| Sep 24 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. CVE-2026-86860Critical9.3fixed in ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 | | Critical9.3 | ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 |
| Sep 24 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19. CVE-2026-13249Critical9.8fixed in PD45 Industrial Printer F10.22.030745 | | Critical9.8 | PD45 Industrial Printer F10.22.030745 |
| Sep 24 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. CVE-2026-13016Critical9.3fixed in ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 | | Critical9.3 | ServiceNow AI Platform Yokohama Patch 13 Hot Fix 5a, ServiceNow AI Platform Zurich Patch 10 Hot Fix 3b, ServiceNow AI Platform Zurich Patch 10 Hot Fix 4a W32 |
| Sep 24 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header. CVE-2026-81549Critical9.6no fix yet | | Critical9.6 | No fix yet |
| Sep 24 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. CVE-2026-19072Critical9.9fixed in Velociraptor 0.77.2 | | Critical9.9 | Velociraptor 0.77.2 |
| Sep 24 | Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. CVE-2026-78308Critical9.8fixed in DIAEnergie 1.11.00.022 | | Critical9.8 | DIAEnergie 1.11.00.022 |
| Sep 24 | Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. CVE-2026-78312Critical9.1fixed in DIAEnergie 1.11.00.022 | | Critical9.1 | DIAEnergie 1.11.00.022 |
| Sep 24 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4. CVE-2026-89078Critical9.9fixed in GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 | | Critical9.9 | GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 |
| Sep 24 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4. CVE-2026-93577Critical9.9fixed in GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 | | Critical9.9 | GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 |
| Sep 23 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system. CVE-2026-6730Critical9.8no fix yet | | Critical9.8 | No fix yet |
| Sep 23 | IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. CVE-2026-6928Critical9.8no fix yet | | Critical9.8 | No fix yet |
| Sep 23 | IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the... CVE-2026-6721Critical9.8no fix yet | | Critical9.8 | No fix yet |
| Sep 23 | A flaw was found in the Ansible Automation Platform automation-controller. CVE-2026-84719Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 23 | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers,... CVE-2026-75884Critical9.1no fix yet | | Critical9.1 | No fix yet |
| Sep 23 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. CVE-2026-84502Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 23 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. CVE-2026-84474Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 23 | An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail... CVE-2026-86930Critical9.1fixed in FileMaker Server 26.0.3 | | Critical9.1 | FileMaker Server 26.0.3 |
| Sep 23 | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML... CVE-2026-86934Critical9.1fixed in FileMaker Server 26.0.3 | | Critical9.1 | FileMaker Server 26.0.3 |
| Sep 23 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). CVE-2026-18872Critical9.3no fix yet | | Critical9.3 | No fix yet |
| Sep 23 | If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files... CVE-2026-96276Critical9.8no fix yet | | Critical9.8 | No fix yet |
| Sep 22 | lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks CVE-2026-85734Critical9.1fixed in 1.5.5 | | Critical9.1 | 1.5.5 |
| Sep 22 | OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack CVE-2026-63132Criticalfixed in 0.0.0-20260713141742-763625a20721 | | Critical | 0.0.0-20260713141742-763625a20721 |
| Sep 22 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function... CVE-2026-18162Critical9.8no fix yet | | Critical9.8 | No fix yet |
| Sep 22 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data. CVE-2026-18163Critical9.8no fix yet | | Critical9.8 | No fix yet |
| Sep 22 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. CVE-2026-18169Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 22 | A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. CVE-2026-19202Critical9.1no fix yet | | Critical9.1 | No fix yet |
| Sep 22 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints. CVE-2026-17635Critical9.1no fix yet | | Critical9.1 | No fix yet |
| Sep 22 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management. CVE-2026-17645Critical9.1no fix yet | | Critical9.1 | No fix yet |
| Sep 22 | IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions. CVE-2026-17472Critical9.6no fix yet | | Critical9.6 | No fix yet |
| Sep 22 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVE-2026-16346Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 22 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. CVE-2026-77987Critical9.3fixed in Enterprise Server 3.17.*, Enterprise Server 3.18.*, Enterprise Server 3.19.* | | Critical9.3 | Enterprise Server 3.17.*, Enterprise Server 3.18.*, Enterprise Server 3.19.* |
| Sep 22 | A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system... CVE-2026-76708Critical9.8no fix yet | | Critical9.8 | No fix yet |
| Sep 22 | A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). CVE-2026-76709Critical9.8no fix yet | | Critical9.8 | No fix yet |
| Sep 22 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. CVE-2026-28324Critical9.8fixed in Observability Self-Hosted 2026.2.3 | | Critical9.8 | Observability Self-Hosted 2026.2.3 |
| Sep 22 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. CVE-2026-82000Critical9.6no fix yet | | Critical9.6 | No fix yet |
| Sep 22 | Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-81995Critical9.1no fix yet | | Critical9.1 | No fix yet |
| Sep 22 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-75745Critical10.0no fix yet | | Critical10.0 | No fix yet |
| Sep 22 | Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the... CVE-2026-75682Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 22 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. CVE-2026-75684Critical9.3no fix yet | | Critical9.3 | No fix yet |
| Sep 22 | Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-75686Critical9.3no fix yet | | Critical9.3 | No fix yet |
| Sep 22 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. CVE-2026-75689Critical9.3no fix yet | | Critical9.3 | No fix yet |
| Sep 22 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. CVE-2026-75697Critical9.3no fix yet | | Critical9.3 | No fix yet |
| Sep 22 | Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. CVE-2026-75698Critical9.3no fix yet | | Critical9.3 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-89275Critical10.0no fix yet | | Critical10.0 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-89276Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. CVE-2026-83660Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-84412Critical10.0no fix yet | | Critical10.0 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-82008Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the... CVE-2026-82009Critical9.1no fix yet | | Critical9.1 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the... CVE-2026-82010Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. CVE-2026-82011Critical9.1no fix yet | | Critical9.1 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. CVE-2026-82013Critical9.9no fix yet | | Critical9.9 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. CVE-2026-82443Critical9.6no fix yet | | Critical9.6 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-75721Critical10.0no fix yet | | Critical10.0 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-75723Critical10.0no fix yet | | Critical10.0 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-75728Critical9.1no fix yet | | Critical9.1 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-73369Critical10.0no fix yet | | Critical10.0 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-75699Critical10.0no fix yet | | Critical10.0 | No fix yet |
| Sep 22 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. CVE-2026-75703Critical10.0no fix yet | | Critical10.0 | No fix yet |
| Sep 22 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). CVE-2026-94127Critical9.3fixed in BIG-IP Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, BIG-IP Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, BIG-IP Hotfix-BIGIP-17.1.3.5.0.41.14-ENG | | Critical9.3 | BIG-IP Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, BIG-IP Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, BIG-IP Hotfix-BIGIP-17.1.3.5.0.41.14-ENG |