658","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-01T17:17:34.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-96658"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-59797","type":"CVE","title":"CVE-2026-59797: Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache ","summary":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59797","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-01T17:17:29.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-59797"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-57941","type":"CVE","title":"CVE-2026-57941: Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.","summary":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57941","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-01T17:17:27.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-57941"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-56154","type":"CVE","title":"CVE-2026-56154: Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: fro","summary":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56154","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-01T17:17:26.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-56154"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-12627","type":"CVE","title":"CVE-2026-12627: Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd","summary":"Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12627","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-01T16:17:40.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-12627"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-103752","type":"CVE","title":"CVE-2026-103752: Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.","summary":"Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103752","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-10-01T15:17:29.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-103752"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-10-01","title":"Active threat: WordPress Core Remote File Inclusion Vulnerability","deck":"7 confirmed active-exploitation signals, 4 critical items, and 7 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":18,"criticalCount":4,"activeCount":7,"highCount":7,"items":[{"id":"CVE-2026-87902","type":"CVE","title":"CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability","summary":"WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.19756,"epssPercentile":0.97324,"activeExploitation":true,"otRelevance":15,"vendor":"WordPress","product":"Core","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WordPress","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87902"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-65660","type":"CVE","title":"CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability","summary":"Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02101,"epssPercentile":0.80979,"activeExploitation":true,"otRelevance":15,"vendor":"Microsoft","product":"SharePoint","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-65660"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88772","type":"CVE","title":"CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01301,"epssPercentile":0.6933,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88772"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88771","type":"CVE","title":"CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01063,"epssPercentile":0.63292,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88771"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67279","type":"CVE","title":"CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","summary":"Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01027,"epssPercentile":0.62212,"activeExploitation":true,"otRelevance":15,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67279","CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86950","type":"CVE","title":"CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability","summary":"Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00812,"epssPercentile":0.55295,"activeExploitation":true,"otRelevance":15,"vendor":"Apple","product":"Multiple Products","region":"Global","publishedAt":"2026-09-29T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Apple","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86950"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76504","type":"CVE","title":"CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability","summary":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","region":"Global","publishedAt":"2026-09-30T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76504"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-102427","type":"CVE","title":"CVE-2026-102427: Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the com","summary":"Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and co","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102427","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-30T16:17:06.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-102427"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-82307","type":"CVE","title":"CVE-2026-82307: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL","summary":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection.\n\nThis issue affects SOPLOG: before Soplog 2026.9.4.1.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82307","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-30T14:17:31.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-82307"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-103395","type":"CVE","title":"CVE-2026-103395: LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied ar","summary":"LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103395","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-30T15:22:27.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Transportation"],"cves":["CVE-2026-103395"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-18782","type":"CVE","title":"CVE-2026-18782: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc","summary":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.\n\nThis issue affects Trex MES: through 2026-09-29.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18782","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-30T15:22:30.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Critical manufacturing"],"cves":["CVE-2026-18782"],"advisoryIds":[],"kevLinked":false},{"id":"cisa-icsa-26-272-07","type":"Vendor Advisory","title":"ICSA-26-272-07: Viidure Dashcam Android Application","summary":"CISA published an ICS advisory for Viidure Dashcam Android Application. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-09-29T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-272-07"],"kevLinked":false}]},{"date":"2026-09-30","title":"Active threat: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","deck":"8 confirmed active-exploitation signals, 2 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":20,"criticalCount":2,"activeCount":8,"highCount":8,"items":[{"id":"CVE-2026-71362","type":"CVE","title":"CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","summary":"Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.87507,"epssPercentile":0.99754,"activeExploitation":true,"otRelevance":15,"vendor":"Adobe","product":"Commerce and Magento ","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Adobe","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-71362"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87902","type":"CVE","title":"CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability","summary":"WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.19756,"epssPercentile":0.97324,"activeExploitation":true,"otRelevance":15,"vendor":"WordPress","product":"Core","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WordPress","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87902"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-65660","type":"CVE","title":"CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability","summary":"Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02101,"epssPercentile":0.80979,"activeExploitation":true,"otRelevance":15,"vendor":"Microsoft","product":"SharePoint","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-65660"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88772","type":"CVE","title":"CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01301,"epssPercentile":0.6933,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88772"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88771","type":"CVE","title":"CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01063,"epssPercentile":0.63292,"activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88771"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67279","type":"CVE","title":"CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","summary":"Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01027,"epssPercentile":0.62212,"activeExploitation":true,"otRelevance":15,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67279","CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86950","type":"CVE","title":"CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability","summary":"Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00812,"epssPercentile":0.55295,"activeExploitation":true,"otRelevance":15,"vendor":"Apple","product":"Multiple Products","region":"Global","publishedAt":"2026-09-29T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Apple","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86950"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-5430","type":"CVE","title":"CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability ","summary":"WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00588,"epssPercentile":0.46006,"activeExploitation":true,"otRelevance":15,"vendor":"WSO2","product":"Multiple Products","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WSO2","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-5430"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2023-54400","type":"CVE","title":"CVE-2023-54400: Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject ar","summary":"Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidenc","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-54400","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-29T16:17:04.000Z","tags":["CVE","NVD"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2023-54400"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-77177","type":"CVE","title":"CVE-2026-77177: Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injecti","summary":"Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77177","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-29T16:17:11.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-77177"],"advisoryIds":[],"kevLinked":false},{"id":"cisa-icsa-26-272-06","type":"Vendor Advisory","title":"ICSA-26-272-06: MikroTik RouterOS","summary":"CISA published an ICS advisory for MikroTik RouterOS. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-09-29T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-272-06"],"kevLinked":false},{"id":"cisa-icsa-26-272-07","type":"Vendor Advisory","title":"ICSA-26-272-07: Viidure Dashcam Android Application","summary":"CISA published an ICS advisory for Viidure Dashcam Android Application. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-09-29T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-272-07"],"kevLinked":false}]},{"date":"2026-09-29","title":"Active threat: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","deck":"7 confirmed active-exploitation signals, 5 critical items, and 7 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":24,"criticalCount":5,"activeCount":7,"highCount":7,"items":[{"id":"CVE-2026-88772","type":"CVE","title":"CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88772"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-65660","type":"CVE","title":"CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability","summary":"Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Microsoft","product":"SharePoint","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-65660"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67279","type":"CVE","title":"CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","summary":"Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67279","CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-71362","type":"CVE","title":"CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","summary":"Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Adobe","product":"Commerce and Magento ","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Adobe","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-71362"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87902","type":"CVE","title":"CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability","summary":"WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"WordPress","product":"Core","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WordPress","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87902"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88771","type":"CVE","title":"CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88771"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-5430","type":"CVE","title":"CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability ","summary":"WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"WSO2","product":"Multiple Products","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WSO2","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-5430"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-101075","type":"CVE","title":"CVE-2026-101075: A security vulnerability has been detected in Netcore NR289-GE 1.4.5102","summary":"A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101075","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-28T15:17:13.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-101075"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-101076","type":"CVE","title":"CVE-2026-101076: A vulnerability was detected in Netcore NR289-GE 1.4.5102","summary":"A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101076","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-28T16:17:11.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-101076"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-101077","type":"CVE","title":"CVE-2026-101077: A flaw has been found in Netcore NR289-GE 1.4.5102","summary":"A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101077","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-28T16:17:12.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-101077"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-101072","type":"CVE","title":"CVE-2026-101072: A vulnerability was identified in Netcore NR289-GE 1.4.5102","summary":"A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101072","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-28T14:17:13.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-101072"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-85526","type":"CVE","title":"CVE-2026-85526: Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to ","summary":"Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85526","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-28T14:17:20.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Transportation"],"cves":["CVE-2026-85526"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-28","title":"Active threat: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","deck":"11 confirmed active-exploitation signals, 1 critical item, and 11 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":31,"criticalCount":1,"activeCount":11,"highCount":11,"items":[{"id":"CVE-2026-71362","type":"CVE","title":"CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","summary":"Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.87507,"epssPercentile":0.99754,"activeExploitation":true,"otRelevance":15,"vendor":"Adobe","product":"Commerce and Magento ","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Adobe","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-71362"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85102","type":"CVE","title":"CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability","summary":"Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00988,"epssPercentile":0.60982,"activeExploitation":true,"otRelevance":36,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-85102"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93616","type":"CVE","title":"CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability","summary":"Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.19654,"epssPercentile":0.97309,"activeExploitation":true,"otRelevance":15,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93616"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87902","type":"CVE","title":"CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability","summary":"WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.18166,"epssPercentile":0.97112,"activeExploitation":true,"otRelevance":15,"vendor":"WordPress","product":"Core","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WordPress","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87902"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-94127","type":"CVE","title":"CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability","summary":"F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02226,"epssPercentile":0.82035,"activeExploitation":true,"otRelevance":15,"vendor":"F5","product":"BIG-IP APM","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"F5","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-94127"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-65660","type":"CVE","title":"CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability","summary":"Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02101,"epssPercentile":0.80969,"activeExploitation":true,"otRelevance":15,"vendor":"Microsoft","product":"SharePoint","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-65660"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93952","type":"CVE","title":"CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability","summary":"Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01062,"epssPercentile":0.63214,"activeExploitation":true,"otRelevance":15,"vendor":"Arista","product":"VeloCloud Orchestrator","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Arista","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93952"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67279","type":"CVE","title":"CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","summary":"Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01027,"epssPercentile":0.62194,"activeExploitation":true,"otRelevance":15,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67279","CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-5430","type":"CVE","title":"CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability ","summary":"WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00588,"epssPercentile":0.45981,"activeExploitation":true,"otRelevance":15,"vendor":"WSO2","product":"Multiple Products","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WSO2","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-5430"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88771","type":"CVE","title":"CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88771"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-88772","type":"CVE","title":"CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-27T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-88772"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-101090","type":"CVE","title":"CVE-2026-101090: Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint","summary":"Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to begin OAuth2 login via a request that reaches Nezha with a forged Host header can","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101090","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-09-27T21:17:03.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-101090"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-27","title":"Active threat: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","deck":"10 confirmed active-exploitation signals, 0 critical items, and 10 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":20,"criticalCount":0,"activeCount":10,"highCount":10,"items":[{"id":"CVE-2026-71362","type":"CVE","title":"CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","summary":"Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.87507,"epssPercentile":0.99754,"activeExploitation":true,"otRelevance":15,"vendor":"Adobe","product":"Commerce and Magento ","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Adobe","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-71362"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85102","type":"CVE","title":"CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability","summary":"Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00988,"epssPercentile":0.60969,"activeExploitation":true,"otRelevance":36,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-85102"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93616","type":"CVE","title":"CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability","summary":"Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.19654,"epssPercentile":0.97308,"activeExploitation":true,"otRelevance":15,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93616"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87902","type":"CVE","title":"CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability","summary":"WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.18166,"epssPercentile":0.97111,"activeExploitation":true,"otRelevance":15,"vendor":"WordPress","product":"Core","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WordPress","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87902"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-7273","type":"CVE","title":"CVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability","summary":"Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02501,"epssPercentile":0.84075,"activeExploitation":true,"otRelevance":15,"vendor":"Zyxel","product":"GS1900 Series Switches","region":"Global","publishedAt":"2026-09-21T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zyxel","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-7273"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-94127","type":"CVE","title":"CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability","summary":"F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02226,"epssPercentile":0.82028,"activeExploitation":true,"otRelevance":15,"vendor":"F5","product":"BIG-IP APM","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"F5","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-94127"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-65660","type":"CVE","title":"CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability","summary":"Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02101,"epssPercentile":0.80962,"activeExploitation":true,"otRelevance":15,"vendor":"Microsoft","product":"SharePoint","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-65660"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67279","type":"CVE","title":"CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","summary":"Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01027,"epssPercentile":0.62179,"activeExploitation":true,"otRelevance":15,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67279","CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93952","type":"CVE","title":"CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability","summary":"Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00895,"epssPercentile":0.579,"activeExploitation":true,"otRelevance":15,"vendor":"Arista","product":"VeloCloud Orchestrator","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Arista","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93952"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-5430","type":"CVE","title":"CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability ","summary":"WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00588,"epssPercentile":0.45955,"activeExploitation":true,"otRelevance":15,"vendor":"WSO2","product":"Multiple Products","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WSO2","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-5430"],"advisoryIds":[],"kevLinked":true},{"id":"cisa-icsa-26-267-01","type":"Vendor Advisory","title":"ICSA-26-267-01: Botslab G980H Dashcams","summary":"CISA published an ICS advisory for Botslab G980H Dashcams. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-267-01"],"kevLinked":false},{"id":"cisa-icsa-26-267-02","type":"Vendor Advisory","title":"ICSA-26-267-02: Eufy Omni C20, Omni X10 Pro","summary":"CISA published an ICS advisory for Eufy Omni C20, Omni X10 Pro. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-267-02"],"kevLinked":false}]},{"date":"2026-09-26","title":"Active threat: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","deck":"10 confirmed active-exploitation signals, 2 critical items, and 10 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":29,"criticalCount":2,"activeCount":10,"highCount":10,"items":[{"id":"CVE-2026-71362","type":"CVE","title":"CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","summary":"Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.89616,"epssPercentile":0.99783,"activeExploitation":true,"otRelevance":15,"vendor":"Adobe","product":"Commerce and Magento ","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Adobe","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-71362"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85102","type":"CVE","title":"CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability","summary":"Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00988,"epssPercentile":0.60904,"activeExploitation":true,"otRelevance":36,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-85102"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93616","type":"CVE","title":"CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability","summary":"Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.19654,"epssPercentile":0.97303,"activeExploitation":true,"otRelevance":15,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93616"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87902","type":"CVE","title":"CVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability","summary":"WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02877,"epssPercentile":0.86275,"activeExploitation":true,"otRelevance":15,"vendor":"WordPress","product":"Core","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WordPress","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87902"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-94127","type":"CVE","title":"CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability","summary":"F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02226,"epssPercentile":0.81996,"activeExploitation":true,"otRelevance":15,"vendor":"F5","product":"BIG-IP APM","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"F5","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-94127"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-7273","type":"CVE","title":"CVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability","summary":"Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01286,"epssPercentile":0.68909,"activeExploitation":true,"otRelevance":15,"vendor":"Zyxel","product":"GS1900 Series Switches","region":"Global","publishedAt":"2026-09-21T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zyxel","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-7273"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-65660","type":"CVE","title":"CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability","summary":"Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01221,"epssPercentile":0.6743,"activeExploitation":true,"otRelevance":15,"vendor":"Microsoft","product":"SharePoint","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-65660"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93952","type":"CVE","title":"CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability","summary":"Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00895,"epssPercentile":0.57824,"activeExploitation":true,"otRelevance":15,"vendor":"Arista","product":"VeloCloud Orchestrator","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Arista","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93952"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67279","type":"CVE","title":"CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","summary":"Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0071,"epssPercentile":0.51535,"activeExploitation":true,"otRelevance":15,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-25T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67279","CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-5430","type":"CVE","title":"CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability ","summary":"WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0058,"epssPercentile":0.45384,"activeExploitation":true,"otRelevance":15,"vendor":"WSO2","product":"Multiple Products","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WSO2","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-5430"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-92161","type":"CVE","title":"CVE-2026-92161: FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers","summary":"FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing the address to Flarum core as trusted through provideTrustedEmail(). When Discord sign-in is enabled, an unauthenticated attacker who knows the email address of a Flarum user can configure a Discord account with that unverified address","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92161","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-09-25T16:17:29.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-92161"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-100075","type":"CVE","title":"CVE-2026-100075: In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters\n\nWhen srpt_alloc_rw_ctxs() fa","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters\n\nWhen srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect\ndescriptor, the unwind path destroys RDMA contexts but leaves stale\nn_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later\nsq_wr_avail accounting in srpt_queue_response() or srpt_write_pending()\ncan then subtract the wrong number of send queue credits.\n\nReset the counters a","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100075","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-25T14:17:14.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-100075"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-25","title":"Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability","deck":"7 confirmed active-exploitation signals, 4 critical items, and 7 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":22,"criticalCount":4,"activeCount":7,"highCount":7,"items":[{"id":"CVE-2026-85102","type":"CVE","title":"CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability","summary":"Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00988,"epssPercentile":0.60847,"activeExploitation":true,"otRelevance":36,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-85102"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93616","type":"CVE","title":"CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability","summary":"Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02421,"epssPercentile":0.8347,"activeExploitation":true,"otRelevance":15,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93616"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-71362","type":"CVE","title":"CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability ","summary":"Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02335,"epssPercentile":0.82839,"activeExploitation":true,"otRelevance":15,"vendor":"Adobe","product":"Commerce and Magento ","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Adobe","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-71362"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-94127","type":"CVE","title":"CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability","summary":"F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01293,"epssPercentile":0.69016,"activeExploitation":true,"otRelevance":15,"vendor":"F5","product":"BIG-IP APM","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"F5","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-94127"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-7273","type":"CVE","title":"CVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability","summary":"Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01286,"epssPercentile":0.68864,"activeExploitation":true,"otRelevance":15,"vendor":"Zyxel","product":"GS1900 Series Switches","region":"Global","publishedAt":"2026-09-21T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zyxel","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-7273"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93952","type":"CVE","title":"CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability","summary":"Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00895,"epssPercentile":0.57763,"activeExploitation":true,"otRelevance":15,"vendor":"Arista","product":"VeloCloud Orchestrator","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Arista","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93952"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-5430","type":"CVE","title":"CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability ","summary":"WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.  Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00374,"epssPercentile":0.28583,"activeExploitation":true,"otRelevance":15,"vendor":"WSO2","product":"Multiple Products","region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"WSO2","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-5430"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-97360","type":"CVE","title":"CVE-2026-97360: HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, a","summary":"HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, an","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97360","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-24T14:18:22.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-97360"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-97359","type":"CVE","title":"CVE-2026-97359: HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to ac","summary":"HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97359","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-24T14:18:22.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-97359"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-93207","type":"CVE","title":"CVE-2026-93207: In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry\n\nsvcauth_gs","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry\n\nsvcauth_gss_decode_credbody() writes the caller's\nrpc_gss_wire_cred field by field and assigns gc_ctx.len only on\nthe success tail.  The caller storage is svcdata->clcred, which\nlives in the per-svc_rqst gss_svc_data and is reused across\nrequests.  Early decode failures leave partially decoded state\nmixed with residue from the prior reque","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93207","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-24T16:17:15.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-93207"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-81549","type":"CVE","title":"CVE-2026-81549: IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of ","summary":"IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81549","sourceTier":1,"severity":"Critical","cvss":9.6,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-24T15:17:39.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-81549"],"advisoryIds":[],"kevLinked":false},{"id":"cisa-icsa-26-267-02","type":"Vendor Advisory","title":"ICSA-26-267-02: Eufy Omni C20, Omni X10 Pro","summary":"CISA published an ICS advisory for Eufy Omni C20, Omni X10 Pro. Confirm affected products and versions in the source, then evaluate exposure and maintenance-window constraints before applying vendor remediation.","sourceName":"CISA ICS Advisories","sourceUrl":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02","sourceTier":1,"severity":"Info","activeExploitation":false,"otRelevance":75,"region":"Global","publishedAt":"2026-09-24T12:00:00.000Z","tags":["CISA ICS","OT Advisory","Primary Source"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":[],"advisoryIds":["ICSA-26-267-02"],"kevLinked":false}]},{"date":"2026-09-24","title":"Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability","deck":"8 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":31,"criticalCount":4,"activeCount":8,"highCount":8,"items":[{"id":"CVE-2026-85102","type":"CVE","title":"CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability","summary":"Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0066,"epssPercentile":0.50214,"activeExploitation":true,"otRelevance":36,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-85102"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93616","type":"CVE","title":"CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability","summary":"Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02422,"epssPercentile":0.8348,"activeExploitation":true,"otRelevance":15,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93616"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-7273","type":"CVE","title":"CVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability","summary":"Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0241,"epssPercentile":0.83386,"activeExploitation":true,"otRelevance":15,"vendor":"Zyxel","product":"GS1900 Series Switches","region":"Global","publishedAt":"2026-09-21T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zyxel","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-7273"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39682","type":"CVE","title":"CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability","summary":"Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0203,"epssPercentile":0.80202,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2025-39682"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-94127","type":"CVE","title":"CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability","summary":"F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01391,"epssPercentile":0.71171,"activeExploitation":true,"otRelevance":15,"vendor":"F5","product":"BIG-IP APM","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"F5","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-94127"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39964","type":"CVE","title":"CVE-2025-39964: Linux Kernel Race Condition Vulnerability","summary":"Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0079,"epssPercentile":0.54784,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation","Safety instrumented system"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-39964"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93952","type":"CVE","title":"CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability","summary":"Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00741,"epssPercentile":0.53212,"activeExploitation":true,"otRelevance":15,"vendor":"Arista","product":"VeloCloud Orchestrator","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Arista","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93952"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-53266","type":"CVE","title":"CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability","summary":"Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00276,"epssPercentile":0.20235,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-53266"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85724","type":"CVE","title":"CVE-2026-85724: Moquette is a lightweight Java MQTT broker","summary":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the result as an MQTT topic filter. A client that uses + or # in either identity can broaden the substituted filter and gain cross-tenant read and write access. A # identity can also produce an invalid filter that triggers a NullPointerE","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85724","sourceTier":1,"severity":"Critical","cvss":9.6,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-09-23T17:17:17.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-85724"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-59167","type":"CVE","title":"CVE-2026-59167: SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies","summary":"SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59167","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-23T14:17:07.000Z","tags":["CVE","NVD"],"assetTypes":["Safety instrumented system"],"purdueLevels":["L1"],"sectors":[],"cves":["CVE-2026-59167"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-86708","type":"CVE","title":"CVE-2026-86708: ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the ","summary":"ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86708","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-23T14:17:09.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-86708"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-96560","type":"CVE","title":"CVE-2026-96560: LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes ","summary":"LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96560","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-23T14:17:11.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-96560"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-23","title":"Active threat: Check Point Multiple Products Improper Certificate Validation Vulnerability","deck":"8 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":37,"criticalCount":4,"activeCount":8,"highCount":8,"items":[{"id":"CVE-2026-85102","type":"CVE","title":"CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability","summary":"Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00329,"epssPercentile":0.26293,"activeExploitation":true,"otRelevance":36,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-85102"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39682","type":"CVE","title":"CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability","summary":"Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0203,"epssPercentile":0.80179,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2025-39682"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-7273","type":"CVE","title":"CVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability","summary":"Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01987,"epssPercentile":0.7972,"activeExploitation":true,"otRelevance":15,"vendor":"Zyxel","product":"GS1900 Series Switches","region":"Global","publishedAt":"2026-09-21T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zyxel","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-7273"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39964","type":"CVE","title":"CVE-2025-39964: Linux Kernel Race Condition Vulnerability","summary":"Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0079,"epssPercentile":0.54744,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation","Safety instrumented system"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-39964"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93952","type":"CVE","title":"CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability","summary":"Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00424,"epssPercentile":0.36318,"activeExploitation":true,"otRelevance":15,"vendor":"Arista","product":"VeloCloud Orchestrator","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Arista","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93952"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-53266","type":"CVE","title":"CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability","summary":"Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00276,"epssPercentile":0.20229,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-53266"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93616","type":"CVE","title":"CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability","summary":"Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Check Point","product":"Multiple Products","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Check Point","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93616"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-94127","type":"CVE","title":"CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability","summary":"F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"F5","product":"BIG-IP APM","region":"Global","publishedAt":"2026-09-22T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"F5","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-94127"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-93088","type":"CVE","title":"CVE-2026-93088: SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's Di","summary":"SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and passes the final frame of received multipart messages directly to pickle.loads() before any validation occurs.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93088","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":22,"region":"Global","publishedAt":"2026-09-22T15:17:21.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-93088"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-80155","type":"CVE","title":"CVE-2026-80155: Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an a","summary":"Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal upload endpoint that allows unauthenticated attackers to read sensitive configuration files and upload files to arbitrary filesystem locations, leading to remote code execution. The web configuration server constructs the session cookie file path using snprintf with","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80155","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-22T16:18:01.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Transportation"],"cves":["CVE-2026-80155"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-80144","type":"CVE","title":"CVE-2026-80144: Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a co","summary":"Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom write command that passes unsanitized user input to a system() call. Attackers can authenticate as any user to the terminal or CLI interface and inject malicious commands through ","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80144","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-22T16:17:59.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-80144"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-80143","type":"CVE","title":"CVE-2026-80143: Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a co","summary":"Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom read command that passes unsanitized user input to a system() call. Attackers can authenticate as any user to the terminal or CLI interface and inject malicious commands through t","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80143","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":15,"region":"Global","publishedAt":"2026-09-22T16:17:57.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-80143"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-22","title":"Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","deck":"7 confirmed active-exploitation signals, 3 critical items, and 9 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":40,"criticalCount":3,"activeCount":7,"highCount":9,"items":[{"id":"CVE-2026-76460","type":"CVE","title":"CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","summary":"Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00784,"epssPercentile":0.54107,"activeExploitation":true,"otRelevance":58,"vendor":"Cisco","product":"Identity Services Engine","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76460"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-7273","type":"CVE","title":"CVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability","summary":"Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00315,"epssPercentile":0.24603,"activeExploitation":true,"otRelevance":58,"vendor":"Zyxel","product":"GS1900 Series Switches","region":"Global","publishedAt":"2026-09-21T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Zyxel","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-7273"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39682","type":"CVE","title":"CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability","summary":"Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.012,"epssPercentile":0.66357,"activeExploitation":true,"otRelevance":33,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2025-39682"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39964","type":"CVE","title":"CVE-2025-39964: Linux Kernel Race Condition Vulnerability","summary":"Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0079,"epssPercentile":0.54297,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation","Safety instrumented system"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-39964"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-53266","type":"CVE","title":"CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability","summary":"Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00276,"epssPercentile":0.20195,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-53266"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87886","type":"CVE","title":"CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability","summary":"Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00254,"epssPercentile":0.17289,"activeExploitation":true,"otRelevance":15,"vendor":"Acronis","product":"Backup","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Acronis","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87886"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-58704","type":"CVE","title":"CVE-2026-58704: Google Pixel Improper Authorization Vulnerability","summary":"Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00207,"epssPercentile":0.11142,"activeExploitation":true,"otRelevance":15,"vendor":"Google","product":"Pixel","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Google","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-58704"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85751","type":"CVE","title":"CVE-2026-85751: Mailu is a mail server distributed as a set of Docker images","summary":"Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header directive in the nginx template at core/nginx/conf/proxy.conf hid the header from upstream responses but did not overwrite the incoming request value in this confi","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85751","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":58,"region":"Global","publishedAt":"2026-09-21T16:17:25.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-85751"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-58491","type":"CVE","title":"CVE-2026-58491: Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux","summary":"Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by warpgate-protocol-http/src/api/sso_provider_list.rs. A victim who follows a crafted link and completes SSO can cause markup and JavaScript to execute in the authenticated Warpgate ori","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-58491","sourceTier":1,"severity":"Critical","cvss":9.3,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-21T19:17:06.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-58491"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-84990","type":"CVE","title":"CVE-2026-84990: ntopng is a web-based network traffic monitoring application","summary":"ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any authenticated non-admin user to list and download system-configuration backups without an administrator check. The download path reaches backup_config.export_backup, and prefs_dump_utils.build_prefs_dump_table includes the ntopng.user.* Redis k","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84990","sourceTier":1,"severity":"High","cvss":8.8,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-21T17:19:13.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-84990"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-79920","type":"CVE","title":"CVE-2026-79920: Ajenti is a Linux & BSD modular server admin panel","summary":"Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management authorization. InstallPlugin and UnInstallPlugin construct a pip package specification from unvalidated name and version fields, and the task worker invokes pip while running as root. A low-privileged user can therefore select or manipu","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79920","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-21T17:18:59.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-79920"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-94184","type":"CVE","title":"CVE-2026-94184: A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support","summary":"A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.\n\nAffects v5.0.8 through v6.6.6.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94184","sourceTier":1,"severity":"High","cvss":8.1,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-21T15:17:38.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-94184"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-21","title":"Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","deck":"6 confirmed active-exploitation signals, 6 critical items, and 6 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":37,"criticalCount":6,"activeCount":6,"highCount":6,"items":[{"id":"CVE-2026-76460","type":"CVE","title":"CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","summary":"Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00784,"epssPercentile":0.54529,"activeExploitation":true,"otRelevance":58,"vendor":"Cisco","product":"Identity Services Engine","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76460"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39682","type":"CVE","title":"CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability","summary":"Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.012,"epssPercentile":0.66798,"activeExploitation":true,"otRelevance":33,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2025-39682"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39964","type":"CVE","title":"CVE-2025-39964: Linux Kernel Race Condition Vulnerability","summary":"Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0079,"epssPercentile":0.54718,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation","Safety instrumented system"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-39964"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-53266","type":"CVE","title":"CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability","summary":"Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00276,"epssPercentile":0.20224,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-53266"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87886","type":"CVE","title":"CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability","summary":"Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00254,"epssPercentile":0.1733,"activeExploitation":true,"otRelevance":15,"vendor":"Acronis","product":"Backup","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Acronis","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87886"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-58704","type":"CVE","title":"CVE-2026-58704: Google Pixel Improper Authorization Vulnerability","summary":"Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00207,"epssPercentile":0.11161,"activeExploitation":true,"otRelevance":15,"vendor":"Google","product":"Pixel","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Google","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-58704"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-94089","type":"CVE","title":"CVE-2026-94089: A vulnerability was determined in D-Link DIR-868L 2.01b05","summary":"A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94089","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-20T21:16:55.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-94089"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-94100","type":"CVE","title":"CVE-2026-94100: A weakness has been identified in Netcore NBR200V2 1.3.241127.071246","summary":"A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94100","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":40,"region":"Global","publishedAt":"2026-09-21T01:16:30.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Transportation"],"cves":["CVE-2026-94100"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-94101","type":"CVE","title":"CVE-2026-94101: A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246","summary":"A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94101","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":40,"region":"Global","publishedAt":"2026-09-21T02:16:53.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-94101"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-94097","type":"CVE","title":"CVE-2026-94097: A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246","summary":"A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94097","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-21T00:16:59.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-94097"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-94095","type":"CVE","title":"CVE-2026-94095: A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246","summary":"A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94095","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-21T00:16:59.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-94095"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-94096","type":"CVE","title":"CVE-2026-94096: A vulnerability was found in Netcore NBR200V2 1.3.241127.071246","summary":"A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94096","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-21T00:16:59.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-94096"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-20","title":"Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","deck":"7 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":35,"criticalCount":4,"activeCount":7,"highCount":8,"items":[{"id":"CVE-2026-76460","type":"CVE","title":"CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","summary":"Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00784,"epssPercentile":0.54531,"activeExploitation":true,"otRelevance":58,"vendor":"Cisco","product":"Identity Services Engine","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76460"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76461","type":"CVE","title":"CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability","summary":"Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02009,"epssPercentile":0.79973,"activeExploitation":true,"otRelevance":33,"vendor":"Cisco","product":"Secure Email Gateway","region":"Global","publishedAt":"2026-09-14T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76461"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39682","type":"CVE","title":"CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability","summary":"Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.012,"epssPercentile":0.66794,"activeExploitation":true,"otRelevance":33,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2025-39682"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39964","type":"CVE","title":"CVE-2025-39964: Linux Kernel Race Condition Vulnerability","summary":"Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0079,"epssPercentile":0.54721,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation","Safety instrumented system"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-39964"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-53266","type":"CVE","title":"CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability","summary":"Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00276,"epssPercentile":0.20232,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-53266"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87886","type":"CVE","title":"CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability","summary":"Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00254,"epssPercentile":0.17351,"activeExploitation":true,"otRelevance":15,"vendor":"Acronis","product":"Backup","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Acronis","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87886"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-58704","type":"CVE","title":"CVE-2026-58704: Google Pixel Improper Authorization Vulnerability","summary":"Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00207,"epssPercentile":0.11172,"activeExploitation":true,"otRelevance":15,"vendor":"Google","product":"Pixel","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Google","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-58704"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-94003","type":"CVE","title":"CVE-2026-94003: A vulnerability has been found in Comfast CF-N1-S 2.6.0.1","summary":"A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94003","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-20T12:17:05.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-94003"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-90817","type":"CVE","title":"CVE-2026-90817: An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malici","summary":"An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. ","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90817","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":40,"region":"Global","publishedAt":"2026-09-20T13:17:44.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":["Transportation"],"cves":["CVE-2026-90817"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-93962","type":"CVE","title":"CVE-2026-93962: A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1","summary":"A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 6.0.8 is sufficient to resolve this issue. This patch is call","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93962","sourceTier":1,"severity":"High","cvss":8.3,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-20T05:16:29.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93962"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-94083","type":"CVE","title":"CVE-2026-94083: Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the a","summary":"Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94083","sourceTier":1,"severity":"Critical","cvss":9.4,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-20T02:16:53.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-94083"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-93958","type":"CVE","title":"CVE-2026-93958: A vulnerability was found in D-Link R95 BE9500_1.00.16","summary":"A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93958","sourceTier":1,"severity":"Critical","cvss":9.1,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-20T02:16:53.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-93958"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-19","title":"Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","deck":"7 confirmed active-exploitation signals, 4 critical items, and 8 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":49,"criticalCount":4,"activeCount":7,"highCount":8,"items":[{"id":"CVE-2026-76460","type":"CVE","title":"CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","summary":"Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00784,"epssPercentile":0.54494,"activeExploitation":true,"otRelevance":58,"vendor":"Cisco","product":"Identity Services Engine","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76460"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76461","type":"CVE","title":"CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability","summary":"Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02009,"epssPercentile":0.79955,"activeExploitation":true,"otRelevance":33,"vendor":"Cisco","product":"Secure Email Gateway","region":"Global","publishedAt":"2026-09-14T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76461"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39682","type":"CVE","title":"CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability","summary":"Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00505,"epssPercentile":0.42129,"activeExploitation":true,"otRelevance":33,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2025-39682"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-39964","type":"CVE","title":"CVE-2025-39964: Linux Kernel Race Condition Vulnerability","summary":"Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00323,"epssPercentile":0.25599,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation","Safety instrumented system"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-39964"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87886","type":"CVE","title":"CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability","summary":"Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00281,"epssPercentile":0.20813,"activeExploitation":true,"otRelevance":15,"vendor":"Acronis","product":"Backup","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Acronis","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87886"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-58704","type":"CVE","title":"CVE-2026-58704: Google Pixel Improper Authorization Vulnerability","summary":"Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00207,"epssPercentile":0.11192,"activeExploitation":true,"otRelevance":15,"vendor":"Google","product":"Pixel","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Google","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-58704"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-53266","type":"CVE","title":"CVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability","summary":"Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00121,"epssPercentile":0.02189,"activeExploitation":true,"otRelevance":15,"vendor":"Linux","product":"Kernel","region":"Global","publishedAt":"2026-09-18T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Linux","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-53266"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-61682","type":"CVE","title":"CVE-2026-61682: kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads","summary":"kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and ","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61682","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":40,"region":"Global","publishedAt":"2026-09-18T16:17:07.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-61682"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-93605","type":"CVE","title":"CVE-2026-93605: vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking ot","summary":"vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93605","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-18T14:19:12.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-93605"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-93603","type":"CVE","title":"CVE-2026-93603: vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandbox","summary":"vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method, `fn.call()`, `fn.apply(undefined)`, `Reflect.apply(fn, undefined, [])`, or `fn.bind()()` — the undefined receiver is passed straight through to the host call, and V8 substitutes the host realm's global object for ","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93603","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-18T14:19:12.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-93603"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-93606","type":"CVE","title":"CVE-2026-93606: vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`","summary":"vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`.then` neutralization is installed only on the sandbox intrinsic `Promise.protot","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93606","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-18T14:19:12.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-93606"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-93569","type":"CVE","title":"CVE-2026-93569: A flaw was found in Netty","summary":"A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potential","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93569","sourceTier":1,"severity":"High","cvss":8.2,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-18T15:17:20.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation","Safety instrumented system"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-93569"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-18","title":"Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","deck":"4 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":85,"criticalCount":7,"activeCount":4,"highCount":5,"items":[{"id":"CVE-2026-76460","type":"CVE","title":"CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","summary":"Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":58,"vendor":"Cisco","product":"Identity Services Engine","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76460"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76461","type":"CVE","title":"CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability","summary":"Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02009,"epssPercentile":0.79862,"activeExploitation":true,"otRelevance":33,"vendor":"Cisco","product":"Secure Email Gateway","region":"Global","publishedAt":"2026-09-14T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76461"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-58704","type":"CVE","title":"CVE-2026-58704: Google Pixel Improper Authorization Vulnerability","summary":"Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00112,"epssPercentile":0.01564,"activeExploitation":true,"otRelevance":15,"vendor":"Google","product":"Pixel","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Google","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-58704"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87886","type":"CVE","title":"CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability","summary":"Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Acronis","product":"Backup","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Acronis","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87886"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-92956","type":"CVE","title":"CVE-2026-92956: vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26","summary":"vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the host error constructor to the host Function constructor, and recovers the real ho","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92956","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-17T14:18:01.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-92956"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-92948","type":"CVE","title":"CVE-2026-92948: vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the e","summary":"vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules exposes the scheme-only key node:test, which is not covered by vm2's family-based DANGEROUS_BUILTINS protection, so it is stored in the generic host-passthrough loader. Because requireImpl() in lib/se","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92948","sourceTier":1,"severity":"Critical","cvss":9.9,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-17T14:18:00.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-92948"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-92937","type":"CVE","title":"CVE-2026-92937: vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process","summary":"vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a rejected host Promise value. Registering the rejection handler through Function.prototype.call or .apply indirection (e.g., p.then.call(p, undefined, cb)) makes the intercepted target host Function.pr","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92937","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":40,"region":"Global","publishedAt":"2026-09-17T14:17:58.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-92937"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-92958","type":"CVE","title":"CVE-2026-92958: vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM","summary":"vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: ['*', '-fs', '-child_process'] }), negative entries are matched by exact module name in lib/builtin.js, so -fs removes only the builtin named fs and does not remove builtin subpaths such as fs/promises. Sandboxed code can therefore call require('fs/promises') or require('node:fs/promises') and reach the pr","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92958","sourceTier":1,"severity":"High","cvss":8.5,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-17T14:18:01.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-92958"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-92940","type":"CVE","title":"CVE-2026-92940: vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow ","summary":"vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method calls such as Agent.prototype.on() are forwarded to the underlying host object, so sandbox code can register a listener for the agent's 'free' event. When an unrelated host HTTPS request releases a pooled connection, the listener receives th","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92940","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-17T14:17:59.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-92940"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-62104","type":"CVE","title":"CVE-2026-62104: Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.","summary":"Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62104","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-17T14:17:15.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-62104"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-92946","type":"CVE","title":"CVE-2026-92946: vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_","summary":"vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS commands via child_process.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92946","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-17T14:17:59.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-92946"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-92947","type":"CVE","title":"CVE-2026-92947: vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and rela","summary":"vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92947","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":33,"region":"Global","publishedAt":"2026-09-17T14:18:00.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-92947"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-17","title":"Active threat: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","deck":"8 confirmed active-exploitation signals, 1 critical item, and 11 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":78,"criticalCount":1,"activeCount":8,"highCount":11,"items":[{"id":"CVE-2026-76460","type":"CVE","title":"CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","summary":"Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":58,"vendor":"Cisco","product":"Identity Services Engine","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76460"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76461","type":"CVE","title":"CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability","summary":"Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02009,"epssPercentile":0.79862,"activeExploitation":true,"otRelevance":33,"vendor":"Cisco","product":"Secure Email Gateway","region":"Global","publishedAt":"2026-09-14T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76461"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42018","type":"CVE","title":"CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability","summary":"JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0092,"epssPercentile":0.5854,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42018"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42016","type":"CVE","title":"CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability","summary":"JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00886,"epssPercentile":0.57488,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42016"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-84869","type":"CVE","title":"CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability","summary":"ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00691,"epssPercentile":0.51113,"activeExploitation":true,"otRelevance":33,"vendor":"ConnectWise","product":"ScreenConnect","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ConnectWise","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-84869"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85706","type":"CVE","title":"CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability","summary":"GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.11957,"epssPercentile":0.95901,"activeExploitation":true,"otRelevance":15,"vendor":"GitLab","product":"Community Edition and Enterprise Edition","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"GitLab","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-85706"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-58704","type":"CVE","title":"CVE-2026-58704: Google Pixel Improper Authorization Vulnerability","summary":"Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00112,"epssPercentile":0.01564,"activeExploitation":true,"otRelevance":15,"vendor":"Google","product":"Pixel","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Google","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-58704"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87886","type":"CVE","title":"CVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability","summary":"Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":15,"vendor":"Acronis","product":"Backup","region":"Global","publishedAt":"2026-09-16T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Acronis","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87886"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-84860","type":"CVE","title":"CVE-2026-84860: ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass\n\n\n\nSpring Security gates DWR endpoints by URL path pattern, but DWR it","summary":"ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass\n\n\n\nSpring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which disables DWR's built-in origin validation. This means any authenticated user can invoke any DWR method (regardless of the URL-based access control) by sending th","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84860","sourceTier":1,"severity":"High","cvss":8.8,"activeExploitation":false,"otRelevance":69,"region":"Global","publishedAt":"2026-09-16T15:18:00.000Z","tags":["CVE","NVD"],"assetTypes":["SCADA","Building automation"],"purdueLevels":["L2","L1"],"sectors":[],"cves":["CVE-2026-84860"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-92395","type":"CVE","title":"CVE-2026-92395: @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and","summary":"@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet rather than the block it names. Because the socket peer then b","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92395","sourceTier":1,"severity":"Critical","cvss":9.1,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-16T15:19:01.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-92395"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-84858","type":"CVE","title":"CVE-2026-84858: ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass\n\n\n\nThe DWR \"DataSourceEdit","summary":"ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass\n\n\n\nThe DWR \"DataSourceEditDwr\" class exposes the \"validateScript\" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privilege user to abuse this flaw by leveraging the DWR routing bypass.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84858","sourceTier":1,"severity":"High","cvss":8.8,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-16T15:18:00.000Z","tags":["CVE","NVD"],"assetTypes":["SCADA"],"purdueLevels":["L2"],"sectors":[],"cves":["CVE-2026-84858"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-82964","type":"CVE","title":"CVE-2026-82964: Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing ","summary":"Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM.\n\n\n\nWhen the sandbox virtualizes a file it copies the original security descriptor, but the driver opened the virtualization target object with GENERIC_WRITE and FILE_WRITE_ATTRIBUTES only, omitting WRITE_DAC. Every attempt to apply the original DACL therefore fa","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82964","sourceTier":1,"severity":"High","cvss":8.8,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-16T15:17:55.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-82964"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-16","title":"Active threat: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability","deck":"7 confirmed active-exploitation signals, 3 critical items, and 9 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":47,"criticalCount":3,"activeCount":7,"highCount":9,"items":[{"id":"CVE-2026-86060","type":"CVE","title":"CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability","summary":"MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.01057,"epssPercentile":0.62635,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67277","type":"CVE","title":"CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability","summary":"MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00869,"epssPercentile":0.56832,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67277"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76461","type":"CVE","title":"CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability","summary":"Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02162,"epssPercentile":0.81239,"activeExploitation":true,"otRelevance":33,"vendor":"Cisco","product":"Secure Email Gateway","region":"Global","publishedAt":"2026-09-14T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76461"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42018","type":"CVE","title":"CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability","summary":"JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0092,"epssPercentile":0.58393,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42018"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42016","type":"CVE","title":"CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability","summary":"JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00886,"epssPercentile":0.57342,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42016"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-84869","type":"CVE","title":"CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability","summary":"ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00691,"epssPercentile":0.50945,"activeExploitation":true,"otRelevance":33,"vendor":"ConnectWise","product":"ScreenConnect","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ConnectWise","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-84869"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85706","type":"CVE","title":"CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability","summary":"GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.11957,"epssPercentile":0.95887,"activeExploitation":true,"otRelevance":15,"vendor":"GitLab","product":"Community Edition and Enterprise Edition","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"GitLab","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-85706"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-59971","type":"CVE","title":"CVE-2026-59971: MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases","summary":"MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or enable_dns_rebinding_protection, while the Starlette routes /, /sse, and /messages/ have no authentication and the service binds to 0.0.0.0 by default. A network attacker can directly reach execute_sql, or can use DNS rebinding to ma","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59971","sourceTier":1,"severity":"Critical","cvss":10,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-15T15:17:19.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Transportation"],"cves":["CVE-2026-59971"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-55158","type":"CVE","title":"CVE-2026-55158: Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests","summary":"Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a fork, whose branch name contains shell metacharacters, and the workflow automat","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55158","sourceTier":1,"severity":"Critical","cvss":9.1,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-15T15:17:18.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-55158"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-91934","type":"CVE","title":"CVE-2026-91934: Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated a","summary":"Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform stored XSS attacks.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91934","sourceTier":1,"severity":"High","cvss":8.8,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-15T16:17:44.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-91934"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-54076","type":"CVE","title":"CVE-2026-54076: ArcadeDB is a Multi-Model DBMS","summary":"ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcadedb/schema/LocalDocumentType.java and engine/src/main/java/com/arcadedb/schema/LocalProperty.java remained unchecked. An authenticated identity, including a read-only API token without UPDATE_SCHEMA permission, can use DROP PROPERTY, ALTER TYP","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54076","sourceTier":1,"severity":"High","cvss":8.1,"activeExploitation":false,"otRelevance":58,"region":"Global","publishedAt":"2026-09-15T16:17:13.000Z","tags":["CVE","NVD"],"assetTypes":[],"purdueLevels":[],"sectors":[],"cves":["CVE-2026-54076","CVE-2026-44221"],"advisoryIds":[],"kevLinked":false},{"id":"CVE-2026-63695","type":"CVE","title":"CVE-2026-63695: Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability","summary":"Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63695","sourceTier":1,"severity":"Critical","cvss":9.8,"activeExploitation":false,"otRelevance":40,"region":"Global","publishedAt":"2026-09-15T15:17:20.000Z","tags":["CVE","NVD"],"assetTypes":["Remote access"],"purdueLevels":["L3","L3.5"],"sectors":[],"cves":["CVE-2026-63695"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-15","title":"Active threat: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability","deck":"11 confirmed active-exploitation signals, 0 critical items, and 12 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":51,"criticalCount":0,"activeCount":11,"highCount":12,"items":[{"id":"CVE-2026-20079","type":"CVE","title":"CVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability","summary":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.75752,"epssPercentile":0.99493,"activeExploitation":true,"otRelevance":40,"vendor":"Cisco","product":"Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-20079"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-19490","type":"CVE","title":"CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.05597,"epssPercentile":0.92461,"activeExploitation":true,"otRelevance":40,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-19490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-25249","type":"CVE","title":"CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability","summary":"Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02403,"epssPercentile":0.83126,"activeExploitation":true,"otRelevance":40,"vendor":"Fortinet","product":"Multiple Products","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-25249"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86060","type":"CVE","title":"CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability","summary":"MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0102,"epssPercentile":0.6146,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87491","type":"CVE","title":"CVE-2026-87491: Google Chromium V8 Out of Bounds Write Vulnerability","summary":"Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00859,"epssPercentile":0.56464,"activeExploitation":true,"otRelevance":40,"vendor":"Google","product":"Chromium V8","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87491"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67277","type":"CVE","title":"CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability","summary":"MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00856,"epssPercentile":0.56357,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67277"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42018","type":"CVE","title":"CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability","summary":"JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0092,"epssPercentile":0.58322,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42018"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42016","type":"CVE","title":"CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability","summary":"JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00886,"epssPercentile":0.57271,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42016"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-84869","type":"CVE","title":"CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability","summary":"ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00691,"epssPercentile":0.50868,"activeExploitation":true,"otRelevance":33,"vendor":"ConnectWise","product":"ScreenConnect","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ConnectWise","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-84869"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-76461","type":"CVE","title":"CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability","summary":"Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","activeExploitation":true,"otRelevance":33,"vendor":"Cisco","product":"Secure Email Gateway","region":"Global","publishedAt":"2026-09-14T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-76461"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85706","type":"CVE","title":"CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability","summary":"GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.11115,"epssPercentile":0.95684,"activeExploitation":true,"otRelevance":15,"vendor":"GitLab","product":"Community Edition and Enterprise Edition","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"GitLab","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-85706"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-61701","type":"CVE","title":"CVE-2026-61701: Laravel MagicLink creates links for authentication without a password or for accessing private content","summary":"Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them through src/MagicLink.php and src/Actions/ResponseAction.php without sufficient integrity protection, while an unsafe legacy unserialize() fallback remains reachable. An attacker who can manipulate database records, such as through a separate S","sourceName":"NIST NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61701","sourceTier":1,"severity":"High","cvss":8.8,"activeExploitation":false,"otRelevance":51,"region":"Global","publishedAt":"2026-09-14T17:17:49.000Z","tags":["CVE","NVD"],"assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-61701"],"advisoryIds":[],"kevLinked":false}]},{"date":"2026-09-14","title":"Active threat: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability","deck":"12 confirmed active-exploitation signals, 0 critical items, and 12 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":40,"criticalCount":0,"activeCount":12,"highCount":12,"items":[{"id":"CVE-2026-20079","type":"CVE","title":"CVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability","summary":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.75752,"epssPercentile":0.99493,"activeExploitation":true,"otRelevance":40,"vendor":"Cisco","product":"Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-20079"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-19490","type":"CVE","title":"CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.05597,"epssPercentile":0.92457,"activeExploitation":true,"otRelevance":40,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-19490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-25249","type":"CVE","title":"CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability","summary":"Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02403,"epssPercentile":0.83116,"activeExploitation":true,"otRelevance":40,"vendor":"Fortinet","product":"Multiple Products","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-25249"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86060","type":"CVE","title":"CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability","summary":"MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0102,"epssPercentile":0.61439,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87491","type":"CVE","title":"CVE-2026-87491: Google Chromium V8 Out of Bounds Write Vulnerability","summary":"Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00859,"epssPercentile":0.56439,"activeExploitation":true,"otRelevance":40,"vendor":"Google","product":"Chromium V8","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87491"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67277","type":"CVE","title":"CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability","summary":"MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00856,"epssPercentile":0.56331,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67277"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86218","type":"CVE","title":"CVE-2026-86218: N-able N-central Static Code Injection Vulnerability","summary":"N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00744,"epssPercentile":0.52733,"activeExploitation":true,"otRelevance":40,"vendor":"N-able","product":"N-central","region":"Global","publishedAt":"2026-09-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"N-able","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86218"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42018","type":"CVE","title":"CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability","summary":"JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0092,"epssPercentile":0.58299,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42018"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42016","type":"CVE","title":"CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability","summary":"JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00886,"epssPercentile":0.57248,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42016"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-84869","type":"CVE","title":"CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability","summary":"ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00691,"epssPercentile":0.50841,"activeExploitation":true,"otRelevance":33,"vendor":"ConnectWise","product":"ScreenConnect","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ConnectWise","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-84869"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85880","type":"CVE","title":"CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability","summary":"Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00572,"epssPercentile":0.45512,"activeExploitation":true,"otRelevance":33,"vendor":"Microsoft","product":"Windows","region":"Global","publishedAt":"2026-09-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-85880"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-75650","type":"CVE","title":"CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability","summary":"Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02148,"epssPercentile":0.8108,"activeExploitation":true,"otRelevance":15,"vendor":"Adobe","product":"Commerce and Magento","region":"Global","publishedAt":"2026-09-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Adobe","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-75650"],"advisoryIds":[],"kevLinked":true}]},{"date":"2026-09-13","title":"Active threat: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability","deck":"12 confirmed active-exploitation signals, 0 critical items, and 12 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":36,"criticalCount":0,"activeCount":12,"highCount":12,"items":[{"id":"CVE-2026-20079","type":"CVE","title":"CVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability","summary":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.75752,"epssPercentile":0.99492,"activeExploitation":true,"otRelevance":40,"vendor":"Cisco","product":"Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-20079"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-19490","type":"CVE","title":"CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.05597,"epssPercentile":0.92458,"activeExploitation":true,"otRelevance":40,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-19490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-25249","type":"CVE","title":"CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability","summary":"Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02403,"epssPercentile":0.83114,"activeExploitation":true,"otRelevance":40,"vendor":"Fortinet","product":"Multiple Products","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-25249"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86060","type":"CVE","title":"CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability","summary":"MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0102,"epssPercentile":0.6144,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87491","type":"CVE","title":"CVE-2026-87491: Google Chromium V8 Out of Bounds Write Vulnerability","summary":"Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00859,"epssPercentile":0.56441,"activeExploitation":true,"otRelevance":40,"vendor":"Google","product":"Chromium V8","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87491"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67277","type":"CVE","title":"CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability","summary":"MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00856,"epssPercentile":0.56333,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67277"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86218","type":"CVE","title":"CVE-2026-86218: N-able N-central Static Code Injection Vulnerability","summary":"N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00744,"epssPercentile":0.52735,"activeExploitation":true,"otRelevance":40,"vendor":"N-able","product":"N-central","region":"Global","publishedAt":"2026-09-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"N-able","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86218"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42018","type":"CVE","title":"CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability","summary":"JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.0092,"epssPercentile":0.58304,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42018"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42016","type":"CVE","title":"CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability","summary":"JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00886,"epssPercentile":0.57253,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42016"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-84869","type":"CVE","title":"CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability","summary":"ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00691,"epssPercentile":0.50847,"activeExploitation":true,"otRelevance":33,"vendor":"ConnectWise","product":"ScreenConnect","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ConnectWise","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-84869"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85880","type":"CVE","title":"CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability","summary":"Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00572,"epssPercentile":0.45535,"activeExploitation":true,"otRelevance":33,"vendor":"Microsoft","product":"Windows","region":"Global","publishedAt":"2026-09-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-85880"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-75650","type":"CVE","title":"CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability","summary":"Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02148,"epssPercentile":0.81079,"activeExploitation":true,"otRelevance":15,"vendor":"Adobe","product":"Commerce and Magento","region":"Global","publishedAt":"2026-09-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Adobe","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-75650"],"advisoryIds":[],"kevLinked":true}]},{"date":"2026-09-12","title":"Active threat: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability","deck":"12 confirmed active-exploitation signals, 0 critical items, and 12 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.","analyzedCount":53,"criticalCount":0,"activeCount":12,"highCount":12,"items":[{"id":"CVE-2026-20079","type":"CVE","title":"CVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability","summary":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.75752,"epssPercentile":0.99491,"activeExploitation":true,"otRelevance":40,"vendor":"Cisco","product":"Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Cisco","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-20079"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-19490","type":"CVE","title":"CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability","summary":"Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.05597,"epssPercentile":0.92445,"activeExploitation":true,"otRelevance":40,"vendor":"Citrix","product":"NetScaler","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Citrix","assetTypes":["Remote access","Building automation"],"purdueLevels":["L3","L3.5","L1","L2"],"sectors":[],"cves":["CVE-2026-19490"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2025-25249","type":"CVE","title":"CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability","summary":"Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02403,"epssPercentile":0.83086,"activeExploitation":true,"otRelevance":40,"vendor":"Fortinet","product":"Multiple Products","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Fortinet","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2025-25249"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-87491","type":"CVE","title":"CVE-2026-87491: Google Chromium V8 Out of Bounds Write Vulnerability","summary":"Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00859,"epssPercentile":0.56375,"activeExploitation":true,"otRelevance":40,"vendor":"Google","product":"Chromium V8","region":"Global","publishedAt":"2026-09-09T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-87491"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-67277","type":"CVE","title":"CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability","summary":"MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00748,"epssPercentile":0.52789,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-67277"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86218","type":"CVE","title":"CVE-2026-86218: N-able N-central Static Code Injection Vulnerability","summary":"N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00744,"epssPercentile":0.52667,"activeExploitation":true,"otRelevance":40,"vendor":"N-able","product":"N-central","region":"Global","publishedAt":"2026-09-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"N-able","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86218"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-86060","type":"CVE","title":"CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability","summary":"MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00689,"epssPercentile":0.50738,"activeExploitation":true,"otRelevance":40,"vendor":"MikroTik","product":"RouterOS","region":"Global","publishedAt":"2026-09-10T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"MikroTik","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-86060"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-85880","type":"CVE","title":"CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability","summary":"Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00572,"epssPercentile":0.45457,"activeExploitation":true,"otRelevance":33,"vendor":"Microsoft","product":"Windows","region":"Global","publishedAt":"2026-09-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Microsoft","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-85880"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-84869","type":"CVE","title":"CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability","summary":"ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00382,"epssPercentile":0.31639,"activeExploitation":true,"otRelevance":33,"vendor":"ConnectWise","product":"ScreenConnect","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"ConnectWise","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-84869"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42018","type":"CVE","title":"CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability","summary":"JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00349,"epssPercentile":0.28044,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42018"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-42016","type":"CVE","title":"CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability","summary":"JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.00266,"epssPercentile":0.184,"activeExploitation":true,"otRelevance":33,"vendor":"JFrog","product":"Artifactory","region":"Global","publishedAt":"2026-09-11T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"JFrog","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":["Critical manufacturing"],"cves":["CVE-2026-42016"],"advisoryIds":[],"kevLinked":true},{"id":"CVE-2026-75650","type":"CVE","title":"CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability","summary":"Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","sourceName":"CISA KEV","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","sourceTier":1,"severity":"High","epss":0.02148,"epssPercentile":0.81048,"activeExploitation":true,"otRelevance":15,"vendor":"Adobe","product":"Commerce and Magento","region":"Global","publishedAt":"2026-09-08T12:00:00.000Z","tags":["CISA KEV","Active Exploitation"],"normalizedVendor":"Adobe","assetTypes":["Building automation"],"purdueLevels":["L1","L2"],"sectors":[],"cves":["CVE-2026-75650"],"advisoryIds":[],"kevLinked":true}]}]