CVE-2026-85880
HIGH
CVSS: 7.8
EPSS: 3.6%
VulnCheck KEV
Weaponized
CWE-122
CWE-908
T1005
T1203
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 3 article(s):
CVE-2026-93616
CRITICAL
CVSS: 9.8
EPSS: 19.7%
VulnCheck KEV
Weaponized
CWE-22
T1083
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Published: 2026-09-22
Mentioned in 2 article(s):
CVE-2026-90898
CRITICAL
CVSS: 9.8
EPSS: 0.6%
CWE-284
CWE-306
T1078
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required.
The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).
transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.
Published: 2026-09-14
Mentioned in 1 article(s):
CVE-2026-86296
CRITICAL
CVSS: 10.0
EPSS: 1.7%
CWE-119
CWE-121
T1203
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-07
Mentioned in 1 article(s):
CVE-2026-93952
CRITICAL
CVSS: 10.0
EPSS: 1.1%
VulnCheck KEV
PoC Available
CWE-20
T1190
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Published: 2026-09-22
Mentioned in 2 article(s):
CVE-2026-89775
CRITICAL
CVSS: 9.3
EPSS: 0.2%
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
Computing the effects of a TLB invalidation involves looking at
the size of the mapping cached by the TLB. For S1 mappings such as
VNCR, this is deducted from the combination of the base granule size
and the mapping level.
However, this implies that the S1 MMU is *on*. When the MMU is off,
we indicate this with the level being set to a "creative" value of
-127 (S1_MMU_DISABLED).
This ends-up being misinterpreted by pgshift_level_to_ttl() as it
doesn't handle negative levels at all (the level is immediately cast
to a u8 and only the bottom two bits considered), leading to an
invalidation size of 0. Not helpful.
Tidy-up pgshift_level_to_ttl() to handle these negative levels, and
ttl_to_size() to always return SZ_1G when no valid TTL is present.
This allows the removal of open-coded checks for similar situations.
Note that the check for a negative value not explicitely checking for
S1_MMU_DISABLED is deliberate, so that actual negative levels introduced
with LVA2 and D128 can take the same path if we ever support them.
Published: 2026-09-16
Mentioned in 1 article(s):
CVE-2026-93485
HIGH
CVSS: 7.1
EPSS: 0.4%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS.
This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35.
The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.
Published: 2026-09-18
Mentioned in 1 article(s):
CVE-2026-7273
HIGH
CVSS: 8.8
EPSS: 2.5%
VulnCheck KEV
PoC Available
CWE-121
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
Published: 2026-06-16
Mentioned in 2 article(s):
CVE-2026-28326
HIGH
CVSS: 8.8
EPSS: 0.7%
CWE-321
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-58138
CRITICAL
CVSS: 9.8
EPSS: 14.7%
VulnCheck KEV
PoC Available
ExploitDB
CWE-94
T1059
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.
Published: 2026-06-30
Mentioned in 2 article(s):
CVE-2025-39682
CRITICAL
CVSS: 9.8
EPSS: 2.9%
VulnCheck KEV
Weaponized
CWE-754
In the Linux kernel, the following vulnerability has been resolved:
tls: fix handling of zero-length records on the rx_list
Each recvmsg() call must process either
- only contiguous DATA records (any number of them)
- one non-DATA record
If the next record has different type than what has already been
processed we break out of the main processing loop. If the record
has already been decrypted (which may be the case for TLS 1.3 where
we don't know type until decryption) we queue the pending record
to the rx_list. Next recvmsg() will pick it up from there.
Queuing the skb to rx_list after zero-copy decrypt is not possible,
since in that case we decrypted directly to the user space buffer,
and we don't have an skb to queue (darg.skb points to the ciphertext
skb for access to metadata like length).
Only data records are allowed zero-copy, and we break the processing
loop after each non-data record. So we should never zero-copy and
then find out that the record type has changed. The corner case
we missed is when the initial record comes from rx_list, and it's
zero length.
Published: 2025-09-05
Mentioned in 2 article(s):
CVE-2026-76460
CRITICAL
CVSS: 10.0
EPSS: 14.0%
VulnCheck KEV
Weaponized
CWE-648
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.
This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Published: 2026-09-16
Mentioned in 3 article(s):
CVE-2026-88097
HIGH
CVSS: 8.1
EPSS: 0.3%
CWE-416
T1203
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
Published: 2026-09-18
Mentioned in 1 article(s):
CVE-2026-85889
CRITICAL
CVSS: 10.0
EPSS: 0.7%
CWE-306
T1078
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Mentioned in 2 article(s):
CVE-2026-53266
HIGH
CVSS: 8.8
EPSS: 0.8%
VulnCheck KEV
PoC Available
CWE-787
T1203
In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: make ebt_snat ARP rewrite writable
The ebtables SNAT target keeps the Ethernet source address rewrite
behind skb_ensure_writable(skb, 0). This is intentional: at the bridge
ebtables hooks the Ethernet header is addressed through
skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet
payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check
the payload, not the Ethernet header, and would reintroduce the small
packet regression fixed by commit 63137bc5882a.
However, the optional ARP sender hardware address rewrite is different.
It writes through skb_store_bits() at an offset relative to skb->data:
skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)
skb_header_pointer() only safely reads the ARP header; it does not make
the later sender hardware address range writable. If that range is
still held in a nonlinear skb fragment backed by a splice-imported file
page, skb_store_bits() maps the frag page and copies the new MAC address
directly into it.
Ensure the ARP SHA range is writable before reading the ARP header and
before calling skb_store_bits().
Published: 2026-06-25
Mentioned in 1 article(s):
CVE-2025-39964
HIGH
CVSS: 7.8
EPSS: 1.0%
VulnCheck KEV
Weaponized
CWE-362
CWE-362
T1068
In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Issuing two writes to the same af_alg socket is bogus as the
data will be interleaved in an unpredictable fashion. Furthermore,
concurrent writes may create inconsistencies in the internal
socket state.
Disallow this by adding a new ctx->write field that indiciates
exclusive ownership for writing.
Published: 2025-10-13
Mentioned in 1 article(s):
CVE-2026-77179
UNKNOWN
EPSS: 0.2%
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.
Published: 2026-09-15
Mentioned in 1 article(s):
CVE-2026-62874
CRITICAL
CVSS: 10.0
EPSS: 0.4%
CWE-345
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-18
Mentioned in 1 article(s):
CVE-2026-69399
CRITICAL
CVSS: 10.0
EPSS: 0.5%
CWE-441
Azure Arc Elevation of Privilege Vulnerability
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-69843
CRITICAL
CVSS: 10.0
EPSS: 0.9%
CWE-290
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-18
Mentioned in 1 article(s):
CVE-2026-69865
CRITICAL
CVSS: 10.0
EPSS: 0.8%
CWE-639
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-70200
CRITICAL
CVSS: 10.0
EPSS: 0.6%
CWE-22
CWE-285
T1083
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-83944
CRITICAL
CVSS: 10.0
EPSS: 0.4%
CWE-284
T1078
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-85878
CRITICAL
CVSS: 9.9
EPSS: 0.8%
CWE-285
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-18
Mentioned in 1 article(s):
CVE-2026-85885
CRITICAL
CVSS: 9.9
EPSS: 0.7%
CWE-77
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-87701
CRITICAL
CVSS: 9.6
EPSS: 0.8%
CWE-74
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-70009
CRITICAL
CVSS: 9.3
EPSS: 0.5%
CWE-22
T1083
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-77903
CRITICAL
CVSS: 9.0
EPSS: 0.4%
CWE-290
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-68791
HIGH
CVSS: 8.6
EPSS: 0.5%
CWE-863
T1078
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-83946
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-18
Mentioned in 1 article(s):
CVE-2026-85887
HIGH
CVSS: 7.7
EPSS: 0.8%
CWE-732
T1222
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
Published: 2026-09-18
Mentioned in 1 article(s):
CVE-2026-85917
HIGH
CVSS: 7.5
EPSS: 1.0%
CWE-918
T1190
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-78501
HIGH
CVSS: 7.4
EPSS: 0.9%
CWE-77
CWE-923
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-55946
MEDIUM
CVSS: 6.1
EPSS: 0.4%
CWE-77
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-17
Mentioned in 1 article(s):
CVE-2026-81642
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.
Published: 2026-09-16
Mentioned in 1 article(s):
CVE-2026-89026
CRITICAL
CVSS: 9.8
EPSS: 0.7%
VulnCheck KEV
PoC Available
CWE-321
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.
Published: 2026-09-15
Mentioned in 1 article(s):
CVE-2026-58704
HIGH
CVSS: 8.8
EPSS: 0.6%
VulnCheck KEV
Weaponized
CWE-285
CWE-693
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Mentioned in 3 article(s):
CVE-2026-87886
HIGH
CVSS: 7.8
EPSS: 0.2%
VulnCheck KEV
Weaponized
CWE-276
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
Published: 2026-09-17
Mentioned in 3 article(s):
CVE-2026-69486
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-09-15
Mentioned in 1 article(s):
CVE-2026-85893
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-416
T1203
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-15
Mentioned in 1 article(s):
CVE-2026-76461
CRITICAL
CVSS: 9.8
EPSS: 28.3%
VulnCheck KEV
PoC Available
CWE-89
T1190
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Published: 2026-09-14
Mentioned in 3 article(s):
CVE-2026-87658
MEDIUM
CVSS: 4.3
EPSS: 0.2%
CWE-200
T1005
T1083
Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87657
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-416
T1203
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87656
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-754
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87655
MEDIUM
CVSS: 5.4
EPSS: 0.2%
CWE-1021
Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87654
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-122
T1203
Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87653
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87652
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-863
T1078
Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87651
MEDIUM
CVSS: 4.3
EPSS: 0.2%
CWE-863
T1078
Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
CVE-2026-87650
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-125
T1005
Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):