Cisco Identity Services Engine Authorization Bypass Vulnerabilities
Cisco fixed authorization bypass flaws in ISE and ISE-PIC web management letting authenticated admins modify file descriptions via crafted HTTP requests.
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine and ISE Passive Identity Connector result from missing server-side validation of Administrator permissions. An authenticated remote attacker with valid Administrator credentials can submit crafted HTTP requests to modify descriptions of files on specific pages. Cisco has released software updates addressing the issues.
Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability
Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.
Jenkins Security Advisory 2026-09-16
Jenkins released a security advisory patching vulnerabilities across 13 plugins, including GitLab, Bitbucket, Gradle, Keycloak Authentication, and Script Security.
The Jenkins security advisory dated September 16, 2026 addresses vulnerabilities in 13 plugins: Bitbucket Push and Pull Request, Bitbucket Server Integration, Coverage, Gitee, GitLab, Gradle, Keycloak Authentication, OWASP Dependency-Check, Pipeline: Groovy Libraries, Pipeline: Multibranch, Robot Framework, Script Security, and Warnings. Jenkins users should update the affected plugins to the patched versions listed in the advisory.
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Cisco disclosed a UEFI Secure Boot bypass in UCS servers and UCS-based appliances letting authenticated or physically present attackers execute unauthorized software.
Cisco published an advisory for a vulnerability in the UEFI Shell implementation of UCS servers and UCS-based appliances. Memory write commands remain available in the UEFI Shell while Secure Boot is enabled, allowing an attacker to modify UEFI memory and bypass validation checks to run unauthorized software. Exploitation requires either valid credentials for a user or admin account, or unauthenticated physical access to select the UEFI Shell boot option at boot time. The issue affects firmware boot integrity rather than the running operating system.
Null Pointer Dereference in Log Report
Fortinet patched a low-severity null pointer dereference (CVSS 2.5) in FortiOS, FortiProxy, and FortiPAM that lets authenticated attackers crash the httpsd daemon.
Fortinet advisory FG-IR-26-173 describes a NULL pointer dereference vulnerability (CWE-476) in FortiOS, FortiProxy, and FortiPAM, scored CVSSv3 2.5. An authenticated attacker can crash the httpsd daemon via crafted HTTP requests, causing a denial of service. The advisory was revised on 2026-09-08.
Open Redirect on FortiSIEM
Fortinet disclosed an open redirect flaw (CVSS 2.8) in FortiSIEM allowing authenticated attackers to redirect users to arbitrary websites via crafted HTTP requests.
Fortinet advisory FG-IR-26-169 covers an open redirect vulnerability (CWE-601) in FortiSIEM, rated CVSSv3 2.8. An authenticated attacker can cause a redirection to any website via specially crafted HTTP requests. The advisory was revised on 2026-09-08.
Arbitrary process termination from exposed minifilter communication port
Fortinet FortiClient Windows fortimon3 driver flaw (CVSS 4.7) lets authenticated attackers terminate arbitrary processes via exposed minifilter communication port.
Fortinet advisory FG-IR-26-165 discloses an unverified ownership vulnerability (CWE-283, CVSSv3 4.7) in the FortiClient Windows fortimon3 minifilter driver. An authenticated attacker can terminate arbitrary processes through an exposed minifilter communication port. The advisory was revised on 2026-09-08.
Broken Access control on Websocket streams
Fortinet FortiSOAR access control flaw (CVSS 4.9) lets zero-permission authenticated attackers subscribe to and inject broadcast messages into websocket streams.
Fortinet advisory FG-IR-26-164 discloses an improper access control vulnerability (CWE-284, CVSSv3 4.9) in FortiSOAR. An authenticated attacker with zero permissions can subscribe to websocket streams and topics and inject broadcast messages via crafted websocket requests. The advisory was revised on 2026-09-08.
Cisco Unified Intelligence Center SQL Injection Vulnerability
Cisco patched a blind SQL injection in Unified Intelligence Center's web interface allowing authenticated local attackers to read the internal database.
Cisco disclosed a blind SQL injection vulnerability in the web-based management interface of Unified Intelligence Center, caused by insufficient validation of user-supplied input. An authenticated local attacker can send crafted requests and read the contents of the device's internal database. Exploitation requires valid user credentials, and Cisco has released software updates.
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
Cisco fixed a stored cross-site scripting flaw in Industrial Ethernet 1000 series switches exploitable by authenticated remote users.
Insufficient validation of user-supplied input in the web-based management interface of Cisco Industrial Ethernet 1000 Series Switches allows stored XSS. An authenticated remote attacker can inject malicious code into specific interface pages and execute arbitrary script in another user's context. Exploitation requires valid credentials; Cisco has released software updates.
Server-Side Request Forgery (SSRF)
Fortinet discloses a low-severity SSRF in the FortiSIEM GUI allowing authenticated attackers to send requests from targeted devices.
Fortinet PSIRT advisory FG-IR-26-159, revised 2026-08-12, describes a server-side request forgery (CWE-918) in the FortiSIEM GUI, scored CVSSv3 3.4. An authenticated attacker can send HTTP requests originating from the targeted device via specially crafted requests, potentially enabling internal network probing. No CVE identifier or exploitation status is included in the advisory text.
Slack resets passwords for about 0.5% of its users due to the exposure of the salted password hashes
CareCam Pro IP Cameras
CISA advisory details hard-coded bootloader credential CVE-2026-85083 in ANJIA AJL33PC0801 CareCam Pro cameras, allowing physical-access firmware compromise.
CISA ICS advisory ICSA-26-251-01 describes CVE-2026-85083, a hard-coded credential (CWE-798) used for bootloader authentication in the ANJIA AJL33PC0801 CareCam Pro IP camera. An attacker with physical access could gain privileged bootloader access and modify firmware and configuration, potentially fully compromising the device. The flaw scores 6.8 on CVSS 3.1 (7.0 on CVSS 4.0), is not remotely exploitable, and no public exploitation has been reported. Affected firmware is linux_linux_202008261138_svn13796 with U-Boot 2010.06; the vendor is headquartered in China with worldwide deployments.
[Control systems] Schneider Electric security advisory (AV26-871)
Canada's Cyber Centre relayed Schneider Electric advisories for vulnerabilities in NetBotz 5-750/755 (5.5.2 and prior) and PowerChute Serial Shutdown (1.5 and prior).
The Canadian Centre for Cyber Security issued control-systems advisory AV26-871 noting Schneider Electric products affected by vulnerabilities as of September 1, 2026. Affected products include NetBotz 5-750/755 versions 5.5.2 and prior, and PowerChute Serial Shutdown versions 1.5 and prior, the latter with an improper restriction of excessive authentication attempts flaw. Administrators are urged to review Schneider Electric's security notifications and apply the suggested mitigations and updates.
Stack buffer overflow in WAD
FortiOS explicit proxy WAD daemon stack buffer overflow (CVSS 5.1) allows code execution only with Kerberos and SOCKS configured.
Fortinet advisory FG-IR-26-161 describes a stack-based buffer overflow (CWE-121) in the WAD daemon of FortiOS explicit proxy, scored CVSSv3 5.1. Exploitation requires an attacker able to bypass stack protection and ASLR, and the explicit proxy must be configured with Kerberos authentication and SOCKS enabled. If successful, it yields arbitrary code or command execution in the WAD daemon context via crafted sockets. No exploitation is reported in the advisory.
ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability
ZDI disclosed a Pwn2Own information disclosure flaw (CVSS 4.3) in Amazon Smart Plug, letting unauthenticated network-adjacent attackers access sensitive information.
The Zero Day Initiative published ZDI-26-557 for an insecure fallback information disclosure flaw in Amazon Smart Plug, demonstrated at Pwn2Own. Unauthenticated network-adjacent attackers can disclose sensitive information on affected installations. ZDI rated the issue CVSS 4.3.
ZDI-26-563: (Pwn2Own) Home Assistant Green Simple Service Discovery Protocol Server-Side Request Forgery Vulnerability
ZDI disclosed a Pwn2Own SSRF flaw (CVSS 5.4) in Home Assistant Green's SSDP server, letting unauthenticated network-adjacent attackers trigger arbitrary server-side requests.
The Zero Day Initiative published ZDI-26-563 for a server-side request forgery in the Simple Service Discovery Protocol server on Home Assistant Green. The bug was demonstrated at Pwn2Own and allows network-adjacent, unauthenticated attackers to initiate arbitrary server-side requests on affected installations. ZDI rated the issue CVSS 5.4.