ZDI publishes 10 advisories on 2026-09-16, including six 0days affecting Microsoft Windows, CrewAI, MindsDB, Airbyte, and BusyBox
The Zero Day Initiative published ten advisories on 2026-09-16 covering flaws in Microsoft Windows HTTP Proxy, CrewAI, MindsDB, Cisco Secure Firewall Management Center, NoMachine, Airbyte, BusyBox, and GIMP; six are unpatched 0days, CVSS scores run 5.3-8.8,…
On 2026-09-16, the Zero Day Initiative published ten vulnerability advisories: ZDI-26-703 through ZDI-26-710, ZDI-26-712, and ZDI-26-713 (no ZDI-26-711 appears among the provided reports). Six carry the (0Day) flag with no vendor patch referenced. ZDI-26-703 (CVE-2026-92203) and ZDI-26-704 (CVE-2026-92204), both CVSS 7.7, describe server-side request forgery flaws in the _get_shared_drive_object function of Airbyte's SharePoint and OneDrive connectors, each letting authenticated remote attackers trigger arbitrary server-side requests for information disclosure. ZDI-26-705 (CVE-2026-92205, CVSS 6.1) details a symlink directory traversal in BusyBox's libarchive enabling arbitrary file creation, requiring user interaction. ZDI-26-706 (CVE-2026-92206, CVSS 8.8) describes an unsafe reflection RCE in the CrewAI framework, exploited when a target loads a malicious agent configuration. ZDI-26-707 (CVE-2026-92207, CVSS 8.8) covers a code injection RCE in MindsDB's OpenBBtable feature, exploitable by authenticated remote users. ZDI-26-708 details an unpatched local privilege escalation in Microsoft Windows HTTP Proxy (CVSS 5.3) requiring prior low-privileged code execution; no CVE id is listed in that bulletin. Four advisories do not carry the 0day flag and their patch status is not stated: ZDI-26-709 describes unauthenticated deserialization of untrusted data in Cisco Secure Firewall Management Center's CommandSinkRmi component enabling RCE (CVE-2026-20242, CVSS 8.1); ZDI-26-710 describes an unauthenticated, network-adjacent heap-based buffer overflow in NoMachine's mDNS service enabling RCE (CVE-2026-92208, CVSS 8.8); ZDI-26-712 describes an unauthenticated SSRF in NoMachine's nxhtd server leading to information disclosure (CVE-2026-92210, CVSS 7.2); and ZDI-26-713 describes a stack-based buffer overflow in GIMP's APNG file parsing enabling RCE (CVE-2026-92183, CVSS 7.8), requiring user interaction such as visiting a malicious page or opening a malicious file. Source discrepancy: the MindsDB report's summary text cites ZDI-26-708, while its title and points identify the advisory as ZDI-26-707; ZDI-26-708 is separately assigned to the Windows HTTP Proxy advisory, so this summary follows the title/points attribution. CVSS scores range from 5.3 (Windows HTTP Proxy) to 8.8 (CrewAI, MindsDB, NoMachine mDNS). None of the reports state that exploitation has been observed in the wild.
- Ten ZDI advisories published 2026-09-16: ZDI-26-703, -704, -705, -706, -707, -708, -709, -710, -712, -713
- Six flagged 0day with no vendor patch referenced: ZDI-26-703, -704, -705, -706, -707, -708
- ZDI-26-703: SSRF in _get_shared_drive_object of Airbyte SharePoint connector, CVE-2026-92203, CVSS 7.7, requires authentication, 0day
- ZDI-26-704: SSRF in _get_shared_drive_object of Airbyte OneDrive connector, CVE-2026-92204, CVSS 7.7, requires authentication, 0day
- ZDI-26-705: symlink directory traversal in BusyBox libarchive enabling arbitrary file creation, CVE-2026-92205, CVSS 6.1, requires user interaction, 0day
- ZDI-26-706: unsafe reflection RCE in CrewAI framework, CVE-2026-92206, CVSS 8.8, requires loading a malicious agent configuration, 0day
- ZDI-26-707: code injection RCE in MindsDB OpenBBtable feature, CVE-2026-92207, CVSS 8.8, requires authentication, 0day
- ZDI-26-708: local privilege escalation in Microsoft Windows HTTP Proxy, CVSS 5.3, requires prior low-privileged code execution, no CVE listed in bulletin, 0day
Coverage timelineoldest first · each row is one article
- · 1d agoZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability
ZDI Published Advisories· 25
ZDI disclosed CVE-2026-92209, an improper authentication flaw in NoMachine's bundled Redis component allowing local privilege escalation (CVSS 7.8).
- · 1d agoZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability
ZDI Published Advisories· 45
ZDI disclosed an unpatched code injection RCE (CVE-2026-92207, CVSS 8.8) in MindsDB's OpenBBtable feature, exploitable by authenticated remote users.
- · 1d agoZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability
ZDI Published Advisories· 45
ZDI disclosed CVE-2026-20242, an unauthenticated deserialization flaw in Cisco Secure Firewall Management Center enabling remote code execution (CVSS 8.1).
- · 1d agoZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability
ZDI Published Advisories· 25
ZDI disclosed CVE-2026-92210, an unauthenticated server-side request forgery in NoMachine's nxhtd server leading to information disclosure (CVSS 7.2).
- · 1d agoZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability
ZDI Published Advisories· 50
ZDI discloses unpatched unsafe reflection RCE vulnerability CVE-2026-92206 (CVSS 8.8) in the CrewAI agent framework.
- · 1d agoZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability
ZDI Published Advisories· 40
ZDI disclosed CVE-2026-92208, an unauthenticated heap-based buffer overflow in NoMachine's mDNS service enabling network-adjacent remote code execution (CVSS 8.8).
- · 1d agoZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
ZDI Published Advisories· 30
ZDI disclosed CVE-2026-92183, a stack-based buffer overflow in GIMP's APNG file parsing that enables remote code execution (CVSS 7.8).
- · 1d agoZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability
ZDI Published Advisories· 50
ZDI disclosed an unpatched local privilege escalation flaw (CVSS 5.3) in Microsoft Windows HTTP Proxy, requiring prior low-privileged code execution.
- · 1d agoZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
ZDI Published Advisories· 38
ZDI disclosed an unpatched SSRF information disclosure flaw (CVE-2026-92204, CVSS 7.7) in Airbyte's OneDrive connector, requiring authentication.
- · 1d agoZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability
ZDI Published Advisories· 35
ZDI disclosed an unpatched symlink directory traversal flaw (CVE-2026-92205, CVSS 6.1) in BusyBox libarchive enabling arbitrary file creation.
- · 1d agoZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
ZDI Published Advisories· 38
ZDI disclosed an unpatched SSRF information disclosure flaw (CVE-2026-92203, CVSS 7.7) in Airbyte's SharePoint connector, exploitable by authenticated remote users.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20242 | Unauthenticated Java Deserialization RCE in Cisco Secure Firewall Management Center Cisco Secure Firewall Management Center (FMC) Software contains a critical insecure deserialization flaw (CWE-502) in its External Database Access feature. An attacker who controls a host listed in the FMC's external database access list can send a crafted serialized Java byte stream to a specific TCP port on the device. Because the deserialization is insecure and the attack is unauthenticated at the protocol level, a successful exploit lets the attacker execute arbitrary commands on the appliance and elevate privileges to root. All deployments of Cisco FMC with the External Database Access feature enabled are potentially affected, though exposure is substantially reduced when the FMC management interface is not reachable from the public internet. Exploitation status: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known. Do: Upgrade FMC to a fixed release per Cisco's security advisory as soon as one is published. As interim mitigation, review and restrict the external database access list to fully trusted hosts, limit which hosts can reach the affected TCP port, and ensure the FMC management interface is not exposed to the public internet. Verify configuration via the FMC admin console and monitor Cisco PSIRT for updates. | 9.8 | — |
| large≈10,000–100,000 FMC deployments worldwide, with likely only a few thousand management interfaces internet-exposed | ||
| CVE-2026-92183 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-92203 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-92204 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-92205 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-92206 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-92207 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-92208 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-92209 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-92210 | NVD description · AI analysis pending | — | — | — | — | — |