ZeroHour
Story · 1 source · 11 articlesfirst updated ()2

ZDI publishes 10 advisories on 2026-09-16, including six 0days affecting Microsoft Windows, CrewAI, MindsDB, Airbyte, and BusyBox

What's new: Expanded from the two previously covered Airbyte advisories (ZDI-26-703, ZDI-26-704) to the full batch of ten ZDI advisories published on 2026-09-16. Added eight newly reported advisories: ZDI-26-705 (BusyBox libarchive file creation), ZDI-26-706 (CrewAI RCE), ZDI-26-707 (MindsDB RCE), ZDI-26-708 (Microsoft Windows HTTP Proxy privilege escalation), ZDI-26-709 (Cisco Secure Firewall Management…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

The Zero Day Initiative published ten advisories on 2026-09-16 covering flaws in Microsoft Windows HTTP Proxy, CrewAI, MindsDB, Cisco Secure Firewall Management Center, NoMachine, Airbyte, BusyBox, and GIMP; six are unpatched 0days, CVSS scores run 5.3-8.8,…

On 2026-09-16, the Zero Day Initiative published ten vulnerability advisories: ZDI-26-703 through ZDI-26-710, ZDI-26-712, and ZDI-26-713 (no ZDI-26-711 appears among the provided reports). Six carry the (0Day) flag with no vendor patch referenced. ZDI-26-703 (CVE-2026-92203) and ZDI-26-704 (CVE-2026-92204), both CVSS 7.7, describe server-side request forgery flaws in the _get_shared_drive_object function of Airbyte's SharePoint and OneDrive connectors, each letting authenticated remote attackers trigger arbitrary server-side requests for information disclosure. ZDI-26-705 (CVE-2026-92205, CVSS 6.1) details a symlink directory traversal in BusyBox's libarchive enabling arbitrary file creation, requiring user interaction. ZDI-26-706 (CVE-2026-92206, CVSS 8.8) describes an unsafe reflection RCE in the CrewAI framework, exploited when a target loads a malicious agent configuration. ZDI-26-707 (CVE-2026-92207, CVSS 8.8) covers a code injection RCE in MindsDB's OpenBBtable feature, exploitable by authenticated remote users. ZDI-26-708 details an unpatched local privilege escalation in Microsoft Windows HTTP Proxy (CVSS 5.3) requiring prior low-privileged code execution; no CVE id is listed in that bulletin. Four advisories do not carry the 0day flag and their patch status is not stated: ZDI-26-709 describes unauthenticated deserialization of untrusted data in Cisco Secure Firewall Management Center's CommandSinkRmi component enabling RCE (CVE-2026-20242, CVSS 8.1); ZDI-26-710 describes an unauthenticated, network-adjacent heap-based buffer overflow in NoMachine's mDNS service enabling RCE (CVE-2026-92208, CVSS 8.8); ZDI-26-712 describes an unauthenticated SSRF in NoMachine's nxhtd server leading to information disclosure (CVE-2026-92210, CVSS 7.2); and ZDI-26-713 describes a stack-based buffer overflow in GIMP's APNG file parsing enabling RCE (CVE-2026-92183, CVSS 7.8), requiring user interaction such as visiting a malicious page or opening a malicious file. Source discrepancy: the MindsDB report's summary text cites ZDI-26-708, while its title and points identify the advisory as ZDI-26-707; ZDI-26-708 is separately assigned to the Windows HTTP Proxy advisory, so this summary follows the title/points attribution. CVSS scores range from 5.3 (Windows HTTP Proxy) to 8.8 (CrewAI, MindsDB, NoMachine mDNS). None of the reports state that exploitation has been observed in the wild.

  • Ten ZDI advisories published 2026-09-16: ZDI-26-703, -704, -705, -706, -707, -708, -709, -710, -712, -713
  • Six flagged 0day with no vendor patch referenced: ZDI-26-703, -704, -705, -706, -707, -708
  • ZDI-26-703: SSRF in _get_shared_drive_object of Airbyte SharePoint connector, CVE-2026-92203, CVSS 7.7, requires authentication, 0day
  • ZDI-26-704: SSRF in _get_shared_drive_object of Airbyte OneDrive connector, CVE-2026-92204, CVSS 7.7, requires authentication, 0day
  • ZDI-26-705: symlink directory traversal in BusyBox libarchive enabling arbitrary file creation, CVE-2026-92205, CVSS 6.1, requires user interaction, 0day
  • ZDI-26-706: unsafe reflection RCE in CrewAI framework, CVE-2026-92206, CVSS 8.8, requires loading a malicious agent configuration, 0day
  • ZDI-26-707: code injection RCE in MindsDB OpenBBtable feature, CVE-2026-92207, CVSS 8.8, requires authentication, 0day
  • ZDI-26-708: local privilege escalation in Microsoft Windows HTTP Proxy, CVSS 5.3, requires prior low-privileged code execution, no CVE listed in bulletin, 0day

Coverage timeline

  1. · 1d ago
    ZDI Published Advisories· 25
    ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability

    ZDI disclosed CVE-2026-92209, an improper authentication flaw in NoMachine's bundled Redis component allowing local privilege escalation (CVSS 7.8).

  2. · 1d ago
    ZDI Published Advisories· 45
    ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability

    ZDI disclosed an unpatched code injection RCE (CVE-2026-92207, CVSS 8.8) in MindsDB's OpenBBtable feature, exploitable by authenticated remote users.

  3. · 1d ago
    ZDI Published Advisories· 45
    ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-20242, an unauthenticated deserialization flaw in Cisco Secure Firewall Management Center enabling remote code execution (CVSS 8.1).

  4. · 1d ago
    ZDI Published Advisories· 25
    ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability

    ZDI disclosed CVE-2026-92210, an unauthenticated server-side request forgery in NoMachine's nxhtd server leading to information disclosure (CVSS 7.2).

  5. · 1d ago
    ZDI Published Advisories· 50
    ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability

    ZDI discloses unpatched unsafe reflection RCE vulnerability CVE-2026-92206 (CVSS 8.8) in the CrewAI agent framework.

  6. · 1d ago
    ZDI Published Advisories· 40
    ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-92208, an unauthenticated heap-based buffer overflow in NoMachine's mDNS service enabling network-adjacent remote code execution (CVSS 8.8).

  7. · 1d ago
    ZDI Published Advisories· 30
    ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-92183, a stack-based buffer overflow in GIMP's APNG file parsing that enables remote code execution (CVSS 7.8).

  8. · 1d ago
    ZDI Published Advisories· 50
    ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability

    ZDI disclosed an unpatched local privilege escalation flaw (CVSS 5.3) in Microsoft Windows HTTP Proxy, requiring prior low-privileged code execution.

  9. · 1d ago
    ZDI Published Advisories· 38
    ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

    ZDI disclosed an unpatched SSRF information disclosure flaw (CVE-2026-92204, CVSS 7.7) in Airbyte's OneDrive connector, requiring authentication.

  10. · 1d ago
    ZDI Published Advisories· 35
    ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability

    ZDI disclosed an unpatched symlink directory traversal flaw (CVE-2026-92205, CVSS 6.1) in BusyBox libarchive enabling arbitrary file creation.

  11. · 1d ago
    ZDI Published Advisories· 38
    ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

    ZDI disclosed an unpatched SSRF information disclosure flaw (CVE-2026-92203, CVSS 7.7) in Airbyte's SharePoint connector, exploitable by authenticated remote users.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20242
Unauthenticated Java Deserialization RCE in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC) Software contains a critical insecure deserialization flaw (CWE-502) in its External Database Access feature. An attacker who controls a host listed in the FMC's external database access list can send a crafted serialized Java byte stream to a specific TCP port on the device. Because the deserialization is insecure and the attack is unauthenticated at the protocol level, a successful exploit lets the attacker execute arbitrary commands on the appliance and elevate privileges to root. All deployments of Cisco FMC with the External Database Access feature enabled are potentially affected, though exposure is substantially reduced when the FMC management interface is not reachable from the public internet. Exploitation status: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

Do: Upgrade FMC to a fixed release per Cisco's security advisory as soon as one is published. As interim mitigation, review and restrict the external database access list to fully trusted hosts, limit which hosts can reach the affected TCP port, and ensure the FMC management interface is not exposed to the public internet. Verify configuration via the FMC admin console and monitor Cisco PSIRT for updates.

9.8
  • Cisco Secure Firewall Management Center (FMC) Software
large≈10,000–100,000 FMC deployments worldwide, with likely only a few thousand management interfaces internet-exposed
CVE-2026-92183

NVD description · AI analysis pending
CVE-2026-92203

NVD description · AI analysis pending
CVE-2026-92204

NVD description · AI analysis pending
CVE-2026-92205

NVD description · AI analysis pending
CVE-2026-92206

NVD description · AI analysis pending
CVE-2026-92207

NVD description · AI analysis pending
CVE-2026-92208

NVD description · AI analysis pending
CVE-2026-92209

NVD description · AI analysis pending
CVE-2026-92210

NVD description · AI analysis pending