Weekly recap led by actively exploited Cisco ISE auth-bypass CVE-2026-76460 (CVSS 10.0), plus Plugin4Shell AI-agent RCE and KREMLIN banking malware.
Cisco warned that maximum-severity CVE-2026-76460 (CVSS 10.0), an authentication bypass in Identity Services Engine caused by insufficient authentication control on an API endpoint, is under active exploitation by unauthenticated remote attackers. Other stories include Hacktron using Claude Opus 5 to chain an OpenAI SSO misconfiguration with libheif RCE CVE-2026-32882 to access employee ChatGPT accounts and internal repositories (fixed in 14 hours), and Plugin4Shell, a zero-click RCE bypassing SHA-pinning verification in Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. Elastic also documented the KREMLIN Brazilian banking malware tracked as REF9334 using malicious Chrome/Edge extensions since May 2025, and US authorities seized two NightmareStresser DDoS-for-hire domains. OpenAI disclosed six new model misalignment incidents with a new reporting framework.
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-70416+1 related CVE | Unauthenticated Deserialization RCE in Dell ObjectScale Dell ObjectScale, Dell's Kubernetes-based enterprise object storage platform, contains a deserialization of untrusted data flaw (CWE-502) in all versions prior to 4.4.0.0. An unauthenticated attacker with remote network access to a vulnerable deployment can supply maliciously crafted serialized data to trigger the flaw, requiring no credentials or user interaction. Successful exploitation results in remote code execution, and the CVSS scope change (S:C) with high confidentiality, integrity, and availability impacts indicates a compromise could extend beyond the vulnerable component to the wider cluster or host. All Dell ObjectScale deployments running versions before 4.4.0.0 are affected. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Upgrade Dell ObjectScale to version 4.4.0.0 or later per Dell's security advisory. Until patched, restrict network access to ObjectScale management and service interfaces to trusted networks only, since the flaw is exploitable remotely without authentication. Review Dell's advisory for related ObjectScale fixes shipped in the same release and monitor for updates. | 9.8 group max | — |
|
| Type | Indicator | Context |
|---|---|---|
| domain | brevo.com | hours, the Worker injected a malicious script into pages of brevo.com and sibforms.com and into three JavaScript files that custo |
| domain | sibforms.com | ker injected a malicious script into pages of brevo.com and sibforms.com and into three JavaScript files that customers embed on the |
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.
The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not always more clarity.
Nothing here needs much drama. Just a lot of small doors left open. Here’s what happened.
Cisco Warns of Actively Exploited ISE Auth Bypass — Cisco warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface."
Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.
Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-58138 (Orkes Conductor), CVE-2026-58704 (Google Pixel), CVE-2026-90894 aka ParaShells (Parallels Desktop), CVE-2026-82079 (Nintendo Switch), CVE-2026-89049 (AWS Systems Manager Agent), CVE-2026-43502 aka ZcopyReaper, CVE-2026-80844 aka DirtyAH6, CVE-2026-81000 aka TUNderflow, CVE-2026-68121 aka PPPoEject, CVE-2026-74469 aka DiagSpill (Linux kernel), CVE-2026-70416, CVE-2025-43936 (Dell ObjectScale and Elastic Cloud Storage), CVE-2026-68488 (Please Backup Manager), CVE-2026-56711, CVE-2026-73324 (VLC Media Player), CVE-2026-65638 (cPanel ConfigServer Security & Firewall), CVE-2026-85982, CVE-2026-78626, CVE-2026-78623 (Okta), CVE-2026-0310 (Palo Alto Networks PAN-OS), CVE-2026-85061 (MapLibre GL JS), GHSA-rvhw-4hpw-9vrx, GHSA-rrgq-978q-36mq, GHSA-4xhx-8cv5-wh62, GHSA-8v35-895w-232p (ArangoDB), CVE-2026-65812 (Microsoft Teams for Android), CVE-2026-80172, CVE-2026-61410, CVE-2026-80238 (Dell Secure Connect), CVE-2026-18851 (Ivanti Endpoint Manager Mobile), CVE-2026-91721, CVE-2026-91749, CVE-2026-91726, CVE-2026-93374, CVE-2026-93372 (Google Chrome), CVE-2026-92033, from CVE-2026-92005 to CVE-2026-92013, from CVE-2026-92015 to CVE-2026-92020, from CVE-2026-92022 to CVE-2026-92029, from CVE-2026-92034 to CVE-2026-92038 (Mozilla Firefox), CVE-2026-15315, CVE-2026-15316 (TP-Link Tapo cameras), CVE-2026-82232, CVE-2026-77147, CVE-2026-73178 (Apache Syncope), CVE-2026-76669, CVE-2026-76670, CVE-2026-76672, CVE-2026-76673, CVE-2026-76674 (HPE Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator), CVE-2026-73693, CVE-2026-73694, CVE-2026-73698, CVE-2026-73699 (FileRun), CVE-2026-39919 (Ghostscript), CVE-2026-91998 (Casdoor), CVE-2026-91932, CVE-2026-91931 (Flowise), CVE-2026-65400, CVE-2026-65414, CVE-2026-65346, CVE-2026-84607, CVE-2026-43790 (Apple), CVE-2026-90999 (Sentry Seer), CVE-2026-77692, CVE-2026-76163, CVE-2026-19667, CVE-2026-19666, CVE-2026-80274 (ISC BIND 9), CVE-2026-91843 (Check Point), CVE-2026-77179 (Docker), CVE-2026-81642, CVE-2026-82717 (Unbound DNS), Click2Shell (WordPress), CVE-2026-28326, CVE-2026-28323, CVE-2026-28309, CVE-2026-28306, CVE-2026-28308, CVE-2026-28310, CVE-2026-28314, CVE-2026-28313, CVE-2026-28307, CVE-2026-28305, CVE-2026-28317, CVE-2026-28304, CVE-2026-28312, CVE-2026-28316, CVE-2026-28311, CVE-2026-28302, CVE-2026-28321, CVE-2026-28315 (SolarWinds), CVE-2026-89026 (Issabel Framework), CVE-2026-78175 (Tutor LMS), an operating system command injection vulnerability in Dokploy, and a pickle deserialization vulnerability in MLflow.
The lesson this week is pretty basic: trust less, check more. A familiar tool, package, login flow, browser prompt, or cloud setup can still be the weak spot. Old payloads can come back, exposed systems still get found, and "trusted" does not mean "safe."
The other lesson is speed. Attack paths are getting shorter, research is getting faster, and weak defaults do not stay quiet for long. Patch what matters, watch what is exposed, and do not assume the boring stuff is harmless. That is usually where the week starts.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html
| CVE-2026-0310 | Buffer Overflow in PAN-OS XML Processing Enables Root RCE on PA-Series Firewalls Palo Alto Networks PAN-OS contains a buffer overflow (CWE-787, out-of-bounds write) in its XML processing functionality. An unauthenticated attacker with network access to the management web interface or the dataplane interface can send malicious XML input to trigger the flaw. On PA-Series hardware firewalls this allows arbitrary code execution with root privileges, while on VM-Series virtual firewalls the impact is limited to a denial-of-service condition. Panorama centralized management is also affected, and exposure is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild (CVSS 4.0 marks exploitability as unproven). Do: Patch to a fixed PAN-OS release as soon as Palo Alto Networks publishes fixed versions, prioritizing PA-Series firewalls and Panorama where root code execution is possible; the advisory does not name specific fixed builds, so consult the vendor advisory for branch-specific updates. Until patching, restrict access to the management web and dataplane interfaces to trusted internal IP addresses per the vendor's management-access hardening guidance, and audit which firewalls, VM-Series instances, and Panorama servers have these interfaces reachable from untrusted networks. Monitor Palo Alto Networks advisories for updates on exploitation status and proof-of-concept releases. | 7.2 | — |
| largetens of thousands of exposed PAN-OS systems (public internet scans have historically shown on the order of 10,000-50,000 PAN-OS management and dataplane… |
| CVE-2026-18851 | Missing Authorization in Ivanti Endpoint Manager Mobile Allows Admin Privilege Escalation CVE-2026-18851 is a missing-authorization flaw (CWE-862) in Ivanti Endpoint Manager Mobile (EPMM) in which certain functionality fails to verify that an authenticated user is authorized to perform administrative actions. A remote attacker who already holds a valid low-privilege session can send crafted requests over the network, with no user interaction required, and escalate to administrator. From an admin position, the attacker gains full control of the mobile device management console, including access to managed-device data and the ability to alter or push configurations to enrolled devices. Organizations running EPMM versions before 12.10.0.0, 12.9.0.2, or 12.8.0.4 are affected. As of the advisory there is no known in-the-wild exploitation and no public proof-of-concept, it is not in CISA KEV (EPSS ~1.0%), and it was patched as part of a larger Ivanti batch covering EPMM, Neurons for ITSM and Sentry flaws enabling RCE and admin access. Do: Upgrade EPMM to 12.10.0.0, 12.9.0.2, or 12.8.0.4 depending on the release branch in use, per Ivanti's advisory. Until patched, restrict EPMM console/API interfaces to trusted networks and review logs for authenticated users performing unexpected administrative actions. Because this fix ships in the same batch as other EPMM, Neurons for ITSM and Sentry patches, apply the full set of vendor updates rather than only this CVE. | 8.8 | 1% |
| massplausibly >1,000,000 managed devices/users across tens of thousands of enterprise and government deployments |
| CVE-2026-32882 | libheif is a HEIF and AVIF file format decoder and encoder libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0. NVD description · AI analysis pending | 7.1 | <1% | — | — |
| CVE-2026-43502 | Linux kernel: net/rds: handle zerocopy send cleanup before the message is queued In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. However, zerocopy ownership is really determined by the presence of op_mmp_znotifier, regardless of whether the message has reached the socket queue. Capture op_mmp_znotifier up front in rds_message_purge() and use it as the cleanup discriminator. If the message is already associated with a socket, keep the existing completion path. Otherwise, drop the pinned page accounting directly and release the notifier before putting the payload pages. This keeps early send failure cleanup consistent with the zerocopy lifetime rules without changing the normal queued completion path. NVD description · AI analysis pending | 7.8 | <1% |
| — |
CVE-2026-56711+1 related CVE | Heap buffer overflow in VLC media player via integer overflow in picture allocation VLC media player contains an integer overflow (CWE-190) in its picture buffer allocation: in AllocatePicture (src/misc/picture.c) the byte total is accumulated with 32-bit arithmetic, so for very large picture dimensions the product of plane pitch and lines wraps before it is widened to a 64-bit size, and both existing guard checks evaluate only the already-wrapped value. As a result, aligned_alloc reserves a much smaller buffer than the picture actually requires, and a crafted PNG whose IHDR chunk declares very large width and height values - which reaches the code through the image demuxer that only limits the input file's byte count, not the declared dimensions - causes the PNG decoder (modules/codec/png.c) to write past the end of the allocation with attacker-influenced length and content (CWE-787). Opening the malicious PNG file directly or through a playlist entry is sufficient to trigger the flaw under default settings, and per the high CVSS 4.0 score (8.6) the attacker gains high confidentiality, integrity, and availability impact on the player process, i.e., controlled heap corruption that can crash VLC and potentially execute code. All VLC users who open untrusted image files are potentially affected; the available data does not specify affected version ranges. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, so no exploitation has been reported to date. Do: Until a patched VLC release is available, avoid opening untrusted PNG image files or playlist entries referencing images with VLC, and consider setting a different application as the default PNG handler. No fixed version is specified in the available data, so monitor VideoLAN advisories for an update addressing CVE-2026-56711 and apply it promptly when released. | 7.3 group max | <1% |
| massplausibly hundreds of millions of desktop installations (VLC has billions of cumulative downloads) |
| CVE-2026-58138 | Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS… Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls. NVD description · AI analysis pending | 9.3 | 9% | — | — |
| CVE-2026-58704 | Permission Bypass in Google Pixel Cellular Modem Allows Proximal Privilege Escalation A logic error in the cellular modem component causes an improper authorization check (CWE-285/CWE-693), allowing a permission bypass. An attacker who already has low privileges and is on an adjacent network (proximal, e.g., a hostile local or cellular-adjacent network) can trigger the flaw without any user interaction, and successful exploitation yields remote escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). The flaw was assigned through Google's device security CNA (dsap-vuln-management@google.com), consistent with modem firmware shipped in Google Pixel-class devices; specific affected firmware versions were not provided in the source data. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and there is no evidence of exploitation in the wild. Defenders should treat this as a patch-on-next-bulletin item unless devices operate in high-risk adjacent-network environments. Do: Install the latest Google monthly security update that includes the cellular modem firmware patch and verify the device's security patch level reflects it. Because exploitation requires network adjacency plus some existing privilege, prioritize devices used in high-risk or shared-network settings and watch for indicators of rogue femtocell/base-station or hostile local-network activity. With no public PoC or KEV listing, standard monthly patch cadence is reasonable outside those high-risk scenarios. | 8.8 | <1% | KEV |
| masstens of millions of devices (≈10M+ active Pixel-class handsets worldwide) | KEV |
CVE-2026-61410+1 related CVE | Missing Authorization Allows Unauthenticated RCE in Dell Secure Connect Gateway 5.0 CVE-2026-61410 is a missing-authorization flaw (CWE-862) in Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated attacker with remote network access can send specially crafted requests that bypass the application's intended restrictions on code execution, triggering remote command execution on the gateway host. Given the CVSS 9.4 vector (high confidentiality and integrity impact, low availability impact), a successful attacker effectively gains broad control over the system, and related reporting also describes unauthenticated RCE and admin access on affected SCG deployments. Any organization running the affected SCG 5.x builds — typically enterprises using SCG as the on-premises gateway that connects Dell EMC infrastructure to Dell support services — is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a modest 1.3% probability of exploitation within 30 days. Do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later, per Dell's advisory. Until patched, restrict network access to the SCG web interface (allowlists, VPN, or firewall rules) and avoid exposing it directly to the internet, and check gateway logs for unexpected or malformed requests. Inventory both appliance and application editions, since each has a separate fixed version. | 9.4 group max | 1% |
| largeon the order of tens of thousands of enterprise deployments (10k–100k systems; estimate |
| CVE-2026-65638 | Unauthenticated shell command injection in ConfigServer Security & Firewall (CSF) CVE-2026-65638 is an unauthenticated shell command injection flaw (CWE-78) in ConfigServer Security & Firewall (CSF), caused by improper escaping of a request URL. An attacker who sends a crafted request URL containing shell metacharacters to the affected web-facing component can have arbitrary commands executed under the CSF service account. Successful exploitation therefore yields command execution on the server in the context of the CSF service account, with a critical CVSS 4.0 score of 9.2 reflecting high confidentiality, integrity, and availability impact on the vulnerable system. The flaw affects versions originally distributed by ConfigServer as well as versions of the WebPros-maintained fork that contain the vulnerable code; WebPros has fixed it in version 16.30, and other independently maintained CSF forks should be evaluated separately. There is no public proof of concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported to date. Do: Upgrade the WebPros-maintained CSF fork to version 16.30 or later and verify which fork and version your deployment actually uses. If you run the original ConfigServer distribution or a third-party fork, monitor the respective maintainer for a patched release and assess your version independently. Until patched, restrict unauthenticated access to the CSF web interface (e.g., limit it to trusted management networks or localhost/VPN) and watch for unexpected command execution by the CSF service account. | 9.2 | — |
| masslikely on the order of 100,000+ hosting server installations (order-of-magnitude estimate; exact published counts not available) |
| CVE-2026-65812 | Sensitive Information Disclosure in Microsoft Teams for Android CVE-2026-65812 is an information disclosure flaw (CWE-201) in Microsoft Teams for Android in which the client inserts sensitive information into data it sends over the network. Per the CVSS vector, an authorized (authenticated, low-privilege) attacker can trigger the condition, user interaction is required, and the changed-scope metric indicates the sensitive data crosses a security boundary to another trust zone. A successful exploit discloses confidential information, with no impact on data integrity or availability. Only users running the Android Teams client are named as affected; other Teams platforms are not specified in this data. No public proof-of-concept or in-the-wild exploitation is known, and EPSS estimates only about a 0.5% chance of exploitation within 30 days. Do: Update Microsoft Teams for Android to the latest build distributed via Google Play (or via Intune/MDM-managed app updates) and verify installed client versions on managed devices. Because exploitation requires an authenticated attacker and user interaction, prioritize patching users who handle highly sensitive data. Monitor Microsoft's advisory for the specific fixed version, which is not stated in this data. | 6.8 | <1% |
| masstens of millions of Android users (Teams has hundreds of millions of monthly active users overall and a very large Google Play install base for the Android… |
| CVE-2026-68121 | Use-After-Free in Linux Kernel PPPoE Send Path Enables Local Root (PPPoEject) CVE-2026-68121 is a use-after-free in the Linux kernel's PPPoE implementation: pppoe_sendmsg() caches a pointer to the PPPoE header before calling dev_hard_header(), but device header callbacks are allowed to reallocate the socket buffer head, leaving that pointer dangling. The race is triggered when a send blocks in copy_from_user() while the first non-Ethernet port is added to an empty team device, causing the team's delegated GRE header callback to expand the skb head; PPPoE then writes six bytes through the stale pointer into freed memory. A local attacker can leverage this memory corruption for privilege escalation, reportedly reaching a root shell as one of four recently disclosed Linux kernel LPE flaws dubbed 'PPPoEject'. Any Linux system with PPPoE support enabled is potentially affected, though practical exploitation requires local code execution plus the uncommon combination of a PPPoE socket and a team device. A public proof-of-concept has been published on GitHub, but the flaw is not in CISA's KEV catalog and EPSS remains low at 0.1%. Do: Update to the latest stable or vendor-supplied kernel that includes the upstream fix ('pppoe: reload header pointer after dev_hard_header()') as soon as your distribution backports it. Until patched, restrict local untrusted code execution on PPPoE-connected hosts and avoid combining PPPoE interfaces with team bonding devices or adding non-Ethernet ports to team devices on such hosts. Verify with your kernel vendor whether your running kernel contains the corrected pppoe_sendmsg() and watch distribution security advisories for the backport. | 7.8 | <1% | PoC |
| massHundreds of millions of Linux installations ship the vulnerable PPPoE code (enabled by default in mainstream distributions), though PPPoE-plus-team-device… |
| CVE-2026-68488 | TOCTOU Symlink Race in Plesk Allows Local Privilege Escalation to Root CVE-2026-68488 is a Time-of-check Time-of-use (TOCTOU) race condition in Plesk that causes the software to insecurely follow symbolic links (CWE-367). An attacker who already holds a low-privileged account on the server (for example, a hosting customer on a shared host) can race a privileged Plesk file operation, swapping in attacker-controlled symlinks so that the operation acts on files or directories of the attacker's choosing. By winning the race, the attacker takes ownership of arbitrary files or directories, which the vendor states leads to privilege escalation to root on the host. This means any multi-tenant or single-tenant server running Plesk where untrusted users have local access is at risk of full root compromise. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported. Do: Apply the patched Plesk release referenced in the vendor security advisory (no fixed version number is available in the data provided, so check Plesk's advisory for the exact build). In the interim, restrict or review low-privileged shell access for tenants on Plesk servers and audit cron/backup tasks that run as root, since the race likely targets such privileged file operations. Check system files and directories for unexpected ownership changes, and prioritize hosts hosting untrusted customers. | 9.9 | — |
| largetens to hundreds of thousands of Plesk-managed servers worldwide (estimated; no install-base figure in the provided data) |
| CVE-2026-74469 | Linux kernel: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit… In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in transport_addr_list. After the wrap, a diagnostic dump reserves an empty payload and writes 8 MiB of peer addresses past the skb tail. Reject a new unique peer when transport_count has reached U16_MAX. Perform the check after the existing-peer lookup so a duplicate address continues to return its existing transport at the limit. NVD description · AI analysis pending | 8.8 | <1% |
| — |
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | 14% | KEV PoC |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces | KEV |
CVE-2026-78623+1 related CVE | SQL Injection in Okta Access Gateway via Unsanitized SAML Assertion Values Okta Access Gateway (CVE-2026-78623, CWE-89) fails to sanitize SAML assertion values before they are interpolated into database queries when the datastore is configured in advanced mode. Because the unsanitized values are substituted directly into the query string prior to statement preparation, an attacker whose crafted SAML assertion is processed by the gateway can cause unintended SQL execution against the configured backend database. Successful exploitation yields a high-confidentiality impact (exposure of backend database data) with limited integrity and availability impact, and the changed-scope score (S:C) means the backend database can be affected beyond the gateway component. Organizations running Okta Access Gateway with an advanced-mode datastore backed by a SQL database are affected; no specific affected version range is provided in the available data. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days. Do: Check whether your Access Gateway datastore is configured in advanced mode against a SQL backend; if so, apply the remediation version or mitigation specified in Okta's security advisory, since no fixed version is stated in the available data. Review the backend database's query logs for anomalous or malformed SQL and constrain which SAML assertion attributes are passed into datastore queries. Because exploitation requires crafted assertion values with low-privilege access, also validate that assertion attribute values follow expected formats as an interim hardening measure. | 9.9 group max | <1% |
| moderate≈1,000–10,000 deployed Access Gateway instances worldwide (order-of-magnitude estimate) |
| CVE-2026-80172 | Unauthenticated Token Replay Flaw in Dell Secure Connect Gateway 5.0 Dell Secure Connect Gateway (SCG) 5.0 contains an Insufficient Verification of Data Authenticity flaw (CWE-345) that lets an unauthenticated remote attacker replay a previously captured request to obtain ADMIN access and refresh tokens. Because the product performs no nonce validation and imposes no time limit on requests, the same captured request can be reused indefinitely to mint new privileged tokens. An attacker gains persistent, unauthorized administrative access to the gateway, which serves as the connectivity hub between Dell customer environments and Dell support services. Organizations running SCG 5.0 Appliance prior to 5.36.00.16 or SCG 5.0 Application prior to 5.36.00.00 are affected. Exploitation has not been observed so far: EPSS puts 30-day exploitation probability at 0.3%, the flaw is not in CISA KEV, and no public proof-of-concept is known. Do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later as soon as possible. Until patched, restrict network access to the gateway's interface to trusted hosts and review recent authentication activity, since any captured request can be replayed indefinitely to obtain ADMIN tokens; consider rotating credentials and tokens if unauthorized access is suspected. | 9.8 | <1% |
| largeon the order of tens of thousands of enterprise deployments worldwide |
| CVE-2026-80844 | Out-of-bounds memory access in Linux kernel AH6 (xfrm) enables local privilege escalation The Linux kernel's IPv6 Authentication Header implementation (net/ipv6/ah6, part of xfrm) fails to validate the segments_left field of an IPv6 routing header before rearranging addresses for ICV computation, so a crafted raw IPv6 (IP_HDRINCL) packet with hdrlen=2 but segments_left=255 drives pointer arithmetic and a memmove roughly 4,064 bytes out of bounds. A local attacker who can open raw sockets (e.g., holding CAP_NET_RAW, which is commonly granted in containers) can trigger this kernel memory corruption — publicly tracked under the name 'DirtyAH6' — and potentially escalate privileges to root. Any Linux system whose kernel includes IPv6 AH support (the ah6 module) is affected, which spans most mainstream distribution kernels on servers, cloud hosts, containers, and embedded devices. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a 0.2% probability of exploitation within 30 days (9th percentile). Do: Update to a kernel containing the upstream xfrm/ah6 fix once your distribution ships it (no fixed version number appears in the source data, so follow distro advisories for CVE-2026-80844). As interim mitigations, blacklist or avoid loading the ah6 module if you do not use IPsec AH, and remove or restrict CAP_NET_RAW from containers and unprivileged users. Check exposure on hosts with 'lsmod | grep ah6' and audit container runtime capability grants for CAP_NET_RAW. | — | <1% | PoC ×2 |
| mass≈10^8–10^9 Linux systems ship the affected code path (kernel ubiquitous; ah6 compiled into most mainstream distro kernels), though only… |
| CVE-2026-81000 | Linux kernel TUN/TAP headroom integer underflow enables local memory corruption An integer underflow in the Linux kernel's TUN/TAP driver (net/tun.c) lets tun_get_user() compute a negative linear data size when the configured headroom (tun->align) exceeds the one-page skb-head budget; the value wraps when stored as a size_t, so tun_alloc_skb() can place skb->data outside the allocated buffer. The oversized headroom can be set locally or propagated to a TUN/TAP port by Open vSwitch when packets arrive from another port, so triggering requires injecting packets into a TUN/TAP device with a large alignment value, which needs local access with privileges. Successful exploitation corrupts kernel memory adjacent to the skb, giving a local attacker full confidentiality, integrity, and availability impact (CVSS 7.8), i.e., potential ring-0 code execution and complete host compromise. Any system running a kernel with the vulnerable tun_get_user() logic is affected, with VPN gateways, container hosts, and Open vSwitch/SDN deployments the most likely exposure paths. No public PoC is known, the flaw is not in CISA's KEV, and no exploitation in the wild has been reported. Do: Apply a kernel update containing the upstream fix commit "net: tun: bound receive headroom" as soon as your distribution or vendor backports it. In the interim, restrict access to /dev/net/tun and CAP_NET_ADMIN for untrusted local users and containers, and review Open vSwitch bridges that forward traffic from ports with large headroom requirements into TUN/TAP ports. Monitor kernel logs for OOPS or BUG output in the tun_get_user/tun_alloc_skb paths as a sign of attempted abuse. | 7.8 | <1% | PoC ×2 |
| mass≈hundreds of millions of devices run kernels containing the affected driver; millions of hosts actively use TUN/TAP (VPN gateways, container networking, Open… |
| CVE-2026-82079 | Stack Buffer Overflow in Nintendo Switch Local Wireless Enables Nearby-Attacker RCE CVE-2026-82079 is a stack-based buffer overflow (CWE-121) in the Nintendo Switch's local wireless networking functionality, affecting system software versions before 23.0.0. An attacker who is physically within wireless range of a console can send crafted network traffic that overruns a stack buffer during local wireless communication. Using return-oriented programming (ROP), the attacker can achieve arbitrary code execution on the console, consistent with the high-impact (8.4) CVSS score covering confidentiality, integrity, and availability. All Nintendo Switch consoles running system software earlier than 23.0.0 are affected; exploitation requires close physical proximity rather than internet access. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Update Nintendo Switch system software to 23.0.0 or later via System Settings > System > System Update; consoles connected to the internet typically download system updates automatically, but verify the installed version manually. Until updated, restrict local wireless (local multiplayer) play to trusted nearby users, since an attacker must be within wireless range and there is no internet-facing exposure. With no public PoC or known in-the-wild exploitation, patching is precautionary rather than urgent. | 7.0 | — |
| mass≈150 million consoles (Nintendo's cumulative Switch hardware sales) |
| CVE-2026-85061 | Sanitization Bypass (DOM XSS) in MapLibre GL JS Attribution Control MapLibre GL JS, an interactive vector tile map library for web browsers distributed via npm, contains a cross-site scripting flaw (CWE-79) in DOM.sanitize() in src/util/dom.ts: the code iterates elem.attributes as a live NamedNodeMap while removeAttributes() deletes entries from that same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied custom attributions can supply consecutive dangerous attributes, so an event-handler attribute such as onload or ontoggle survives sanitization. The surviving attribute executes when the attribution control inserts the content into the page via innerHTML and the victim renders the affected map content — no interaction beyond viewing the map is required, which is why coverage describes it as a zero-click XSS. Any website or application embedding a vulnerable MapLibre GL JS version and rendering attacker-influenced attributions is affected; successful exploitation gives the attacker arbitrary JavaScript execution in the trusted site's origin, useful for credential/session theft or content manipulation. Exploitation is not yet confirmed: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.3% probability of exploitation within 30 days, despite the critical CVSS 3.1 score of 10. Do: Upgrade to MapLibre GL JS 6.4.1 or later, which fixes the live NamedNodeMap iteration bug in DOM.sanitize(). In the interim, strip or validate event-handler attributes (e.g., onload, ontoggle) from third-party style attribution strings and user-supplied custom attributions before they reach the map library, and check npm lockfiles for maplibre-gl versions below 6.4.1. | 10.0 | <1% |
| mass≈2.7M users of MapLibre-embedded sites (per related news coverage of this flaw) |
| CVE-2026-85982 | Stored XSS in Auth0 AD/LDAP Connector Admin Panel The Auth0 AD/LDAP Connector fails to properly HTML-encode directory data shown in search results and updater log content within its admin panel, allowing stored Cross-Site Scripting (CWE-79). An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector runs, can insert script content that is later rendered to an administrator. When an administrator views the affected search results or update logs, the injected script executes in the admin's browser, enabling session-context actions with high confidentiality, integrity, and availability impact per the CVSS scope-changed rating (9.0, critical). Only organizations running the self-hosted Auth0 AD/LDAP Connector to federate on-premises Active Directory/LDAP with Auth0 are affected. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so no active exploitation is currently known. Do: Update the AD/LDAP Connector to the fixed release published by Okta/Auth0 (consult the vendor advisory for the exact patched version, since none is listed here), and verify via the connector's updater/admin panel that the new build is deployed. In the meantime, restrict which accounts can modify directory attributes and limit local logon access on the connector host, and have administrators inspect any directory attribute values or updater log entries from untrusted users before viewing them in the admin panel. | 9.0 | <1% |
| moderate≈ low thousands of installations (self-hosted enterprise connector) |
| CVE-2026-89049 | SSRF in AWS Systems Manager Agent can expose instance IAM role credentials AWS Systems Manager Agent (SSM Agent) versions before 3.3.4851.0 on all platforms contain a server-side request forgery (CWE-918) in the port-forwarding-to-remote-hosts functionality, caused by improper validation of equivalent address representations (CWE-1289) when checking destination hosts against the remote destination denylist. An authenticated remote user with privileges to start an SSM Session Manager port-forwarding session can supply a crafted destination host value that expresses a denied link-local address in an alternate representation, bypassing the denylist and causing the agent to reach link-local endpoints such as the instance metadata service. From there, the attacker can potentially obtain the managed instance's temporary IAM role credentials and then act with that role's permissions from outside the instance, producing high confidentiality impact on the node and on downstream systems reachable with the role. The flaw affects any organization running affected SSM Agent versions on managed nodes, including EC2 instances, hybrid-activated on-premises servers, VMs and edge devices. No public proof-of-concept is known and the issue is not in the CISA KEV catalog, so no active exploitation is known at this time. Do: Upgrade SSM Agent to version 3.3.4851.0 or later on every managed node across all platforms (EC2 instances, hybrid-activated on-premises servers, VMs and edge devices), and inventory current agent versions via Systems Manager to find stragglers. As interim risk reduction, restrict IAM permissions for initiating Session Manager port-forwarding sessions and scope managed-instance IAM roles tightly so stolen role credentials have limited downstream access. | 8.5 | — |
| masslikely millions of SSM-managed instances/nodes (SSM Agent ships by default in Amazon Linux and many AWS machine images) |
| CVE-2026-90894 | Local Root Privilege Escalation in Parallels Desktop via tar Argument Injection Parallels Desktop on macOS runs its prl_disp_service daemon as root and exposes it on the world-writable Unix socket /var/run/prl_disp_service.socket, where PrlSrv_LoginLocal authenticates clients purely on peer credentials without checking for a Parallels signature or administrator group membership. Once connected, any local user can call PrlSrv_InstallAppliance and supply an appliance folder path (sVmParentPath) that gets embedded in the command string tar -xf "%1" -C "%2"; because Qt's QProcess::splitCommand re-splits the string into words, an embedded quote closes the argument early and turns leftover text into attacker-chosen tar flags. macOS tar's --use-compress-program option then executes the named program, giving the attacker arbitrary code execution as root — a full local privilege escalation from any unprivileged account on the Mac. All Macs running an affected Parallels Desktop build (the advisory does not specify version ranges) with additional local user accounts are exposed. No public proof of concept is known and the CVE is not in CISA's KEV catalog, so there is no evidence of in-the-wild exploitation at this time. Do: Update Parallels Desktop to the newest available release as soon as the vendor ships a fix — no patched version is named in this advisory, so check the Parallels security bulletin directly. Until patched, treat any Mac running Parallels Desktop with local untrusted or shared accounts (e.g., guest, student lab, or kiosk logins) as exposed to full root compromise, and restrict local account creation on those machines. Monitor prl_disp_service for unexpected child processes, particularly tar invocations carrying --use-compress-program or odd -C paths from appliance installs. | 7.8 | — |
| masslikely millions of Macs (Parallels Desktop is the leading commercial macOS virtualization product; no affected-version install counts published) |
CVE-2026-91749+1 related CVE | Critical Use-After-Free in Google Chrome Workers Enables Sandbox Escape CVE-2026-91749 is a critical-severity use-after-free vulnerability (CWE-416) in the Workers component of Google Chrome, fixed in version 153.0.8010.47. A remote attacker triggers the flaw by luring a victim to a crafted HTML page, where a freed memory object in the Worker implementation is improperly reused, potentially allowing arbitrary code execution outside the browser sandbox. Successful exploitation means a malicious webpage can escape Chrome's sandbox and run code on the underlying operating system with the user's privileges, effectively fully compromising the workstation. All Chrome installations prior to 153.0.8010.47 are affected on every platform, and third-party Chromium-based browsers inherit the vulnerable engine code until they ship the upstream fix. No public proof-of-concept is known and the bug is not on CISA's Known Exploited Vulnerabilities catalog, but the Critical severity rating indicates Google judged the potential impact to be severe. Do: Update Google Chrome to version 153.0.8010.47 or later immediately and verify via chrome://settings/help; enterprises should confirm update policies have applied the fix fleet-wide. Because exploitation requires only that a victim visit a crafted page, defenders should monitor EDR telemetry for renderer/worker-process crashes or unexpected child processes spawned by Chrome until the fleet is fully patched. Administrators of Chromium-based browsers that bundle the same engine (e.g., Edge, Brave, Vivaldi, Opera) should deploy those vendors' equivalent updates as soon as they are released. | 9.6 group max | — |
| mass≈3 billion users potentially exposed at patch release (Chrome's global installed base) |