<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>OT-Advisories</title>
    <link>https://ot-advisories.com/</link>
    <description>OT/ICS vulnerability intelligence for defenders</description>
    <atom:link href="https://ot-advisories.com/rss.xml" rel="self" type="application/rss+xml"/>
    <lastBuildDate>Mon, 28 Sep 2026 03:38:22 GMT</lastBuildDate>
    <item>
      <title>Fortinet FortiPAM Chrome Extension All 8.0 and 7.4 Versions Improperly Restricts Rendered UI Layers, Potentially Enabling Clickjacking Attacks Against Users of the PAM Interface</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-84388/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-84388/</guid>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.6 Critical  
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack</description>
    </item>
    <item>
      <title>Lantronix SLC8000, SLC9000, EMG, and SLB Series Set Script Schedule Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80152/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80152/</guid>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set script schedule command that passes unsanitized user input to a system() call. Attackers with the services permission can authenticate to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices. (NVD)</description>
    </item>
    <item>
      <title>Lantronix SLC8000, SLC9000, EMG, and SLB Series Set NFS Download Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80151/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80151/</guid>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set nfs download command that passes unsanitized user input to a system() call. Attackers with the services permission can authenticate to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices. (NVD)</description>
    </item>
    <item>
      <title>Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80146/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80146/</guid>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom read command that copies unbounded user input into a bounded stack buffer before passing it to a system() call. Attackers can authenticate as any user to the terminal or CLI interface and supply an oversized input to trigger the overflow, potentially achieving complete loss of confidentiality, integrity, and availability on the affected device and impacting downstream serial-attached devices. (NVD)</description>
    </item>
    <item>
      <title>MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 28</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-67279/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-67279/</guid>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 6.5 Medium  
Affected: MikroTik  
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. (CISA)  
What to do: ** Monitor MikroTik's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-93616/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-93616/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Check Point  
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.  
What to do: ** Monitor Check Point's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-85046/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-85046/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Google  
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.  
What to do: ** Monitor Google's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-81578/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-81578/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: PaperCut  
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the  completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.  
What to do: ** Monitor PaperCut's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-76461/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-76461/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Cisco  
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.  
What to do: There are no workarounds that address this vulnerability. Cisco strongly recommends that administrators cross-check the network logs and the firewall logs outside of the impacted device to identify any potential suspicious activity, including but not limited to unexpected uploads initiated from the affected device to external IP addresses or downloads from malicious IP addresses.</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-76460/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-76460/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Cisco  
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.  
What to do: There are no workarounds that address this vulnerability. However, there is a mitigation. To prevent remote exploitation of this vulnerability, use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. Cisco has published fixed releases: Cisco ISE or ISE-PIC 3.1 -&gt; 3.1 Patch 12, 3.2 -&gt; 3.2 Patch 11, 3.3 -&gt; 3.3 Patch 12, 3.4 -&gt; 3.4 Patch 7, 3.5 -&gt; 3.5 Patch 4.</description>
    </item>
    <item>
      <title>Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-75650/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-75650/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Adobe  
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.  
What to do: ** Monitor Adobe's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Linux Kernel SCTP ASCONF-ACK Parameter Walk Loops Indefinitely on an Unpadded Short Parameter Due to SCTP_PAD4 Rounding, Causing a Soft Lockup</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-98123/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-98123/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel BPF Verifier Fails to Reject Legacy Packet Loads from Callback Subprograms, Which Can Model a Failed BPF_LD_ABS as an Implicit Zero Return Causing Incorrect Program Behavior</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-98044/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-98044/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel au1000 Ethernet Driver Calls free_irq While Holding a Spinlock with Interrupts Disabled, Which Can Sleep and Deadlock on Platforms Without Threaded IRQs</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-93815/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-93815/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel mac80211 IBSS Leave Path Flushes Stations and Turns Off the Carrier Without Waiting for In-Flight TX to Complete, Leading to Use-After-Free on Concurrent Packet Transmission</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-93804/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-93804/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-67278/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-67278/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: MikroTik  
MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. The same permissive verification also undermines RSA-based SSH authentication.  
What to do: ** Monitor MikroTik's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 27</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-5430/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-5430/</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: WSO2  
WSO2 API Control Plane, API Manager, Traffic Manager &amp; Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.  
What to do: ** Monitor WSO2's web page for any future patch releases.</description>
    </item>
    <item>
      <title>MarkLogic SSRF Flaw Exposes Cloud Instance Credentials to Low-Privilege Users</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9203/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9203/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.5 High  
Affected: Progress  
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Crafted Links Let Attackers Hijack MarkLogic Administrator Sessions Through Query Console XSS</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9195/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9195/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.3 Critical  
Affected: Progress  
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Low-Privilege Hadoop Role Escalates to Full Control of MarkLogic's Security Database</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9193/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9193/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Progress  
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Unauthenticated Attackers Can Impersonate Any MarkLogic User Through ODBC Authentication Bypass</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9192/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9192/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Progress  
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>HTTP Request Smuggling Bypasses MarkLogic Authentication and Hijacks Sessions</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9190/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9190/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Progress  
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ConnectWise Automate agent trusts unverified plugin and update downloads, fixed in 2026.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9089/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9089/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: ConnectWise  
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.  
What to do: ** Monitor ConnectWise's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>MarkLogic's REST document-patch API lets low-privileged users seize administrator control</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-8709/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-8709/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Progress  
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Unauthenticated attackers impersonate any MarkLogic administrator through a SAML signature flaw</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-7557/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-7557/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Progress  
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>MarkLogic's SQL, SPARQL, and Optic query interfaces open a path from low-privileged access to full admin</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-7329/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-7329/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Progress  
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>MarkLogic's document-processing pipeline lets an administrative REST role escalate further, exposing server-side data</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-7327/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-7327/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: Progress  
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>A CSRF flaw in MarkLogic's Admin UI lets attackers hijack lured administrators for configuration changes</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-7326/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-7326/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Progress  
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71474/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71474/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.1 High  
Affected: Red Hat  
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services.  
What to do: ** Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache NiFi's gzip request handling bypasses size limits, opening a memory-exhaustion path, fixed in 2.11.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68981/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68981/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache NiFi's asset-deletion API skips ownership checks across Parameter Contexts, fixed in 2.11.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68980/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68980/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Apache  
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Missing authorization on Apache NiFi's Parameter Context updates can trigger code execution, fixed in 2.11.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68979/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68979/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Apache  
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting content, updating a Parameter can result in code execution during automatic component validation, without starting the referencing component. The impact was limited to stopped components by existing verification checks, and the issue applies only to deployments that use component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which aligns the Parameter Context update method authorization with other methods, adding authorization checking on affected components.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Pre-authentication attackers can exhaust memory in Apache Qpid Broker-J via oversized type handling, fixed in 10.1.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68060/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68060/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Qpid ProtonJ2 lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.2.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-67589/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-67589/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Unbounded symbol caching in Apache Qpid ProtonJ2 lets pre-authentication attackers exhaust memory, fixed in 1.2.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-67588/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-67588/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Qpid Proton-Dotnet lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.1.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-67551/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-67551/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Unbounded symbol caching in Apache Qpid Proton-Dotnet lets pre-authentication attackers exhaust memory, fixed in 1.1.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-67465/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-67465/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>A critical alternate-path flaw in Apache Tika precedes the 4.0.0-beta-1 fix, CVSS 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66756/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66756/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Apache  
Improper Protection of Alternate Path vulnerability in Apache Tika.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Tika's ISA-Tab parser lets crafted filenames leak arbitrary file contents into extracted text, fixed in 3.3.2</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66755/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66755/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a "Study Assay File Name" value in the ISA-Tab investigation file that traverses outside the dataset directory. Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1, which fixes this issue.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Qpid Proton-J lets pre-authentication attackers trigger oversized memory allocations, fixed in 0.35.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66273/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66273/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Unbounded symbol caching in Apache Qpid Proton-J lets pre-authentication attackers exhaust memory, fixed in 0.35.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66257/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66257/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>A JFrog Platform privilege-escalation flaw grants temporary admin access under admin-provisioned accounts</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66015/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66015/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.2 High  
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.  
What to do: How to Fix Cloud Environment : Affected Cloud environments have already been fortified. No action is required for cloud instances. Self-Hosted Environment : Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.34, 7.161.15.</description>
    </item>
    <item>
      <title>An authentication weakness in JFrog Artifactory's internal request processing lets attackers escalate access</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66014/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66014/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 8.8 High  
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.  
What to do: How to Fix Cloud Environment : Affected Cloud environments have already been fortified. No action is required for cloud instances. Self-Hosted Environment : Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.</description>
    </item>
    <item>
      <title>Limited-access JFrog Artifactory users can write to restricted internal metadata under specific conditions</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-65922/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-65922/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.1 High  
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.  
What to do: How to Fix Cloud Environment : Affected Cloud environments have already been fortified. No action is required for cloud instances. Self-Hosted Environment : Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.</description>
    </item>
    <item>
      <title>A deserialization flaw in JFrog Artifactory package handling lets low-privileged users compromise confidentiality, integrity, and availability</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-65617/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-65617/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 8.8 High  
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.  
What to do: How to Fix Cloud Environment : Affected Cloud environments have already been fortified. No action is required for cloud instances. Self-Hosted Environment : Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.</description>
    </item>
    <item>
      <title>Flawed refresh-token signature validation lets non-admin JFrog users obtain a signed administrator token</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-65616/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-65616/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 8.8 High  
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.  
What to do: How to Fix Cloud Environment : Affected Cloud environments have already been fortified. No action is required for cloud instances. Self-Hosted Environment : Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.27.</description>
    </item>
    <item>
      <title>An incomplete fix for a prior Kyuubi flaw still lets clients bypass the local-directory allowlist via Spark config aliases, fixed in 1.12.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-62391/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-62391/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: Apache  
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>A path traversal vulnerability in Apache Jena Fuseki is fixed in 6.2.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-61372/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-61372/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ConnectWise Automate's Solution Center allowed unencrypted client-server traffic open to interception, fixed in 2026.4</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-6066/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-6066/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.1 High  
Affected: ConnectWise  
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate deployments. The issue has been resolved in Automate 2026.4 by enforcing secure communication for affected Solution Center connections.  
What to do: ** Monitor ConnectWise's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>An information-exposure flaw in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-60413/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-60413/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Oracle  
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core).   The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Insecure deserialization in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-60412/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-60412/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Oracle  
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core).   The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Unauthenticated network attackers can reach all Oracle Hyperion Infrastructure Technology data over HTTP, CVSS 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-60393/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-60393/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Oracle  
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Insecure deserialization in Oracle's Outside In PDF Export SDK lets a logged-in attacker take full control, CVSS 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-60392/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-60392/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Oracle  
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK).   The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Unauthenticated network attackers can reach all Oracle Hyperion Financial Reporting data over HTTP, CVSS 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-60391/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-60391/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Oracle  
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Tampered RadFilter state in Telerik UI for ASP.NET AJAX enables server-side remote code execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-6023/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-6023/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: Progress  
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Telerik UI for ASP.NET AJAX chunked upload flaw lets attackers bypass size limits and exhaust disk space</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-6022/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-6022/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Progress  
In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Red Hat OpenShift AI's odh-dashboard leaks Kubernetes service account tokens through a NodeJS endpoint</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-5483/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-5483/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 8.5 High  
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.</description>
    </item>
    <item>
      <title>Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-54100/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-54100/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.3 High  
Affected: Red Hat  
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.  
What to do: ** Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-54099/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-54099/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Red Hat  
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.  
What to do: ** Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Path traversal in Apache Kyuubi's REST batch upload lets remote attackers write files outside the intended directory, fixed in 1.12.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-52680/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-52680/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Apache  
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Improper input validation in Progress MOVEit Automation opens a path to privilege escalation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-5174/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-5174/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.7 High  
Affected: Progress  
Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Improper input validation in NVIDIA Triton Inference Server on Linux can trigger denial of service</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47629/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47629/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Unbounded resource allocation in NVIDIA Triton Inference Server on Linux opens a denial-of-service path</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47628/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47628/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>A critical path-traversal flaw in NVIDIA Triton Inference Server on Linux enables denial of service, CVSS 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47627/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47627/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: nvidia  
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-4740/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-4740/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.2 High  
Affected: Red Hat  
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.  
What to do: ** Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>An event-handling flaw in JFrog Artifactory exposes privileged authorization material to lower-privileged users</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-42017/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-42017/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 8.8 High  
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.  
What to do: How to Fix Cloud Environment : Affected Cloud environments have already been fortified. No action is required for cloud instances. Self-Hosted Environment : Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.133.21, 7.146.8.</description>
    </item>
    <item>
      <title>Stored XSS in VMware Cloud Foundation Operations lets privileged users trigger admin actions via injected scripts</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-41724/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-41724/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: VMware  
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.  
What to do: ** Monitor VMware's web page for any future patch releases.</description>
    </item>
    <item>
      <title>A stored XSS spanning VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-41723/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-41723/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: VMware  
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.  
What to do: ** Monitor VMware's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Another stored XSS across VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-41722/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-41722/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: VMware  
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.  
What to do: ** Monitor VMware's web page for any future patch releases.</description>
    </item>
    <item>
      <title>A TOCTOU flaw in a VMware Fusion SETUID binary lets local non-admin users escalate to root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-41702/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-41702/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: VMware  
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.  
What to do: ** Monitor VMware's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Authenticated Command Injection in Progress LoadMaster UI Enables Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-4048/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-4048/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 8.4 High  
Affected: Progress  
OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.9</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-40141/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-40141/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: BeyondTrust  
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.  
What to do: ** Monitor BeyondTrust's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-40140/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-40140/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: BeyondTrust  
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability.  
What to do: ** Monitor BeyondTrust's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-40139/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-40139/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: BeyondTrust  
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.  
What to do: ** Monitor BeyondTrust's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-40138/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-40138/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: BeyondTrust  
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled  
What to do: ** Monitor BeyondTrust's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SQL Injection in Fortinet FortiDDoS-F 7.2 May Allow Unauthorized Data Access</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-39815/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-39815/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Fortinet  
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache ActiveMQ NIO SSL Transports Vulnerable to Denial-of-Service via Memory Exhaustion</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-39304/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-39304/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Low-Privilege OS Command Injection in Progress Flowmon Reporting Component</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-3692/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-3692/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Progress  
In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Race Condition in Apache Kafka Producer Can Silently Deliver Messages to Wrong Topics</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-35554/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-35554/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.7 High  
Affected: Apache  
A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Progress LoadMaster API Exposes Authenticated Command Injection for VS Administration Role</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-3519/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-3519/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 8.4 High  
Affected: Progress  
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Tomcat Cloud Clustering Component Logs Kubernetes Credentials in Plain Text</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34487/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34487/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Improper Output Encoding in Apache Tomcat JsonAccessLogValve Enables Log Injection</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34483/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34483/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Log4j RFC 5424 Layout Vulnerable to Log Injection in Versions 2.21 through 2.25</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34478/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34478/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Apache Log4j Core's  Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache OpenMeetings REST Login Exposes Credentials in URL Query String</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34020/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34020/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache OpenMeetings Uses Default Hard-Coded Encryption Key for Remember-Me Cookies</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-33266/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-33266/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-33105/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-33105/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 10.0 Critical  
Affected: Microsoft  
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Unsafe Deserialization in Red Hat Quay Resumable Upload Handling</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32590/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32590/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.1 High  
Affected: Red Hat  
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.  
What to do: ** Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Use-After-Free in Microsoft PowerPoint Enables Local Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32200/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32200/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Use-After-Free in Microsoft Office Excel Enables Local Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32199/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32199/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Office Excel Use-After-Free Lets Local Attacker Execute Code</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32198/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32198/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Local Code Execution via Use-After-Free in Microsoft Office Excel</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32197/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32197/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Use-After-Free in Microsoft Office Enables Local Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32190/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32190/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.4 High  
Affected: Microsoft  
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Office Excel Carries Additional Use-After-Free Code Execution Risk</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32189/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32189/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Out-of-Bounds Read in Microsoft Office Excel Discloses Information to Local Attackers</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32188/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32188/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.1 High  
Affected: Microsoft  
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical SSRF in Microsoft Bing Enables Network-Based Privilege Escalation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32186/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32186/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 10.0 Critical  
Affected: Microsoft  
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Deserialization Flaw in Microsoft HPC Pack Allows Authorized User to Escalate Privileges</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32184/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32184/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Use-After-Free in Windows Speech Component Allows Local Privilege Escalation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32153/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32153/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32091/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32091/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.4 High  
Affected: Microsoft  
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Tomcat CLIENT_CERT Authentication Bypass When Soft Fail Is Disabled</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-29145/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-29145/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Apache  
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Tomcat Fails to Preserve Configured Cipher Preference Order</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-29129/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-29129/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Configured cipher preference order not preserved vulnerability in Apache Tomcat.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache JSPWiki Renders Wiki Markup Without Authentication, Exposing Sensitive Data</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28814/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28814/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>JSON Hijacking in Apache JSPWiki Enables Cross-Site Request Forgery</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28813/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28813/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Apache  
Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache JSPWiki UserManager Spoofing Flaw Allows Attackers to Escalate Privileges</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28812/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28812/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Apache  
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache JSPWiki Leaks Internal Information via Debug Messages</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28811/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28811/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-27914/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-27914/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-27909/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-27909/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Cassandra 5.0 CREATE Permission Allows Privilege Escalation in mTLS Environments</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-27314/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-27314/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Apache  
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role,  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-26181/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-26181/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-26170/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-26170/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Control Sequence Injection in Microsoft Power Apps Enables Network-Based Spoofing</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-26149/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-26149/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.0 Critical  
Affected: Microsoft  
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Improper Input Validation in Microsoft PowerShell Allows Unauthorized Security Feature Bypass</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-26143/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-26143/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.8 High  
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.</description>
    </item>
    <item>
      <title>Apache Tomcat Chunk Extension Parsing Allows HTTP Request Smuggling</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24880/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24880/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA NeMoClaw Sandbox Initialization Exposes System Information to Remote Attackers</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24222/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24222/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.6 High  
Affected: nvidia  
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Path Traversal in NVIDIA BioNeMo Core Allows Malicious File to Escape Sandbox</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24217/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24217/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: nvidia  
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Deserialization of Untrusted Data in NVIDIA BioNeMo Enables Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24216/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24216/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: nvidia  
NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Integer Overflow in NVIDIA Triton Inference Server DALI Backend</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24214/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24214/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, or denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Out-of-Bounds Read in NVIDIA Triton Inference Server DALI Backend</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24213/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24213/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Integer Overflow in NVIDIA Triton Inference Server Allows Code Execution or Denial of Service</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24210/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24210/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Path Traversal Vulnerability in NVIDIA Triton Inference Server</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24209/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24209/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Authentication Bypass in NVIDIA Triton Inference Server</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24207/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24207/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA Triton Inference Server Authentication Bypass via Alternate Path Scores 7.3</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24206/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24206/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.3 High  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA TensorRT Out-of-Bounds Write Scores 8.2</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24188/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24188/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.2 High  
Affected: nvidia  
NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA NVFlare Deserialization of Untrusted Data Scores 8.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24186/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24186/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: nvidia  
NVIDIA FLARE SDK  contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA Cumulus Linux Buffer Overflow Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24184/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24184/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Cumulus Linux Excessive-Privilege Execution Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24183/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24183/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: nvidia  
NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Critical NVIDIA NVFlare Authorization Bypass via User-Controlled Key Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24178/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24178/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: nvidia  
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA Triton Inference Server Uncaught Exception Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24175/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24175/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request header to the server. A successful exploit of this vulnerability might lead to denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA Triton Inference Server Numeric Type Conversion Error Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24174/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24174/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the server. A successful exploit of this vulnerability might lead to denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA Triton Inference Server Integer Overflow Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24173/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24173/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the server. A successful exploit of this vulnerability might lead to denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA TensorRT-LLM Deserialization Flaw Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24163/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24163/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could  cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA Data Loading Library Deserialization Vulnerability Scores 7.3</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24156/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24156/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.3 High  
Affected: nvidia  
NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA Triton Inference Server Oversized Allocation Request Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24146/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24146/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a large number of outputs could cause a server crash. A successful exploit of this vulnerability might lead to denial of service.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Fortinet FortiSOAR Authentication Flaw Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23708/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23708/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Fortinet  
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration, which raises the attack complexity.  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Office LTSC Use-After-Free Vulnerability Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23657/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23657/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Microsoft  
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23429/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23429/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23428/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23428/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23427/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23427/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23425/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23425/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.1</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23424/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23424/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.1 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23422/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23422/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23415/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23415/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23414/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23414/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23413/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23413/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23412/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23412/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23411/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23411/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23410/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23410/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel AppArmor Double Free of Namespace Name Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23408/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23408/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23407/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23407/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Fortinet FortiManager and FortiAnalyzer Cloud Heap Overflow Scores 8.1</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-22828/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-22828/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: Fortinet  
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-22619/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-22619/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Eaton  
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download center.  
What to do: ** Monitor Eaton's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle Java SE JAXP Component Exposes Sensitive Information, Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-22016/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-22016/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Oracle  
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).  Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and  21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle Applications DBA ADPatch Access Control Weakness Scores 7.6</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-22011/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-22011/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.6 High  
Affected: Oracle  
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications DBA, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H).  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle Financial Services Infrastructure Platform Access Control Flaw Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-22010/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-22010/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Oracle  
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle Life Sciences Empirica Signal Access Control Weakness Scores 8.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-21997/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-21997/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.5 High  
Affected: Oracle  
Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core).  Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Empirica Signal.  While the vulnerability is in Oracle Life Sciences Empirica Signal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Life Sciences Empirica Signal accessible data as well as  unauthorized read access to a subset of Oracle Life Sciences Empirica Signal accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-21662/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-21662/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Johnson Controls  
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.  
What to do: ** Monitor Johnson Controls's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20160/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20160/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Cisco  
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20155/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20155/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: Cisco  
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20151/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20151/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.3 High  
Affected: Cisco  
A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco UCS Command Injection Scores 8.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20094/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20094/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Cisco  
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Red Hat Cost Management Metrics Operator SSRF via Crafted Custom Resource Scores 7.6</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-18381/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-18381/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.6 High  
Affected: Red Hat  
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.  
What to do: ** Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Red Hat Cost Management Metrics Operator SSRF via Arbitrary Upload URL Scores 7.6</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-18378/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-18378/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.6 High  
Affected: Red Hat  
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.  
What to do: ** Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Google Chrome on Linux Use-After-Free in Views via Crafted HTML Scores 8.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-17894/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-17894/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 8.8 High  
Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)</description>
    </item>
    <item>
      <title>Google Chrome on Linux Chromoting Flaw Enables Local Privilege Escalation, Scores 8.4</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-17877/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-17877/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 8.4 High  
Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)</description>
    </item>
    <item>
      <title>Google Chrome on Linux File Input Flaw Exposes Potential Sandbox Escape, Scores 7.1</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-17744/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-17744/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.1 High  
Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)</description>
    </item>
    <item>
      <title>Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.4</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-16443/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-16443/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.4 High  
Affected: Red Hat  
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.  
What to do: ** Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0288/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0288/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.5 High  
Affected: Palo Alto Networks  
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS OS Command Injection Scores 7.2</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0273/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0273/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.2 High  
Affected: Palo Alto Networks  
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS Missing Authorization Scores 7.2</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0272/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0272/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.2 High  
Affected: Palo Alto Networks  
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks Prisma Access Agent Permission Misconfiguration Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0271/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0271/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.8 High  
Affected: Palo Alto Networks  
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks Cortex XSOAR Path Traversal Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0270/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0270/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Palo Alto Networks  
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux  allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.1</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0265/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0265/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: Palo Alto Networks, Siemens  
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled.  
What to do: ** Monitor Siemens's and Palo Alto Networks's web pages for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0264/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0264/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Palo Alto Networks, Siemens  
A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending specially crafted network traffic (PA-Series hardware only).  
What to do: ** Monitor Siemens's and Palo Alto Networks's web pages for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0263/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0263/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
Affected: Palo Alto Networks  
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE1808</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0262/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0262/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Palo Alto Networks, Siemens  
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic.  
What to do: ** Monitor Siemens's and Palo Alto Networks's web pages for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.2</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0261/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0261/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.2 High  
Affected: Palo Alto Networks, Siemens  
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI.  
What to do: ** Monitor Siemens's and Palo Alto Networks's web pages for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS External File Path Control Scores 8.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0259/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0259/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 8.8 High  
Affected: Palo Alto Networks  
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.1</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0258/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0258/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Palo Alto Networks, Siemens  
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition.  
What to do: ** Monitor Siemens's and Palo Alto Networks's web pages for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks GlobalProtect Untrusted Search Path Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0251/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0251/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.8 High  
Affected: Palo Alto Networks  
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks GlobalProtect Out-of-Bounds Write Scores 8.1</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0250/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0250/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 8.1 High  
Affected: Palo Alto Networks  
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks Prisma Access Agent Missing Authorization Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0246/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0246/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 7.8 High  
Affected: Palo Alto Networks  
A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks Prisma SD-WAN Certificate Validation Flaw Scores 8.1</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0244/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0244/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: Palo Alto Networks  
An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks Prisma Browser Alternate Path Protection Flaw Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0237/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0237/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Palo Alto Networks  
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks Prisma Browser Code Injection Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0236/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0236/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Palo Alto Networks  
A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Palo Alto Networks ADEM Certificate Validation Flaw Scores 8.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0233/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0233/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Palo Alto Networks  
A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM  privileges.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Nokia MantaRay NM sudo Privilege Escalation Reaches Root, Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-7406/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-7406/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Nokia  
Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts.  
What to do: ** Monitor Nokia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Traffic Server HTTP Request Smuggling Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-65114/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-65114/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
Apache Traffic Server allows request smuggling if chunked messages are malformed.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache DolphinScheduler Sensitive Information Exposure Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-62188/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-62188/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.  
What to do: ** Monitor Apache's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Fortinet FortiManager SQL Injection Scores 7.2</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-61848/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-61848/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.2 High  
Affected: Fortinet  
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2 through 7.6.3, FortiAnalyzer-BigData 7.6.0 through 7.6.1, FortiAnalyzer-BigData 7.4.0 through 7.4.5, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.2 through 7.6.4 may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Traffic Server Incorrect Control Flow Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-58136/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-58136/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Apache  
A bug in POST request handling causes a crash under a certain condition.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Fortinet FortiMail SQL Injection Scores 7.2</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-53681/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-53681/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.2 High  
Affected: Fortinet  
An improper neutralization of special elements used in an SQL Command ("SQL Injection&amp;") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA TensorRT-LLM MPI Server Deserialization Flaw Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-33255/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-33255/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Nokia MantaRay NM OS Command Injection in Log Search Scores 8.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-24818/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-24818/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: Nokia  
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.  
What to do: ** Monitor Nokia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Nokia MantaRay NM OS Command Injection in Symptom Collector Scores 8.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-24817/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-24817/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: Nokia  
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.  
What to do: ** Monitor Nokia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Nokia MantaRay NM Unrestricted File Upload Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-24815/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-24815/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Nokia  
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system.  
What to do: ** Monitor Nokia's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ABB T-MAC Plus Incorrect Authorization Scores 7.4</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-14774/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-14774/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.4 High  
Affected: ABB  
Incorrect Authorization vulnerability in ABB T-MAC Plus.  
What to do: ** Monitor ABB's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ABB T-MAC Plus Cross-Site Scripting Scores 8.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-14773/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-14773/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: ABB  
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus.  
What to do: ** Monitor ABB's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ABB T-MAC Plus Authorization Bypass via User-Controlled Key Scores 8.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-14772/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-14772/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: ABB  
Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus.  
What to do: ** Monitor ABB's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ABB T-MAC Plus Exposes Files to External Parties, Scores 9.9</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-14771/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-14771/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: ABB  
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.  
What to do: ** Monitor ABB's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Forcepoint VPN Client Excessive-Privilege Execution Scores 7.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-12694/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-12694/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Forcepoint  
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior.  
What to do: ** Monitor Forcepoint's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ProSoft ICX35-HWC OS Command Injection via Web UI Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2017-20236/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2017-20236/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: prosoft-technology  
ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input through unvalidated fields. Attackers can exploit this vulnerability to gain root privileges and execute arbitrary commands on the device through the accessible web interface.  
What to do: ** Monitor prosoft-technology's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ProSoft ICX35-HWC Authentication Bypass in Web Interface Scores 9.1</title>
      <link>https://ot-advisories.com/advisories/CVE-2017-20235/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2017-20235/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: prosoft-technology  
ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism in affected firmware versions to obtain full administrative access to device configuration and settings.  
What to do: ** Monitor prosoft-technology's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Strips Backslash Characters but Not Forward Slashes During Path Validation, Letting Authenticated Attackers Write Files to Arbitrary Filesystem Locations</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80156/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80156/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management portal upload endpoint that allows authenticated attackers to write arbitrary data to any location on the device's filesystem, leading to remote code execution. The upload filename validation strips backslash characters but does not subsequently check for forward slashes when a backslash is detected; by supplying a filename containing both characters an attacker writes outside the intended upload directory to any writable path. Attackers can use this vulnerability to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-connected devices. (NVD)</description>
    </item>
    <item>
      <title>Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Requires No Authentication, Allowing Unauthenticated Attackers to Read Configuration Files and Upload to Arbitrary Filesystem Locations, Scoring CVSS 10.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80155/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80155/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 10.0 Critical  
Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal upload endpoint that allows unauthenticated attackers to read sensitive configuration files and upload files to arbitrary filesystem locations, leading to remote code execution. The web configuration server constructs the session cookie file path using snprintf with a fixed-size buffer; by supplying a cookie value of a specific length an attacker causes the path to truncate at the required delimiter and leverages path traversal to redirect authentication validation to an arbitrary on-disk file such as the local user database, bypassing all session checks. Attackers can use this vulnerability to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-connected devices. (NVD)</description>
    </item>
    <item>
      <title>Lantronix SLC8000, SLC9000, EMG, and SLB Series Web Portal Derives Session Tokens Deterministically from Device Model and Current Second, Letting Unauthenticated Attackers Predict and Forge Valid Sessions on All Firmware Versions</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80154/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80154/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.6 Critical  
All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices. (NVD)</description>
    </item>
    <item>
      <title>Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80147/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80147/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom write command that copies unbounded user input into a bounded stack buffer before passing it to a system() call. Attackers can authenticate as any user to the terminal or CLI interface and supply an oversized input to trigger the overflow, potentially achieving complete loss of confidentiality, integrity, and availability on the affected device and impacting downstream serial-attached devices. (NVD)</description>
    </item>
    <item>
      <title>Lantronix SLC8000/SLC9000 and EMG Series Set CIFS Password Command Passes User Input Unsanitized to system(), Enabling Authenticated Users with Services Permission to Run Commands as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80145/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80145/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set cifs password command that passes unsanitized user input to a system() call. Attackers with the services permission can authenticate to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices. (NVD)</description>
    </item>
    <item>
      <title>Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80144/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80144/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom write command that passes unsanitized user input to a system() call. Attackers can authenticate as any user to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices. (NVD)</description>
    </item>
    <item>
      <title>Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80143/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80143/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom read command that passes unsanitized user input to a system() call. Attackers can authenticate as any user to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices. (NVD)</description>
    </item>
    <item>
      <title>SolarWinds Observability Self-Hosted Insufficient Integrity Checks Allow Unauthenticated Remote Code Execution on Non-Default, Non-Hardened Installations</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28324/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28324/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected. (NVD)</description>
    </item>
    <item>
      <title>Honeywell PD45 Industrial Printer F10.19.010040 Web Management Interface Allows Unauthenticated File Upload of Attacker-Controlled Files, Enabling Remote Code Execution Without Credentials</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-13249/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-13249/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication.</description>
    </item>
    <item>
      <title>Cisco IOS's Multiple Cross-Site Request Forgery Flaws Allow Remote Attackers to Execute Arbitrary Commands via Show Privilege and Alias Exec Requests; CISA's July 16th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2008-4128/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2008-4128/</guid>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.1 High  
Affected: Cisco  
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Progress LoadMaster OS Command Injection via Geo Administration API Scores 8.4</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-3517/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-3517/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 8.4 High  
Affected: Progress  
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Apache Tomcat EncryptInterceptor Padding Oracle Scores 7.5</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-29146/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-29146/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 7.5 High  
Affected: Apache  
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.  
What to do: ** Monitor Apache's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.9</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20180/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20180/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 9.9 Critical  
Affected: Cisco  
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Fortinet FortiSandbox Path Traversal Enables Privilege Escalation, Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-39813/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-39813/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 9.8 Critical  
Affected: Fortinet  
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Fortinet FortiWeb Out-of-Bounds Write Scores 7.2</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-40688/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-40688/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 7.2 High  
Affected: Fortinet  
An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Progress MOVEit Automation Authentication Bypass Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-4670/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-4670/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 9.8 Critical  
Affected: Progress  
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical VMware vCenter Authentication Bypass in Directory Service Scores 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-59309/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-59309/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 9.8 Critical  
Affected: VMware  
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.  
What to do: ** Monitor VMware's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Progress LoadMaster OS Command Injection via Full-Permission API Scores 8.4</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-3518/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-3518/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 8.4 High  
Affected: Progress  
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command  
What to do: ** Monitor Progress's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Critical Cisco ISE and ISE-PIC Command Injection Scores 9.9</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20147/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20147/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[EPSS-Imminent]  
CVSS 9.9 Critical  
Affected: Cisco  
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-94127/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-94127/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: F5  
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.  
What to do: ** Monitor F5's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-93952/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-93952/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Arista  
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.  
What to do: ** Monitor Arista's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-85102/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-85102/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Check Point  
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.  
What to do: ** Monitor Check Point's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Advantech EKI-1242EIMS Firmware V1.06.01 edgserver Management Service Passes Unsanitized Input to the OS Shell, Enabling Unauthenticated Remote Attackers to Execute Arbitrary Commands</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-73172/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-73172/</guid>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.3 Critical  
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.</description>
    </item>
    <item>
      <title>Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9586/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9586/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Sangoma  
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with &lt;PolycomIPPhone&gt; and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.  
What to do: ** Monitor Sangoma's web page for any future patch releases.</description>
    </item>
    <item>
      <title>IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9198/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9198/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: IBM, langflow  
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments  
What to do: ** Monitor IBM's and langflow's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9082/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9082/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Drupal  
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.  
What to do: ** Monitor Drupal's web page for any future patch releases.</description>
    </item>
    <item>
      <title>N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-86218/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-86218/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: N-able  
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.  
What to do: ** Monitor N-able's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-85706/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-85706/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: GitLab  
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.  
What to do: ** Monitor GitLab's web page for any future patch releases.</description>
    </item>
    <item>
      <title>SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-83549/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-83549/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: SonicWall  
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.  
What to do: ** Monitor SonicWall's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-83548/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-83548/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: SonicWall  
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.  
What to do: ** Monitor SonicWall's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-82329/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-82329/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: JFrog  
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.  
What to do: ** Monitor JFrog's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-8037/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-8037/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.6 Critical  
Affected: Progress  
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints  
What to do: ** Monitor Progress's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-73570/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-73570/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.9 High  
Affected: Synacor  
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.  
What to do: ** Monitor Synacor's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72898/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72898/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Metabase  
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.  
What to do: ** Monitor Metabase's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-6973/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-6973/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.2 High  
Affected: Ivanti  
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.  
What to do: ** Monitor Ivanti's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68820/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68820/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.0 High  
Affected: Microsoft  
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-65400/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-65400/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Apple  
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.  
What to do: ** Monitor Apple's web page for any future patch releases.</description>
    </item>
    <item>
      <title>MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-64849/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-64849/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.3 Critical  
Affected: MLflow, lfprojects  
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.  
What to do: ** Monitor MLflow's and lfprojects's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-63077/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-63077/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: JetBrains  
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.  
What to do: ** Monitor JetBrains's web page for any future patch releases.</description>
    </item>
    <item>
      <title>WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-63030/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-63030/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: WordPress  
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.  
What to do: ** Monitor WordPress's web page for any future patch releases.</description>
    </item>
    <item>
      <title>WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-60137/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-60137/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 5.9 Medium  
Affected: WordPress  
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.  
What to do: ** Monitor WordPress's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-60004/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-60004/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Gitea  
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.  
What to do: ** Monitor Gitea's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-59310/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-59310/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Broadcom, VMware  
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.  
What to do: ** Monitor Broadcom's and VMware's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-56291/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-56291/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Balbooa  
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.  
What to do: ** Monitor Balbooa's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-56290/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-56290/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Joomlack  
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.  
What to do: ** Monitor Joomlack's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-55040/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-55040/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.1 Critical  
Affected: Microsoft  
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-50751/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-50751/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.3 Critical  
Affected: Check Point  
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.  
What to do: ** Monitor Check Point's web page for any future patch releases.</description>
    </item>
    <item>
      <title>iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-48939/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-48939/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: iCagenda  
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.  
What to do: ** Monitor iCagenda's web page for any future patch releases.</description>
    </item>
    <item>
      <title>JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-48908/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-48908/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: JoomShaper  
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.  
What to do: ** Monitor JoomShaper's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-48907/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-48907/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Widget Factory  
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.  
What to do: ** Monitor Widget Factory's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-48710/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-48710/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 6.5 Medium  
Affected: Kludex, Red Hat, encode  
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.  
What to do: ** Monitor Kludex, encode, and Red Hat's web pages for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-48558/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-48558/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: SimpleHelp   
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.  
What to do: ** Monitor SimpleHelp 's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-48172/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-48172/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: LiteSpeed  
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.  
What to do: ** Monitor LiteSpeed's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46817/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46817/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Oracle  
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.  
What to do: ** Monitor Oracle's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-45498/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-45498/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 4.0 Medium  
Affected: Microsoft  
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-45247/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-45247/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Mirasvit  
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.  
What to do: ** Monitor Mirasvit's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-42897/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-42897/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.1 High  
Affected: Microsoft  
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-42018/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-42018/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.5 High  
Affected: JFrog  
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.  
What to do: ** Monitor JFrog's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-42016/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-42016/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.1 High  
Affected: JFrog  
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.  
What to do: ** Monitor JFrog's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-41940/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-41940/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: WebPros  
WebPros cPanel &amp; WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.  
What to do: ** Monitor WebPros's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-41091/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-41091/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Microsoft  
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-39987/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-39987/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Marimo  
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.  
What to do: ** Monitor Marimo's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-39808/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-39808/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Fortinet  
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.  
What to do: ** Monitor Fortinet's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-35616/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-35616/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Fortinet  
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.  
What to do: ** Monitor Fortinet's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-35273/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-35273/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Oracle  
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.  
What to do: ** Monitor Oracle's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34926/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34926/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 6.7 Medium  
Affected: Trend Micro  
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.  
What to do: ** Monitor Trend Micro's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34910/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34910/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Ubiquiti  
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.  
What to do: ** Monitor Ubiquiti's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34909/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34909/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Ubiquiti  
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.  
What to do: ** Monitor Ubiquiti's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34908/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34908/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Ubiquiti  
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.  
What to do: ** Monitor Ubiquiti's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34486/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34486/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.5 High  
Affected: Apache, Red Hat  
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.  
What to do: ** Monitor Apache's and Red Hat's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-34197/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-34197/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Apache  
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.  
What to do: ** Monitor Apache's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-33825/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-33825/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Microsoft  
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-33824/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-33824/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Microsoft  
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-32202/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-32202/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 4.3 Medium  
Affected: Microsoft  
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-31431/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-31431/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Linux  
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28318/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28318/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.5 High  
Affected: SolarWinds  
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.  
What to do: ** Monitor SolarWinds's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-25089/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-25089/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Fortinet  
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.  
What to do: ** Monitor Fortinet's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-21962/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-21962/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Oracle  
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in.  While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).  
What to do: ** Monitor Oracle's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-21643/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-21643/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Fortinet  
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.  
What to do: ** Monitor Fortinet's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20316/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20316/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 5.3 Medium  
Affected: Cisco  
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20262/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20262/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 6.5 Medium  
Affected: Cisco  
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20253/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20253/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Splunk  
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.  
What to do: ** Monitor Splunk's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20245/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20245/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Cisco  
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20230/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20230/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.6 High  
Affected: Cisco  
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco Unified Computing System's Argument Delimiter Injection Allows an Authenticated Attacker to Execute Arbitrary Commands on the Management Controller</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20200/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20200/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 8.8 High  
Affected: Cisco  
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&amp;nbsp;  
What to do: Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20182/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20182/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Cisco  
Cisco Catalyst SD-WAN Controller &amp; Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20133/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20133/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 6.5 Medium  
Affected: Cisco  
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20128/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20128/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.5 High  
Affected: Cisco  
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20122/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20122/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 5.4 Medium  
Affected: Cisco  
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20079/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20079/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Cisco  
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  
What to do: Workarounds: No workarounds available. Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory.</description>
    </item>
    <item>
      <title>Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-19490/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-19490/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Citrix  
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.  
What to do: ** Monitor Citrix's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-16232/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-16232/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Check Point  
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.  
What to do: ** Monitor Check Point's web page for any future patch releases.</description>
    </item>
    <item>
      <title>SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-15410/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-15410/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.2 High  
Affected: SonicWall  
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.  
What to do: ** Monitor SonicWall's web page for any future patch releases.</description>
    </item>
    <item>
      <title>SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-15409/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-15409/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: SonicWall  
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.  
What to do: ** Monitor SonicWall's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-1340/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-1340/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Ivanti  
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.  
What to do: ** Monitor Ivanti's web page for any future patch releases.</description>
    </item>
    <item>
      <title>PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-12569/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-12569/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: PTC  
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.  
What to do: ** Monitor PTC's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-10520/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-10520/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Ivanti  
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.  
What to do: ** Monitor Ivanti's web page for any future patch releases.</description>
    </item>
    <item>
      <title>PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0300/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0300/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Palo Alto Networks, Siemens  
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.  
What to do: ** Monitor Siemens's and Palo Alto Networks's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0257/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0257/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.1 Critical  
Affected: Palo Alto Networks, Siemens  
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.  
What to do: ** Monitor Siemens's and Palo Alto Networks's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Fortinet FortiOS's Information Exposure Flaw Allows a Remote Unauthenticated Attacker to Bypass the Previously Issued Patch for Symbolic Link Persistency; CISA's August 10th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-68686/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-68686/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 5.9 Medium  
Affected: Fortinet  
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.  
What to do: ** Monitor Fortinet's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Lantronix EDS5000's Code Injection via the Username Parameter Executes Injected OS Commands with Root Privileges; CISA's June 26th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-67038/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-67038/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Lantronix  
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.  
What to do: ** Monitor Lantronix's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Ray-Project Ray's Code Injection Flaw Allows Remote Attackers to Execute Arbitrary Code on the Distributed ML Framework's Cluster Nodes; CISA's August 20th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-62593/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-62593/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Ray-Project, anyscale  
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.  
What to do: ** Monitor Ray-Project's and anyscale's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Windows Link Following Flaw Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-60710/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-60710/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Microsoft  
Microsoft Windows contains a link following vulnerability that allows for privilege escalation  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>D-Link DIR-823X's set_prohibiting POST Endpoint Accepts Injected Commands and Executes Them on Remote Devices; CISA's May 8th KEV Deadline Has Passed for This Potentially End-of-Life Router</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-29635/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-29635/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.2 High  
Affected: D-Link  
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.  
What to do: ** Monitor D-Link's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Kentico Xperience's Path Traversal in the Staging Sync Server Allows Authenticated Users to Upload Arbitrary Data Outside Expected Directories; CISA's May 4th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-2749/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-2749/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.2 High  
Affected: Kentico  
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.  
What to do: ** Monitor Kentico's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Samsung MagicINFO 9 Path Traversal Enabling Arbitrary File Writes as System Authority Has Missed CISA's May 8th KEV Deadline; Covered Entities Remain Out of Compliance</title>
      <link>https://ot-advisories.com/advisories/CVE-2024-7399/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2024-7399/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Samsung  
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.  
What to do: ** Monitor Samsung's web page for any future patch releases.</description>
    </item>
    <item>
      <title>SimpleHelp's Zip Slip Path Traversal Lets Admin Users Write Arbitrary Files to Any Location on the Server and Execute Code as the Service Account; CISA's May 8th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2024-57728/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2024-57728/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.2 High  
Affected: SimpleHelp   
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.  
What to do: ** Monitor SimpleHelp 's web page for any future patch releases.</description>
    </item>
    <item>
      <title>SimpleHelp Lets Low-Privilege Technicians Mint Overpowered API Keys Through a Missing Authorization Check; CISA's May 8th KEV Deadline for Covered Entities Has Lapsed</title>
      <link>https://ot-advisories.com/advisories/CVE-2024-57726/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2024-57726/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.9 Critical  
Affected: SimpleHelp   
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.  
What to do: ** Monitor SimpleHelp 's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Unauthenticated T3 and IIOP Network Access to Oracle WebLogic Enables System Compromise; CISA's June 4th KEV Mandate for Covered Entities Has Been Lapsed for Months</title>
      <link>https://ot-advisories.com/advisories/CVE-2024-21182/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2024-21182/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.5 High  
Affected: Oracle  
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.  
What to do: ** Monitor Oracle's web page for any future patch releases.</description>
    </item>
    <item>
      <title>ConnectWise ScreenConnect's Path Traversal Enables Remote Code Execution or Direct Access to Confidential Data and Critical Systems; CISA's May 12th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2024-1708/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2024-1708/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.4 High  
Affected: ConnectWise  
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.  
What to do: ** Monitor ConnectWise's web page for any future patch releases.</description>
    </item>
    <item>
      <title>ownCloud's Improper Authentication Allows Unauthenticated Remote Attackers to Gain Access to Protected Files Without Valid Credentials; CISA's August 30th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2023-49105/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2023-49105/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: ownCloud  
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.  
What to do: ** Monitor ownCloud's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Windows Common Log File System Driver's Out-of-Bounds Read Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2023-36424/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2023-36424/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Microsoft  
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Exchange Server's Deserialization of Untrusted Data Enables Authenticated Attackers to Achieve Remote Code Execution; CISA's April 27th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2023-21529/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2023-21529/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Microsoft  
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel's Out-of-Bounds Write Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 9th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2022-0995/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2022-0995/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Linux, fedoraproject, netapp  
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.  
What to do: ** Monitor Linux, fedoraproject, and netapp's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel's cgroup v1 release_agent Feature Enables Privilege Escalation; CISA's June 5th KEV Deadline for Covered Entities Has Lapsed</title>
      <link>https://ot-advisories.com/advisories/CVE-2022-0492/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2022-0492/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Linux  
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Unauthenticated Attackers Can Overflow DD-WRT's UPnP Stack Buffer; CISA's July 24th KEV Mandate for Covered Entities Has Lapsed</title>
      <link>https://ot-advisories.com/advisories/CVE-2021-27137/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2021-27137/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.1 High  
Affected: DD-WRT  
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.  
What to do: ** Monitor DD-WRT's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Ajax.NET Professional's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via a Crafted Serialized Object; CISA's September 9th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2021-23758/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2021-23758/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.1 High  
Affected: Ajax.NET Professional, ajaxpro.2_project, michaelschwarz  
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.  
What to do: ** Monitor Ajax.NET Professional, ajaxpro.2_project, and michaelschwarz's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft SQL Server's Unspecified Flaw Allows Authenticated Attackers to Execute Arbitrary Code on the Database Server; CISA's August 29th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2019-1068/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2019-1068/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Microsoft  
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Red Hat Automatic Bug Reporting Tool's Privilege Escalation Flaw Allows Local Attackers to Gain Root Access on Affected Enterprise Linux Systems; CISA's September 9th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2015-5287/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2015-5287/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Oracle, Red Hat, Red Hat - duplicate  
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.  
What to do: ** Monitor Red Hat - duplicate, Red Hat, and Oracle's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Red Hat Enterprise Linux's Libuser Race Condition in Password File Writes Allows Local Attackers to Corrupt System Files; CISA's September 9th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2015-3246/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2015-3246/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 5.1 Medium  
Affected: Red Hat, Red Hat - duplicate, libuser_project, opensuse  
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.  
What to do: ** Monitor Red Hat - duplicate, Red Hat, opensuse, and libuser_project's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Visual Basic for Applications Loads Libraries Insecurely, Enabling Remote Code Execution; CISA's April 27th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2012-1854/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2012-1854/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Microsoft  
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Internet Explorer's Use-After-Free Enables Remote Code Execution via Invalid Pointer Access After Object Deletion; CISA's June 3rd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2010-0806/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2010-0806/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Microsoft  
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Internet Explorer's Use-After-Free Gives Remote Attackers Code Execution via a Pointer to a Deleted Object; CISA's June 3rd KEV Deadline Has Passed for This End-of-Life Browser</title>
      <link>https://ot-advisories.com/advisories/CVE-2010-0249/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2010-0249/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Microsoft  
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft DirectX's QuickTime Movie Parser Filter Lets Remote Attackers Execute Arbitrary Code via a Crafted Media File; CISA's June 3rd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2009-1537/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2009-1537/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Microsoft  
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Office Code Injection From 2009 Added to CISA's Known Exploited Vulnerabilities Catalog with an April 28th Federal Deadline That Has Since Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2009-0238/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2009-0238/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Microsoft  
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Windows Server Service's Path Canonicalization Buffer Overflow Enables Remote Code Execution via Crafted RPC Requests; CISA's June 3rd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2008-4250/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2008-4250/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Microsoft  
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-7273/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-7273/</guid>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Zyxel  
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.  
What to do: ** Monitor Zyxel's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-87886/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-87886/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Acronis  
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel &amp; WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.  
What to do: ** Monitor Acronis's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-86060/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-86060/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: MikroTik  
RouterOS contains an argument-handling flaw in the SSH login  
What to do: ** Monitor MikroTik's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-85880/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-85880/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Microsoft  
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-84869/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-84869/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.9 Critical  
Affected: ConnectWise  
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.  
What to do: ** Monitor ConnectWise's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Windows' Improper Link Resolution Before File Access Allows a Local Attacker to Follow Symbolic Links to Privileged Files and Gain Elevated Access; CISA's September 22nd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-81963/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-81963/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Microsoft  
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Fortinet FortiManager's Authentication Bypass via an Alternate Path Grants Unauthenticated Attackers Access to Management Functions</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-70468/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-70468/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: Fortinet  
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via &lt;insert attack vector here&gt;  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Fortinet FortiClient's Classic Buffer Overflow Allows an Attacker to Corrupt Memory and Potentially Execute Arbitrary Code</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-70465/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-70465/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: Fortinet  
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-67277/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-67277/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.2 High  
Affected: MikroTik  
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.  
What to do: ** Monitor MikroTik's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-53362/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-53362/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-53266/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-53266/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Azure Kubernetes Service's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Interact with Privileged Cluster Management Endpoints</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-50516/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-50516/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.4 Critical  
Affected: Microsoft  
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Fortinet FortiWeb's Improper Authentication Allows Unauthenticated Attackers to Bypass Login Controls and Access the Web Application Firewall Management Interface</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-26035/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-26035/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Fortinet  
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password  
What to do: ** Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20349/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20349/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.6 High  
Affected: Cisco  
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  
What to do: ** Monitor Cisco's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Cisco IOS XE's Unchecked Loop Condition Input Allows Network-Accessible Devices to Be Crashed via a Specially Crafted Packet</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20301/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20301/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 8.6 High  
Affected: Cisco  
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  
What to do: Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. There is a mitigation that addresses this vulnerability.</description>
    </item>
    <item>
      <title>Cisco IOS XE's Improper Input Validation Allows a Remote Attacker to Trigger a Device Crash or Disruption via a Specially Crafted Input</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20273/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20273/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.6 High  
Affected: Cisco  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20272/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20272/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Cisco  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20271/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20271/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.6 High  
Affected: Cisco  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco IOS XE's Incorrect Calculation Vulnerability Allows a Remote Attacker to Cause an Unrecoverable Device Condition via a Specially Crafted Input</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20270/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20270/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.6 High  
Affected: Cisco  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20269/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20269/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.6 High  
Affected: Cisco  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco IOS XE's Improper Restriction of Memory Buffer Operations Allows Remote Attackers to Potentially Execute Code or Crash the Device via a Malformed Packet</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20268/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20268/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.6 High  
Affected: Cisco  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco IOS XE's Improper Access Control Allows Network-Based Attackers to Access Protected Functions or Data Without Proper Authorization</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20267/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20267/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.0 Critical  
Affected: Cisco  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  
What to do: ** Monitor Cisco's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco IOS XE's Memory Resource Leak Allows Remote Attackers to Exhaust Device Memory and Cause a Denial of Service via Repeated Packet Transmission</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20124/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20124/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 7.7 High  
Affected: Cisco  
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.  
What to do: Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. There is a mitigation that addresses this vulnerability.</description>
    </item>
    <item>
      <title>Palo Alto Networks Cloud NGFW and Prisma Access Use of Uninitialized Resource Allows a Network-Based Attacker to Access Sensitive Information</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0301/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0301/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 7.5 High  
Affected: Palo Alto Networks  
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.  
What to do: PAN-OS 12.1/11.2: no action needed. PAN-OS 11.1: upgrade to 11.1.16-h1 or later. PAN-OS 10.2: upgrade to 10.2.8 or 11.1.16-h1 or later. Older unsupported PAN-OS versions: upgrade to a supported fixed version. Cloud NGFW customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade.</description>
    </item>
    <item>
      <title>Palo Alto Networks GlobalProtect's Untrusted Search Path Allows a Local Attacker to Load a Malicious Library and Execute Code in the Application's Context</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0299/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0299/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 7.8 High  
Affected: Palo Alto Networks  
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.  
What to do: GlobalProtect App: fixed releases vary by platform and prior version (6.3.3-h15 on Linux, 6.3.3-h14 on macOS/Windows, 6.0.15 for 6.0.x) -- see the advisory's own version table for the exact upgrade path.</description>
    </item>
    <item>
      <title>Palo Alto Networks GlobalProtect's Code Injection Vulnerability Allows an Authenticated Remote Attacker to Execute Arbitrary Code in the Context of the VPN Client</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0298/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0298/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 8.1 High  
Affected: Palo Alto Networks  
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.  
What to do: GlobalProtect App 6.3 on Windows (6.3.0 through 6.3.3-h13): upgrade to 6.3.3-h14 (6.3.3-1121) or later. 6.2 on Windows (6.2.0 through 6.2.8-h12): upgrade to 6.2.8-h13 (6.2.8-1045) or later. 6.0 on Windows (6.0.0 through 6.0.14): upgrade to 6.0.15 or later. macOS/Linux/iOS/Android/Chrome OS: no action needed.</description>
    </item>
    <item>
      <title>Palo Alto Networks GlobalProtect's Out-of-Bounds Write Allows a Remote Attacker to Corrupt Memory and Execute Code or Crash the Application</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0297/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0297/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 8.1 High  
Affected: Palo Alto Networks  
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).  
What to do: GlobalProtect App: upgrade to 6.3.3-h15 (Linux), 6.3.3-h14 (macOS/Windows), or 6.3.5 (iOS/Android/Chrome OS) as applicable -- see the advisory's own version table for the exact fixed release per platform.</description>
    </item>
    <item>
      <title>Palo Alto Networks GlobalProtect's Improper Certificate Validation Allows a Network Adversary to Present a Forged Certificate and Intercept the VPN Connection</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0296/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0296/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 7.4 High  
Affected: Palo Alto Networks  
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.  
What to do: GlobalProtect App: upgrade paths vary by platform/version (see the advisory's own version table); iOS, Android, and Chrome OS are not affected. No known workarounds beyond upgrading to a fixed release.</description>
    </item>
    <item>
      <title>Palo Alto Networks GlobalProtect's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0295/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0295/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 7.0 High  
Affected: Palo Alto Networks  
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.  
What to do: GlobalProtect App 6.3 on macOS (6.3.0 through 6.3.3-h13): upgrade to 6.3.3-h14 (6.3.3-1121) or later. 6.2 on macOS (6.2.0 through 6.2.8-h12): upgrade to 6.2.8-h13 (6.2.8-1045) or later. 6.0 on macOS (6.0.0 through 6.0.14): upgrade to 6.0.15 or later. All other platforms: no action needed. Workarounds and Mitigations: no known workarounds.</description>
    </item>
    <item>
      <title>Palo Alto Networks Prisma Access Agent's Uncontrolled Search Path Allows a Local Attacker to Place a Malicious Library Where the Agent Will Load It</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0294/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0294/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Exploited]  
CVSS 7.8 High  
Affected: Palo Alto Networks  
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges.  
What to do: Prisma Access Agent on Windows and macOS (24.0 through 26.2.2): upgrade to 26.3 or later. Prisma Access Agent on Linux, iOS, Android, and Chrome OS: no action needed. Workarounds and Mitigations: no known workarounds exist for this issue.</description>
    </item>
    <item>
      <title>Linux Kernel's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges on the System; CISA's September 21st KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-39964/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-39964/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Linux, Siemens  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's and Siemens's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel's Improper Check for Exceptional Conditions Allows Remote Attackers to Execute Arbitrary Code or Crash Affected Systems; CISA's September 21st KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-39682/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-39682/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Linux, debian  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's and debian's web pages for any future patch releases.</description>
    </item>
    <item>
      <title>Fortinet Multiple Products' Heap-Based Buffer Overflow Allows Remote Attackers to Potentially Execute Arbitrary Code or Crash Affected Devices; CISA's September 12th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-25249/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-25249/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.1 High  
Affected: Fortinet, Siemens  
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets  
What to do: ** Monitor Fortinet's and Siemens's web pages for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-82078/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-82078/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.1 Critical  
Affected: PaperCut  
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.  
What to do: ** Monitor PaperCut's web page for any future patch releases.</description>
    </item>
    <item>
      <title>TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72530/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72530/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.0 Critical  
Affected: TrueConf  
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.  
What to do: ** Monitor TrueConf's web page for any future patch releases.</description>
    </item>
    <item>
      <title>TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72529/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72529/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: TrueConf  
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.  
What to do: ** Monitor TrueConf's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft SharePoint Online's Cross-Site Scripting Flaw Lets Attackers Execute Arbitrary JavaScript in the Victim's Browser Session</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-70332/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-70332/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.6 Critical  
Affected: Microsoft  
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Edge's Origin Validation Error Allows a Cross-Origin Attacker to Bypass Boundary Enforcement and Access Content from a Different Origin</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66322/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66322/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.1 High  
Affected: Microsoft  
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Edge's Type Confusion in the Browser Engine Allows a Remote Attacker to Execute Arbitrary Code via a Crafted Web Page</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66321/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66321/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.4 High  
Affected: Microsoft  
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Edge's Origin Validation Error Exposes Protected Resources to Cross-Origin Content Access by a Network Attacker</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66318/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66318/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.1 High  
Affected: Microsoft  
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Edge's Use After Free Vulnerability Lets a Remote Attacker Corrupt the Browser Heap and Potentially Execute Code via a Crafted Web Page</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66315/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66315/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Microsoft  
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Edge's Externally Controlled File Path Allows a Crafted Web Page to Reference Arbitrary Files on the Local System</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-66310/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-66310/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.7 High  
Affected: Microsoft  
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Edge's External Control of a File Path Flaw Allows Attackers to Read or Write Files Outside the Intended Browsing Sandbox via a Crafted Page</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-65802/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-65802/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.4 High  
Affected: Microsoft  
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Purview eDiscovery's Improper Access Control Allows Authenticated Attackers to Access Data Outside Their Authorized Scope</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-65668/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-65668/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Microsoft  
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Teams Carries a Critical 10.0 CVSS Score for a Missing Authorization Flaw That Lets Authenticated Users Access Privileged Functions</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-65667/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-65667/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 10.0 Critical  
Affected: Microsoft  
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Planetary Computer's Missing Authentication on a Critical Endpoint Allows Unauthenticated Attackers to Access and Execute Privileged Functions</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-63508/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-63508/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 10.0 Critical  
Affected: Microsoft  
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Teams' Improper Cryptographic Signature Verification Allows Attackers to Submit Forged Messages That the Application Accepts as Authentic</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-62918/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-62918/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: Microsoft  
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Teams' Improper Authentication Allows Unauthenticated Remote Attackers to Access the Platform Without Valid Credentials</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-62896/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-62896/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.6 Critical  
Affected: Microsoft  
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Windows Admin Center's Improper Cryptographic Signature Verification Enables Unauthenticated Attackers to Forge Signed Requests and Gain Unauthorized Access</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-62873/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-62873/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Microsoft  
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Excel's Use After Free Vulnerability Lets Remote Attackers Execute Arbitrary Code via a Specially Crafted Workbook</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-62870/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-62870/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.8 High  
Affected: Microsoft  
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft Entra Provisioning Service's Path Traversal Flaw Allows Attackers to Navigate Outside the Intended Directory and Access Provisioned Tenant Data</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-59115/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-59115/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Microsoft  
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft PowerShell's High-Severity Flaw Allows a Network-Based Attacker to Gain Unauthorized Access on Affected Installations</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-58612/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-58612/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.4 High  
Affected: Microsoft  
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Microsoft SharePoint Server's Unspecified Flaw Allows an Authenticated Attacker to Gain Unauthorized Access to Server Resources</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-57105/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-57105/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.0 High  
Affected: Microsoft  
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Siemens SCALANCE LPE9403's Configuration Parameter Handling Flaw Lets Non-Privileged Local Attackers Execute Commands as Root When SINEMA Remote Connect Edge Client Is Installed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-40582/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-40582/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Siemens  
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions &lt; V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters.  
What to do: Update to V2.1 HF0 or later version (Available on Industrial Edge Hub for ARM 64 and X86). Mitigations: Only use trusted SINEMA Remote Connect Servers; Restrict access to authorized and trusted personal only.</description>
    </item>
    <item>
      <title>Siemens SCALANCE LPE9403's Authentication Bypass Allows Non-Privileged Local Attackers to Bypass Authentication Controls on Affected Versions</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-40581/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-40581/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.1 High  
Affected: Siemens  
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions &lt; V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass.  
What to do: Update to V2.1 HF0 or later version (Available on Industrial Edge Hub for ARM 64 and X86). Mitigation: Restrict access to authorized and trusted personal only.</description>
    </item>
    <item>
      <title>Siemens SCALANCE LPE9403's Incorrect Permissions on Critical Resources Expose the Backup Manager Service to Non-Privileged Local Attackers</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-40574/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-40574/</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.8 High  
Affected: Siemens  
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions &lt; V4.0 HF0). Affected devices do not properly assign permissions to critical ressources.  
What to do: Update to V4.0 HF0 or later version (https://support.industry.siemens.com/cs/ww/en/view/109989944/). Mitigation: Restrict access to authorized and trusted personal only.</description>
    </item>
    <item>
      <title>Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-87491/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-87491/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Google  
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.  
What to do: ** Monitor Google's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-59822/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-59822/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.2 High  
Affected: BerriAI, litellm  
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.  
What to do: ** Monitor BerriAI's and litellm's web pages for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-58704/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-58704/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.8 High  
Affected: Google  
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.  
What to do: ** Monitor Google's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-49869/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-49869/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Kestra  
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container.  This vulnerability is fixed in 1.0.45 and 1.3.21.  
What to do: ** Monitor Kestra's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Mitsubishi Electric GX Works3 and Motion Control Setting Authentication Algorithm Allows a Local Attacker to Successfully Authenticate with an Invalid Block Password by Modifying the Executable Module in Memory</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-15688/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-15688/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.2 Critical  
Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs.</description>
    </item>
    <item>
      <title>Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Server</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-12745/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-12745/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Ivanti  
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.  
What to do: ** Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows a Second Unauthenticated Remote Code Execution Path on the Server</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-12744/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-12744/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Ivanti  
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.  
What to do: ** Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows Authenticated Remote Attackers to Execute Arbitrary Code on the Server, Scoring CVSS 9.9</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-12650/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-12650/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Ivanti  
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.  
What to do: ** Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server, Scoring CVSS 9.9</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-12647/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-12647/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Ivanti  
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.  
What to do: ** Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server via a Second Unprotected Path</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-12646/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-12646/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Ivanti  
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.  
What to do: ** Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server via a Third Unprotected Path</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-12645/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-12645/</guid>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Ivanti  
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.  
What to do: ** Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Linux Kernel HID Roccat Driver Uses an 8-bit Device-Supplied Profile Value as an Array Index Without Bounds Checking, Enabling an Out-of-Bounds Memory Access via a Crafted USB Device</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-93188/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-93188/</guid>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel TC Classifier Filter Allocations in the change() Path Use Plain GFP Flags Without Accounting to memcg, Allowing Container Workloads to Exhaust Host Memory Without Being Charged</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-90099/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-90099/</guid>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel qdisc_calculate_pkt_len Amplifies User-Supplied Size Table Values Without Bounds Checking, Allowing a Crafted Size Table to Cause a Soft Lockup in the Packet Scheduler</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-90058/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-90058/</guid>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Arista EOS P4Runtime Client Interface Allows Unauthenticated Arbitrary Code Execution Under Certain Conditions on Platforms Running EOS with P4Runtime Configured, Scoring CVSS 10.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-73453/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-73453/</guid>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 10.0 Critical  
An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch.</description>
    </item>
    <item>
      <title>Arista EOS gRPC Network Security Interface Certz Service Lets a Privileged Authenticated User Execute Arbitrary Commands with Root Privileges, Leading to Full Device Compromise</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-73447/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-73447/</guid>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected. (NVD)</description>
    </item>
    <item>
      <title>Arista EOS DHCP Relay Forwards Crafted Reply Packets From Non-Helper-Address Sources to Clients Without Validation, Letting Unauthenticated Network Attackers Inject Arbitrary DHCP Responses to Hosts</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-73437/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-73437/</guid>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.6 Critical  
On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent would forward it to clients without validating the source. This could allow the attacker to supply clients with malicious network configuration parameters, potentially resulting in traffic interception or denial of service for affected clients. (NVD)</description>
    </item>
    <item>
      <title>Linux Kernel SCTP Authenticated ASCONF DEL-IP Removes a Transport While a Backlogged Chunk Still Holds a Pointer to It, Enabling Use-After-Free on the Next SACK</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-89478/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-89478/</guid>
      <pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Fortinet FortiMonitorOnSight 7.2.0 Through 7.2.7 Embeds Sensitive Information in Source Code, Potentially Allowing Attackers to Gain Unauthorized Access via Exposed Credentials</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-84390/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-84390/</guid>
      <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via &lt;insert attack vector here&gt;</description>
    </item>
    <item>
      <title>Advantech WISE-6610 Series Management Interface Fails to Neutralize Special Elements in a Command Argument, Allowing Unauthenticated Remote Attackers to Inject Arbitrary Application Commands</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-79698/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-79698/</guid>
      <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. (NVD)</description>
    </item>
    <item>
      <title>LXD NVIDIA Instance Configuration Handler Accepts Newline Characters in nvidia.driver.capabilities and nvidia.require.* Values, Letting Authenticated Attackers Inject Arbitrary Directives into the GPU Configuration</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-63298/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-63298/</guid>
      <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: canonical  
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon. (NVD)  
What to do: ** Monitor canonical's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Sequelize Before 6.37.4 Fails to Escape Quotes in the Oracle Dialect When a String Value Starts with TO_TIMESTAMP or TO_DATE, Enabling SQL Injection Against Oracle Databases</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-69240/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-69240/</guid>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacker can inject arbitrary SQL expressions through an application value that reaches this escape path. This issue is fixed in version 6.37.4. (NVD)</description>
    </item>
    <item>
      <title>SonicWall Network Security Manager On-Prem File Upload Extracts Archive Entries Without Validating Path Components, Enabling Zip Slip File Placement Outside the Intended Destination Directory</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-81939/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-81939/</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.</description>
    </item>
    <item>
      <title>Advantech WISE-6610 Series Management Interface Exposes a Second Special-Element Injection Path, Allowing Unauthenticated Remote Attackers to Manipulate Application Command Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-79697/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-79697/</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. (NVD)</description>
    </item>
    <item>
      <title>SonicWall Network Security Manager On-Prem Lets a Lower-Privileged Admin Escalate to SuperAdmin Due to a Missing Authorization Check</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-78328/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-78328/</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.</description>
    </item>
    <item>
      <title>SonicWall Network Security Manager On-Prem Management Interface Passes Authenticated User Input to the OS Shell, Enabling Arbitrary Command Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-78327/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-78327/</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.</description>
    </item>
    <item>
      <title>IXON VPN Client Before 1.4.7 Writes Local Service Configuration Values to a File Without Stripping Line-Ending Sequences, Letting an Attacker Inject Commands That Execute as Root or SYSTEM via a Privileged Subprocess</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-75925/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-75925/</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.6 Critical  
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester. The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user. (NVD)</description>
    </item>
    <item>
      <title>OpenSIPS 4.0.0 and Prior Stack Buffer Overflow in sip_to_json When a SIP Header Name Exceeds 255 Bytes, Enabling Remote Code Execution via Crafted SIP Messages</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-45538/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-45538/</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes a stack buffer overflow when sip_to_json() is called in the routing script. Function sip_to_json() (modules/sipmsgops/sipmsgops.c) copies SIP header names into a fixed 255-byte stack buffer without bounds checking, performing a memcpy of the full header-name length even though the SIP parser imposes no such limit (a header name can be roughly 65000 bytes). As a result, when a routing script calls sip_to_json(), a SIP message with a header name longer than 255 bytes triggers a stack buffer overflow in which both the length and content of the overwrite are attacker-controlled, corrupting the saved frame pointer and return address. A single unauthenticated UDP packet to the SIP port (5060) can crash the process or, on builds without stack protections, hijack the return address to achieve remote code execution. This affects deployments whose routing script invokes sip_to_json(). This issue was not fixed at the time of publication. (NVD)</description>
    </item>
    <item>
      <title>Fortinet FortiSandbox 4.4.x and 5.0.x Improper Access Control Lets Attackers Access Sensitive Information via Crafted HTTP Requests</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-26084/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-26084/</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.</description>
    </item>
    <item>
      <title>Red Hat Advanced Cluster Management Application Subscription Controller Lets a User with Namespace-Scoped Edit Privileges Create a Channel Pointing to an Attacker-Controlled Helm Repository, Enabling Privilege Escalation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-10090/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-10090/</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.0 Critical  
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the "open-cluster-management:subscription-admin" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the "cluster-admin" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only. (NVD)</description>
    </item>
    <item>
      <title>D-Link DNS-320 ShareCenter 2.06B01 File Sharing CGI Passes the fileurl Parameter Unsanitized to the Shell, Enabling Remote Code Execution by Authenticated Admin Users</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-85224/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-85224/</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. (NVD)</description>
    </item>
    <item>
      <title>D-Link DNS-340L 1.01B04 Dropbox CGI Injects the callback_url and sync_interval Fields Directly into the Shell, Allowing Low-Privileged Authenticated Attackers to Execute Remote Commands</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-85223/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-85223/</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. (NVD)</description>
    </item>
    <item>
      <title>D-Link DNS-340L 1.01B04 Add-On Center CGI Passes f_name, f_url, and f_flag Unsanitized to the Shell, Enabling Authenticated Admin Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-85222/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-85222/</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. (NVD)</description>
    </item>
    <item>
      <title>D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 USB Device Handler Passes Unsanitized Input to the Shell, Enabling Authenticated Admin Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-82691/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-82691/</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. (NVD)</description>
    </item>
    <item>
      <title>D-Link DNS-340L and DNS-345 Virtual Volume CGI Injects Input Arguments Unsanitized into the Shell, Enabling Authenticated Admin Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-82688/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-82688/</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. (NVD)</description>
    </item>
    <item>
      <title>D-Link DIR-825M 1.1.8 LTE Fibocom Firmware Upgrade Handler Copies Unbounded User Input into a Fixed Stack Buffer, Enabling Unauthenticated Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-82593/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-82593/</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. (NVD)</description>
    </item>
    <item>
      <title>D-Link DNS-340L and DNS-345 iSCSI Manager CGI Passes alias, username, and password Arguments Directly to the Shell, Allowing Low-Privileged Attackers to Execute Remote Code</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-82692/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-82692/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. (NVD)</description>
    </item>
    <item>
      <title>D-Link DNS-327L and DNS-340L Virtual Environment Manager CGI Injects Unsanitized User Arguments into the Shell, Enabling Authenticated Admin Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-82690/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-82690/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. (NVD)</description>
    </item>
    <item>
      <title>D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 ISO Image Mount Handler Passes Mount Arguments Unsanitized to the Shell, Allowing Low-Privileged Attackers to Execute Remote Commands</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-82689/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-82689/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. (NVD)</description>
    </item>
    <item>
      <title>D-Link DIR-825M 1.1.8 Disk Format Handler Overflows a Stack Buffer When the manipulation Parameter Exceeds Its Declared Bounds, Enabling Unauthenticated Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-82592/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-82592/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 app.cgi Overflows a Stack Buffer on a Long netAcc.addlist[].name Value, Enabling Unauthenticated Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71957/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71957/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 app.cgi Injects the netDig.ping.dst Field Unsanitized into the Shell, Enabling Unauthenticated Remote Code Execution with Root Privileges</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71956/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71956/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 PIN Management Setup Handler Injects the oldPIn Field Into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71952/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71952/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 IMEI Setup Handler Passes the IMEI_value Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71951/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71951/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 SMS Management Handler Injects the action_value Field Directly into the Shell, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71950/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71950/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 Traceroute Diagnostic Handler Injects the host and ipVer Fields into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71947/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71947/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 Ping Diagnostic Run Handler Passes the host Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71946/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71946/</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>Linux Kernel OCC hwmon Driver Unregisters sysfs Devices While Holding the OCC Lock, Causing a Deadlock When hwmon_device_unregister Tries to Flush sysfs Work Items</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80660/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80660/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel MMC vub300 Driver Issues a Reset While Holding cmd_mutex, Blocking the Command Thread That Must Complete Before the Reset Can Proceed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-80659/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-80659/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 quicksetup.cgi Overflows a Stack Buffer on Long test4, ssid2, or username Values, Enabling Unauthenticated Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71958/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71958/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 formWsc Handler Injects localPin, targetAPSsid, peerPin, and peerRptPin Fields into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71955/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71955/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 L2TPv3 Configuration Handler Injects tunnelid and sessionid Fields Directly into the Shell, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71954/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71954/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 NTP Setup Handler Passes the ntpServerIp1 Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71953/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71953/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 USSD Setup Handler Injects ussdValue and selectMenuValue into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71949/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71949/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 Debug Diagnostic Run Handler Passes the host Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71948/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71948/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 LTE Fibocom Firmware Upgrade Handler Injects the fota_url Field into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71945/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71945/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>D-Link DWR-M961 C1 LTE Quectel Firmware Upgrade Handler Passes the fota_url Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71944/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71944/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges. (NVD)</description>
    </item>
    <item>
      <title>Splunk Enterprise Below 10.4.1 Exposes Session Material in the HTML Source of Pages Embedding Reports, Letting Unauthenticated Users Who Can Read That Source Access All Report Data and Affect System Integrity</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-76312/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-76312/</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.4 Critical  
Affected: Splunk  
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system integrity. The vulnerability is possible because the dispatch archive download path does not correctly enforce the embedded-report authorization boundary and includes sensitive session material in archived search-job data. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and Embed scheduled reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation. (NVD)  
What to do: ** Monitor Splunk's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Search Job Dispatch Archive and Recover Session Material for Full Report Data Access</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-76311/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-76311/</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.4 Critical  
Affected: Splunk  
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system integrity on the Splunk platform instance. The vulnerability is possible because the embedded report authorization flow does not block dispatch archive download requests before Splunk Enterprise begins sending the archive to the requester. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and Embed scheduled reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation. (NVD)  
What to do: ** Monitor Splunk's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Dispatch Archive and Recover Session Tokens That Grant Access to All Data Available to the Report Owner</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-76310/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-76310/</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.4 Critical  
Affected: Splunk  
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk role. The vulnerability is possible because embedded report access does not block Representational State Transfer (REST) API dispatch archive download requests. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/9.1/report-management/additional-configuration-for-embedded-reports) and About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation. (NVD)  
What to do: ** Monitor Splunk's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Red Hat Advanced Cluster Management Multicloud Subscription Component Lets a Namespace-Admin Tenant Abuse a Privileged ServiceAccount via Subscription CRs, Enabling a Confused-Deputy Attack Against Other Cluster Namespaces</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72508/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72508/</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster. (NVD)</description>
    </item>
    <item>
      <title>Red Hat Advanced Cluster Management GitOpsCluster Controller Lets an Authenticated Tenant Redirect Spoke Cluster Bearer Tokens to an Attacker-Controlled Endpoint, Enabling a Confused-Deputy Attack</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-70398/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-70398/</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.6 Critical  
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects. (NVD)</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Component Allows Unauthenticated HTTP Attackers to Compromise the Application, Enabling Full Takeover of the EnterpriseOne Tools Instance</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-61272/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-61272/</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Zyxel WAH7601 Through July 2026 Firmware OS Command Injection Allows Attackers to Execute Arbitrary OS Commands on Affected Devices</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-13206/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-13206/</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection.</description>
    </item>
    <item>
      <title>Linux Kernel SCTP Heartbeat ACK Chunk Caches a Transport Without Taking a Reference, Enabling Use-After-Free When That Transport Is Concurrently Removed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-74688/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-74688/</guid>
      <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel SCTP Retransmit Path Moves a Gap-Acked Chunk to a New Transport Without Updating the Chunk's Cached Transport Pointer, Enabling Use-After-Free</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-74588/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-74588/</guid>
      <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel SCTP Teardown Path Frees the Cached Outbound ASCONF Chunk Without Clearing the Cache Pointer, Exposing a Use-After-Free</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-74587/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-74587/</guid>
      <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel SCTP Fails to Clear new_transport After DEL-IP Peer Removal, Leaving a Dangling Pointer That Subsequent ASCONF Processing Reads</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-74586/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-74586/</guid>
      <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel GRO Path Performs Double Aggregation of flush-Marked Skbs Because skb_gro_receive_list Lacks the Flush Check Added to skb_gro_receive</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68136/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68136/</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel ipheth USB Ethernet Driver Re-Arms carrier_work on Any Non-Zero URB Status After Disconnect Begins, Causing a Use-After-Free When the Work Item Runs After the Device Structure Is Freed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-74677/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-74677/</guid>
      <pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>VMware Avi Load Balancer 31.x Through 31.2.2 and 30.x Through 30.2.6 Authentication Bypass Lets Network-Accessible Attackers Reach the Avi Control Plane Without Valid Credentials</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47865/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47865/</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Broadcom  
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.  
What to do: ** Monitor Broadcom's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco Secure Workload Improper Neutralization of Special Elements Vulnerabilities Allow Authenticated Attackers to Inject Directives into Application Commands, Scoring CVSS 9.9</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20231/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20231/</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.</description>
    </item>
    <item>
      <title>Cisco Crosswork Multiple Internally Discovered SQL Injection Vulnerabilities Allow Authenticated Attackers to Execute Arbitrary SQL Against the Underlying Database, Scoring CVSS 10.0</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20030/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20030/</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 10.0 Critical  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.</description>
    </item>
    <item>
      <title>Linux Kernel PCH GPIO Driver Acquires a Regular Spinlock in irq_set_type Which Can Be Called From a Non-IRQ Context, Leading to a Deadlock When Interrupts Are Disabled</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-74468/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-74468/</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel IPv6 FIB6 Walk Reuses a Stale Position Index Across Hash Chain Batches During a Multi-Batch Netlink Dump, Triggering a NULL Dereference in fib6_walk_continue</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72392/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72392/</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel USB Gadget Printer Driver printer_read Uses the Same Variable for Requested Copy Size and Bytes Copied, Looping Indefinitely When copy_to_user Fails to Copy Anything</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68369/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68369/</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel Ceph Cap Handler Reads snap_trace_len from the Wire and Uses It Without Bounds Checking, Enabling a Network-Controlled Out-of-Bounds Read Before Authentication</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68160/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68160/</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel X.25 Drops the x25_list_lock Before Calling sock_hold During Neighbour Teardown, Allowing a Concurrent Free to Race and Produce a Use-After-Free</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68137/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68137/</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel ILA Caches the IPv6 Header Pointer Before pskb_may_pull, Which Can Reallocate the Header on a Non-Linear skb, Producing a Stale Pointer in Checksum Adjust</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68127/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68127/</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel TIPC Socket Creation Error Path Frees the sk While Leaving sock-&gt;sk Pointing at the Freed Object, Enabling a Use-After-Free on Subsequent Socket Operations</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68117/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68117/</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel Input ims-pcu Driver ims_pcu_process_data Processes Incoming URB Data Without Checking Whether read_pos Exceeds IMS_PCU_BUF_SIZE, Enabling Heap Buffer Overflow via a Crafted USB Device</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-64565/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-64565/</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel SCTP DEL-IP Processing Frees the Transport Cached on the ASCONF Chunk Itself, Triggering Use-After-Free on the Chunk's Own Transport Pointer</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-64564/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-64564/</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>CVE-2026-72585 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72585/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72585/</guid>
      <pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.</description>
    </item>
    <item>
      <title>Linux Kernel SCTP ASCONF Chunk Processing Skips Length Validation of Embedded Address Parameters, Allowing Network-Controlled Data to Trigger Out-of-Bounds Reads</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-74287/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-74287/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>CVE-2026-72568 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72568/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72568/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.</description>
    </item>
    <item>
      <title>CVE-2026-72540 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72540/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72540/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.</description>
    </item>
    <item>
      <title>Linux Kernel KVM s390 VSIE Shadow Fault Handler Missing radix_tree_preload Call Can Block Forward Progress Under Memory Pressure During Fault Handling</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72293/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72293/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel nvidiafb Driver nvidiafb_probe Error Path Leaks the modelist Memory Allocated by nvidia_set_fbinfo When Subsequent Initialization Steps Fail</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-72265/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-72265/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>CVE-2026-71245 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-71245/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-71245/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.</description>
    </item>
    <item>
      <title>Linux Kernel MPTCP Cleans Up Subflow backlog References Outside the Lock That Guards the Backlog List, Leaving a Stale skb-&gt;sk Pointer After Subflow Close</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68170/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68170/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel OpenVPN Driver Peer Reference Count Leaks in the TCP Error Path When defer_del_work Is Already Pending, Preventing Timely Peer Cleanup</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68122/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68122/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel Uses the jiffies Clocksource Before It Is Registered With the Clocksource Framework, Causing XEN HVM Guests to Experience Long Boot Delays Due to Negative Motion Reporting</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68092/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68092/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel debugobjects OOM Disable Path Races Against a Concurrent hrtimer_fixup_assert_init Call, Producing a Spurious stub_timer Callback Warning</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-68090/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-68090/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel Intel HID ACPI Notify Handler Can Run Concurrently on Multiple CPU Cores Since commit e2ffcda16290, Causing Race Conditions in the Hot-Plug Notification Handler</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-64603/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-64603/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Linux Kernel btrfs Trim Path Calls blkdev_issue_discard on a Device Marked Read-Only During Degraded Mount, Dereferencing a NULL Device Pointer and Panicking</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-64593/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-64593/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>SolarWinds Web Help Desk SAML 2.0 Authentication Bypass Lets Attackers Authenticate Without Valid Credentials When SAML Is Enabled</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28323/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28323/</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: SolarWinds  
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Addresses Multiple Internally Discovered Improper Link Resolution Vulnerabilities That Could Allow Local Privilege Escalation via Symlink Following</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20310/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20310/</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Improper Access Control Vulnerabilities Allow Attackers to Perform Unauthorized Actions on Affected Systems, Scoring CVSS 9.9</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20304/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20304/</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Improper Input Validation Vulnerabilities Enable Attackers to Cause Unintended System Behavior on Affected Deployments, Scoring CVSS 9.9</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20303/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20303/</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.9 Critical  
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.</description>
    </item>
    <item>
      <title>Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-64125/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-64125/</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>FormGent WordPress Plugin Through 1.9.2 Missing Capability Check on the formgent/responses/attachments REST Endpoint Lets Any Authenticated User Delete Arbitrary Attachments</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-3141/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-3141/</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This makes it possible for unauthenticated attackers to delete arbitrary files within the formgent uploads directory. Additionally, on Linux servers where the wp-content/uploads/formgent directory does not yet exist (the default state after plugin installation), the path traversal protection can be bypassed, enabling deletion of arbitrary files including wp-config.php which can lead to complete site takeover via a fresh WordPress installation. (NVD)</description>
    </item>
    <item>
      <title>Dell Virtual Storage Integrator for VMware vSphere Client IAPI Component Accepts Unauthenticated Remote Input and Passes It to the OS Shell, Enabling Arbitrary Command Execution on the Application Host</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-67261/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-67261/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: dell  
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity. (NVD)  
What to do: ** Monitor dell's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Azure Red Hat OpenShift Improper Authorization Lets an Authorized Attacker Escalate Privileges Over the Network</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-56160/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-56160/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Microsoft  
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.  
What to do: ** Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Dell Virtual Storage Integrator for VMware vSphere Client Exposes Sensitive Information to Unauthenticated Remote Attackers, Enabling Information Disclosure and Session Hijacking</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-54489/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-54489/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: dell  
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity. (NVD)  
What to do: ** Monitor dell's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo's Deserialization of Untrusted Data Allows Remote Attackers to Execute Arbitrary Code via a Crafted Serialized Object</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47623/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47623/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.2 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo's Server-Side Request Forgery Flaw Lets Attackers Use the Inference Server as an HTTP Proxy to Reach Internal Services</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47618/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47618/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo Server-Side Request Forgery Flaw Allows Attackers to Make the Service Issue Requests to Arbitrary Hosts, Including Internal Resources</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47617/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47617/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo's SSRF Vulnerability Exposes Internal Network Infrastructure to Attackers Who Can Redirect the Server's Outbound HTTP Connections</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47616/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47616/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo's Unvalidated URL Handling Lets Attackers Steer the Inference Server's HTTP Requests Toward Internal Hosts and Retrieve Their Responses</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47615/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47615/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo Carries an SSRF Flaw That Enables Attackers to Probe Internal Services via the Dynamo Server's Request Mechanism</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47614/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47614/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo's Server-Side Request Forgery Vulnerability Allows Attackers to Redirect the AI Inference Server's HTTP Requests Toward Internal or External Targets</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47613/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47613/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo's Path Traversal Flaw Allows Attackers to Navigate Outside the Intended Directory and Read or Write Files in Restricted Locations</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47612/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47612/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo's Incomplete Input Comparison Allows Attackers to Bypass a Security Check by Supplying Input the Comparison Logic Fails to Fully Evaluate</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24255/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24255/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 7.5 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access the AI Inference Platform Without Valid Credentials</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24254/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24254/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>NVIDIA Dynamo's Out-of-Bounds Write Allows Remote Attackers to Corrupt Memory and Potentially Execute Arbitrary Code via a Crafted Request</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-24253/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-24253/</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 8.2 High  
Affected: nvidia  
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.  
What to do: ** Monitor nvidia's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Check Point Security Management Server and Multi-Domain Management Server Authentication Bypass Lets Unauthenticated Remote Attackers Execute Arbitrary Commands via Management Service Network Access</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-18574/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-18574/</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.3 Critical  
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation. (NVD)</description>
    </item>
    <item>
      <title>pgAdmin 4 Import/Export Data Tool Builds a psql \copy Command by Interpolating User-Supplied SQL into a Jinja Template Without Sufficient Escaping, Enabling Authenticated Attackers to Execute Arbitrary OS Commands</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-17566/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-17566/</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: pgadmin  
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/&lt;sid&gt;, gated only by the ordinary, commonly-granted tools_import_export_data permission) validated the query with a hand-written parenthesis-balance checker, _is_query_parens_balanced(). That checker always treated a backslash before a single quote (\') as escaping the quote, i.e. as if standard_conforming_strings were off. PostgreSQL has defaulted standard_conforming_strings to on since 9.1 (2010), the default on every PostgreSQL version pgAdmin 4 currently supports (13-18); under that default psql's own \copy tokenizer treats \ as an ordinary character, so a single quote immediately after it closes the string literal. A query such as SELECT 'a\') TO PROGRAM 'echo pwned' x' was therefore accepted as "balanced" by pgAdmin's checker (which believed the ) was still inside the string), while psql, run through the actual rendered command line, closes the string at that point and treats the following ) as the end of the wrapping \copy (...) subquery, exposing an attacker-chosen TO PROGRAM '&lt;command&gt;' clause that psql executes via popen() -- independent of a subsequent syntax error later on the same line. This is the same class of bug as CVE-2025-12762/CVE-2025-13780 (RCE via psql meta-command/COPY injection during PLAIN-format dump restore), reached through an independently written defense in a different module (Import/Export Data rather than Restore) that had its own, different logic bug (inverted backslash-escape semantics rather than a BOM-defeated regex anchor).  
What to do: ** Monitor pgadmin's web page for any future patch releases.</description>
    </item>
    <item>
      <title>CVE-2026-13325 Rejected by Red Hat Product Security After Concluding the CVE Record Is Not Needed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-13325/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-13325/</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <description>[New]  
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.</description>
    </item>
    <item>
      <title>Honeywell Control Network Module Web Interface Allows Command Delimiter Injection, Potentially Enabling Remote Code Execution via the Web Management Interface</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-5433/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-5433/</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
Honeywell Control</description>
    </item>
    <item>
      <title>VMware ESX VMXNET3 Virtual Network Adapter Contains an Out-of-Bounds Write Reachable by a Local VM Admin, Potentially Enabling Code Execution on the Underlying Host</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-47876/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-47876/</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.3 Critical  
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. (NVD)</description>
    </item>
    <item>
      <title>Arista EOS Orchestrator API Component Fails to Validate Input Before Building Backend Queries, Letting Authenticated Users Access Unauthorized Data and Trigger Unintended Outbound Network Connections</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-17191/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-17191/</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.1 Critical  
An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections.</description>
    </item>
    <item>
      <title>Linux Kernel KVM x86 Fast IN Path Calls emulator_pio_in When __emulator_pio_in Could Be Used Directly, Causing Unnecessary Indirection in the PIO Emulation Path</title>
      <link>https://ot-advisories.com/advisories/CVE-2022-4994/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2022-4994/</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-16812/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-16812/</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Arista  
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.  
What to do: ** Monitor Arista's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Linux Kernel amdgpu GEM Op IOCTL Leaks a drm_exec Lock Held at the Time of a kvcalloc Failure in AMDGPU_GEM_OP_GET_MAPPING_INFO, Causing a Lock Imbalance</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-63880/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-63880/</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
In the Linux kernel, the following vulnerability has been resolved:</description>
    </item>
    <item>
      <title>CVE-2026-10517 Retracted by Red Hat Product Security and Upstream Clair/Claircore Maintainer After Confirming the Described PSK Authentication Behavior Is Intentional and Implemented in a Separate Package</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-10517/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-10517/</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is implemented entirely in github.com/quay/clair; no PSK-related code exists anywhere in claircore's codebase or git history. The unauthenticated indexer API is Clair's documented, intentional design, authentication is an opt-in deployment choice, not a code defect. No fix commit was found in claircore between the version recorded as the affected boundary (1.5.52) and the following release (1.5.53); intervening commits are unrelated dependency and feature changes, so the "fixed in 1.5.52" status is inaccurate. (NVD)</description>
    </item>
    <item>
      <title>Linux Kernel DVB-net ULE Extension Handler Uses a Network-Controlled Index into a 255-Entry Table Without Bounds Checking, Enabling Out-of-Bounds Reads and Writes</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-31405/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-31405/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U Broken Access Control Allows a Domain Administrator to Read and Write Arbitrary Files, Then Escalate Privileges and Execute Code as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28321/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28321/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U IDOR Vulnerability Lets a Domain Administrator Reference Objects Outside Their Authorized Scope to Escalate Privileges</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28317/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28317/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U IDOR Vulnerability Lets a Domain Account With Administrator Access Escalate to System Administrator and Execute Commands as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28316/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28316/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U IDOR Vulnerability Allows Authenticated Users to Reference Objects Outside Their Authorized Scope, Leading to Account Takeover</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28314/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28314/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U IDOR Vulnerability Enables SMTP Configuration Hijacking, Allowing an Authenticated User to Take Over Arbitrary Accounts</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28313/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28313/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U Privilege Escalation Lets a Group's Access Be Elevated to System Administrator, Enabling Code Execution as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28312/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28312/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U Privilege Escalation Allows a Domain Administrator to Elevate Their User Type to System Administrator</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28310/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28310/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U Broken Access Control Lets a Domain Administrator Create System Administrator Accounts Without Proper Authorization</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28309/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28309/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U IDOR Vulnerability Allows a Domain Administrator to Reference Objects Outside Authorized Scope, Leading to Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28308/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28308/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U Privilege Escalation Allows a Domain User Group to Be Elevated to Administrator Access Without Authorization</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28307/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28307/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U Privilege Escalation Allows a Domain Administrator to Elevate Their Privileges to System Administrator Level</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28306/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28306/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U IDOR Vulnerability Allows a Domain Administrator with Home Directory Access to Reference Out-of-Scope Objects, Enabling Remote Code Execution as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28305/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28305/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U Remote Code Execution Vulnerability Allows Arbitrary Code to Run as Root on Affected Linux Installations</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28304/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28304/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U IDOR Vulnerability Lets Group Administrators Reference Out-of-Scope Objects to Escalate Privileges and Execute Code as Root</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-28302/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-28302/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: SolarWinds  
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments. (NVD)  
What to do: ** Monitor SolarWinds's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Linux Kernel SMC-over-TCP SYN Receive Path Calls sock_hold Then Schedules a tcp_close Work Item Without Synchronizing Against Concurrent Stack Cleanup, Enabling Use-After-Free and Null Dereference</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-23450/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-23450/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Samsung Exynos L2 Layer Incorrect Handling of LTE MAC Packets Containing Many MAC Control Elements Leads to Uncontrolled Resource Consumption, Affecting Processors from Exynos 980 Through W1000</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-58349/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-58349/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Samsung  
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Incorrect handling of LTE MAC packets containing many MAC Control Elements (CEs) leads to baseband crashes. (NVD)  
What to do: ** Monitor Samsung's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Samsung Exynos Modem SMS Processing Stack-Based Buffer Overflow, Scoring CVSS 10.0 and Affecting Processors from Exynos 980 Through Exynos 2500 and Multiple Modem Generations</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-54328/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-54328/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 10.0 Critical  
Affected: Samsung  
An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. A Stack-based Buffer Overflow occurs while parsing SMS RP-DATA messages. (NVD)  
What to do: ** Monitor Samsung's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Mitsubishi Electric GENESIS64 and ICONICS Suite 10.97.3 and Prior Store Sensitive Information in Cleartext in the GUI, Potentially Allowing Local Attackers to Recover Credentials From Screen Captures or Memory</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-14816/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-14816/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.3 Critical  
Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric AnalytiX versions 10.97.3 and prior, Mitsubishi Electric GENESIS versions 11.02 and prior, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions AnalytiX versions 10.97.3 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS versions 11.02 and prior allows a local attacker to disclose the SQL Server credentials displayed in plain text in the GUI of the Hyper Historian Splitter feature by exploiting this vulnerability, when SQL authentication is used for the SQL Server authentication. As a result, the unauthorized attacker could access the SQL Server and disclose, tamper with, or destroy data on the server, potentially cause a denial-of-service (DoS) condition on the system. (NVD)</description>
    </item>
    <item>
      <title>Mitsubishi Electric GENESIS64 and ICONICS Suite 10.97.3 and Prior Store Sensitive Information in Cleartext in Persistent Storage, Potentially Allowing Local Attackers to Recover Credentials From Disk</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-14815/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-14815/</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.3 Critical  
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric AnalytiX versions 10.97.3 and prior, Mitsubishi Electric GENESIS versions 11.02 and prior, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions AnalytiX versions 10.97.3 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS versions 11.02 and prior allows a local attacker to disclose the SQL Server credentials stored in plaintext within the local SQLite file by exploiting this vulnerability, when the local caching feature using SQLite is enabled and SQL authentication is used for the SQL Server authentication. As a result, the unauthorized attacker could access the SQL Server and disclose, tamper with, or destroy data on the server, potentially cause a denial-of-service (DoS) condition on the system. (NVD)</description>
    </item>
    <item>
      <title>LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-54420/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-54420/</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.5 High  
Affected: LiteSpeed  
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.  
What to do: ** Monitor LiteSpeed's web page for any future patch releases.</description>
    </item>
    <item>
      <title>SSH Channel Write Path Overflows a Size Counter on Payloads Larger Than 4GB, Causing the Write Loop to Spin Indefinitely Sending Empty Packets Without Making Progress</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-39834/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-39834/</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: golang  
When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation. (NVD)  
What to do: ** Monitor golang's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Ivanti Sentry Before R10.5.2 / R10.6.2 / R10.7.1 Authentication Bypass Lets Unauthenticated Remote Attackers Create Arbitrary Administrative Accounts and Obtain Full Administrative Access</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-10523/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-10523/</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Ivanti  
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access  
What to do: ** Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Trend Micro Apex One Management Console Path Traversal in a Second Executable Allows Remote Attackers to Upload Malicious Code and Execute Commands on Affected Installations</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-71211/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-71211/</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: trendmicro  
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable.  
What to do: ** Monitor trendmicro's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Trend Micro Apex One Management Console Path Traversal Allows Remote Attackers to Upload Malicious Code and Execute Commands on Affected Installations</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-71210/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-71210/</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: trendmicro  
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.  
What to do: ** Monitor trendmicro's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Android Framework's Integer Overflow Enables Code Execution and Local Privilege Escalation; CISA's June 5th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-48595/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-48595/</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 8.4 High  
Affected: Android  
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.  
What to do: ** Monitor Android's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Arista EOS with OpenConfig Configured Fails to Reject Certain gNMI Set Requests That Should Not Execute, Potentially Allowing Unauthorized Configuration Changes on Affected Switches</title>
      <link>https://ot-advisories.com/advisories/CVE-2024-27892/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2024-27892/</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.6 Critical  
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch. (NVD)</description>
    </item>
    <item>
      <title>Arista EOS with OpenConfig Configured Fails to Reject a Second Class of gNMI Set Requests That Should Not Execute, Potentially Allowing Unauthorized Configuration Changes on Affected Switches</title>
      <link>https://ot-advisories.com/advisories/CVE-2024-27890/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2024-27890/</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.6 Critical  
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch. (NVD)</description>
    </item>
    <item>
      <title>Suprema BioStar 2 Exposes Backup ZIP Files Without Authentication When Administrator Places the Backup Path Inside the NGINX Webroot, Allowing Database Download and Server Impersonation</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-9508/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-9508/</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 10.0 Critical  
Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an attacker with network access to directly download backup ZIP files via ‘http(s)://[server]/download/…’ without requiring authentication. This exposes highly sensitive information that can lead to server impersonation, unauthorized access to databases, and lateral movement. (NVD)</description>
    </item>
    <item>
      <title>KNX Protocol Connection Authorization Option 1's Overly Restrictive Lockout Mechanism Lets Attackers Purge Devices and Lock Out Authorized Users with a BCU Key; CISA's July 29th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2023-4346/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2023-4346/</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.5 High  
Affected: KNX Association  
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.  
What to do: ** Monitor KNX Association's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-56155/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-56155/</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 7.8 High  
Affected: Microsoft  
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.  
What to do: ** Monitor Microsoft's web page for any future patch releases.</description>
    </item>
    <item>
      <title>WAGO System I/O Field Series Activates an Undocumented Diagnostic Interface Without Authentication During Early Boot, Granting Unauthenticated Network Access for a Brief Window at Each Power Cycle</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-4769/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-4769/</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise. (NVD)</description>
    </item>
    <item>
      <title>Cortex XSOAR and XSIAM Microsoft Teams Integration Fails to Verify Cryptographic Signatures, Letting Unauthenticated Users Access and Modify Protected Resources</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-0234/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-0234/</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Palo Alto Networks  
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>CVE-2026-50238 Rejected by Red Hat Product Security as Not Required; Underlying Issue Reclassified as a Regular Bug to Be Fixed Through Standard Bug-Fixing Process</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-50238/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-50238/</guid>
      <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
      <description>[New]  
Rejected reason: Red Hat Product Security has concluded that this CVE is not required. The reported issue has been classified as a regular bug and will be addressed through the standard bug-fixing process. (NVD)</description>
    </item>
    <item>
      <title>Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-53225/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-53225/</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Linux  
In the Linux kernel, the following vulnerability has been resolved:  
What to do: ** Monitor Linux's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Advantech Hospital Queuing Management System Exposes API Documentation to Unauthenticated Remote Attackers via a Specific URL, Facilitating Unauthorized Access to Internal API Details</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-14162/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-14162/</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.</description>
    </item>
    <item>
      <title>Delta Electronics DVP12SE PLC Modbus TCP Service Runs Without Authentication or Access Control, Granting Unauthenticated Network Access to Security-Sensitive PLC Functions</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-12819/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-12819/</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.3 Critical  
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated interaction with security-sensitive PLC functions.</description>
    </item>
    <item>
      <title>Delta Electronics DVP12SE PLC Modbus TCP Service Has No Resource Allocation Limits, Making the PLC Susceptible to Denial-of-Service via Request Flooding</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-12818/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-12818/</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.3 Critical  
Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne General Ledger E1 Foundation Component Allows Low-Privileged SMB Attackers to Compromise the Application, With Attacks Potentially Spreading to Additional Oracle Products</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46893/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46893/</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne General Ledger.  While the vulnerability is in JD Edwards EnterpriseOne General Ledger, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne General Ledger. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Human Resources Management Component Allows Unauthenticated HTTP Attackers to Read and Modify Data, Affecting Confidentiality and Integrity</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46892/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46892/</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Human Resources Management accessible data as well as  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Human Resources Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Idira Secrets Manager SaaS Edge Before 1.8 Improper Access Control in Internal Authentication Components Lets Unauthenticated Remote Attackers Access Protected Resources Under Specific Conditions</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-45177/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-45177/</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Palo Alto Networks  
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20 (NVD)  
What to do: ** Monitor Palo Alto Networks's web page for any future patch releases.</description>
    </item>
    <item>
      <title>MISP Before 2.5.36 ApacheAuthenticate Module Passes Unsanitized Username Values Into an LDAP Query, Enabling LDAP Injection by Unauthenticated Users When ApacheAuthenticate Is Enabled</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-39962/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-39962/</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.6 Critical  
Affected: misp-project  
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.apacheEnv is configured to use a user-controlled server variable instead of REMOTE_USER (such as in certain proxy setups). An attacker able to control that value can manipulate the LDAP search filter and potentially bypass authentication constraints or cause unauthorized LDAP queries. This vulnerability is fixed in 2.5.36. (NVD)  
What to do: ** Monitor misp-project's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Splunk AI Toolkit Below 5.7.4 Constructs OS Command Strings from Dynamic btool Configuration Parameters Without Sanitization, Letting Admin-Role Users Execute Arbitrary OS Commands on the Host</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20266/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20266/</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Splunk  
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance.  
What to do: ** Monitor Splunk's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Installation Security Component Allows Unauthenticated Local Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46913/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46913/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.3 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Project Costing Job Costing Component Allows Low-Privileged JDENET Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46911/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46911/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.6 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Project Costing product of Oracle JD Edwards (component: Job Costing).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Project Costing.  While the vulnerability is in JD Edwards EnterpriseOne Project Costing, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Project Costing accessible data as well as  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Project Costing accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated HTTP Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46909/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46909/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Accounts Payable Component Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46908/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46908/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable.  While the vulnerability is in JD Edwards EnterpriseOne Accounts Payable, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Accounts Payable. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Order Promising Integration Component Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Spreading to Additional Oracle Products</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46907/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46907/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Oracle JD Edwards (component: Order Promising Integration).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Order Promising.  While the vulnerability is in JD Edwards EnterpriseOne Order Promising, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Order Promising. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46906/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46906/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.6 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Web Runtime Security Component Allows Unauthenticated HTTP Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46905/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46905/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.8</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46904/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46904/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance in Versions 9.2.0.0 Through 9.2.26.2, One of Six Related CVEs</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46883/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46883/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance in Versions 9.2.0.0 Through 9.2.26.2, One of Six Related CVEs</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46882/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46882/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Third in a Set of Six JDENET-Reachable Takeover Vulnerabilities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46881/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46881/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Fourth in a Set of Six JDENET-Reachable Takeover Vulnerabilities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46880/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46880/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Fifth in a Set of Six JDENET-Reachable Takeover Vulnerabilities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46879/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46879/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Sixth in a Set of Six JDENET-Reachable Takeover Vulnerabilities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46878/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46878/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-8398/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-8398/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Daemon  
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.  
What to do: ** Monitor Daemon's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Ivanti Xtraction Before 2026.2 Lets Authenticated Remote Attackers Supply Arbitrary File Paths to Read Sensitive Files or Write HTML Files into a Web-Accessible Directory</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-8043/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-8043/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.6 Critical  
Affected: Ivanti  
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.  
What to do: ** Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-7473/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-7473/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 5.8 Medium  
Affected: Arista  
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.  
What to do: ** Monitor Arista's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-48027/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-48027/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.8 Critical  
Affected: Nx  
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.  
What to do: ** Monitor Nx's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Web Runtime Security Component Allows Unauthenticated HTTP Attackers to Compromise the Application, With High Impact on Confidentiality, Integrity, and Availability</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46912/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46912/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.3 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated HTTP Attackers to Read and Write Data in a Way That Affects Confidentiality and Integrity</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-46910/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-46910/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: Oracle  
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).  Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H). (NVD)  
What to do: ** Monitor Oracle's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-45321/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-45321/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 9.6 Critical  
Affected: TanStack  
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.  
What to do: ** Monitor TanStack's web page for any future patch releases.</description>
    </item>
    <item>
      <title>ai-scanner 1.0.0 Through 1.4.0 Remote Code Execution via JavaScript Injection in BrowserAutomation PlaywrightService, Reachable Without Authentication</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-41512/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-41512/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.9 Critical  
Affected: mozilla  
ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerability via JavaScript injection in `BrowserAutomation::PlaywrightService`. This issue has been patched in version 1.4.1. (NVD)  
What to do: ** Monitor mozilla's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>ChurchCRM Before 6.5.3 Backup Restore Functionality Allows Authenticated Administrators to Upload Files to Arbitrary Paths via Path Traversal, Enabling Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-35573/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-35573/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.1 Critical  
Affected: churchcrm  
ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. The vulnerability exists in src/ChurchCRM/Backup/RestoreJob.php. The $rawUploadedFile['name'] parameter is user-controlled and allows uploading files with arbitrary names to /var/www/html/tmp_attach/ChurchCRMBackups/. This vulnerability is fixed in 6.5.3. (NVD)  
What to do: ** Monitor churchcrm's web page for any future patch releases.</description>
    </item>
    <item>
      <title>Intel Data Center Graphics Driver for VMware ESXi Before 2.0.2 Ring 1 Device Driver Buffer Overflow Allows a Privileged System Software Adversary to Escalate Privileges and Execute Code Locally</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20794/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20794/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.3 Critical  
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (high) impacts. (NVD)</description>
    </item>
    <item>
      <title>Cisco Webex SSO Integration with Control Hub Performed Improper Certificate Validation, Allowing Unauthenticated Attackers to Impersonate Any User Within the Service Prior to Patching</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20184/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20184/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service.</description>
    </item>
    <item>
      <title>Cisco Integrated Management Controller Change Password Handler Incorrectly Processes Password Change Requests, Letting Unauthenticated Remote Attackers Bypass Authentication and Gain Admin Access</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-20093/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-20093/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[New]  
CVSS 9.8 Critical  
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as&amp;nbsp;Admin.</description>
    </item>
    <item>
      <title>Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-1952/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-1952/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: deltaww  
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.  
What to do: ** Monitor deltaww's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-1951/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-1951/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: deltaww  
Delta Electronics AS320T has no checking of the length of the buffer with the directory name  
What to do: ** Monitor deltaww's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-1950/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-1950/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: deltaww  
Delta Electronics AS320T has  
What to do: ** Monitor deltaww's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service</title>
      <link>https://ot-advisories.com/advisories/CVE-2026-1949/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2026-1949/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: deltaww  
Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.  
What to do: ** Monitor deltaww's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Samsung Exynos Modem SMS Processing Out-of-Bounds Write Due to TP-UDHI Header Mismatch, Affecting Processors from Exynos 980 Through Exynos 2500 and Multiple Modem Generations</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-62818/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-62818/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Samsung  
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. An out-of-bounds write occurs due to a mismatch between the TP-UDHI and UDL values when processing an SMS TP-UD packet. (NVD)  
What to do: ** Monitor Samsung's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Samsung Exynos Wi-Fi Driver NL80211 Vendor Command Handler Overflows a Buffer via a Crafted Packet, Affecting Exynos 980 Through W1000 Mobile and Wearable Processors</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-52909/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-52909/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Samsung  
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 vendor command leads to a buffer overflow via a certain ioctl message, issue 2 of 2. (NVD)  
What to do: ** Monitor Samsung's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Samsung Exynos Wi-Fi Driver NL80211 Vendor Command Handler Contains a Second Buffer Overflow Path via a Crafted Packet, Affecting Exynos 980 Through W1000 Mobile and Wearable Processors</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-52908/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-52908/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[Updated]  
CVSS 9.8 Critical  
Affected: Samsung  
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 vendor command leads to a buffer overflow via a certain ioctl message, issue 1 of 2. (NVD)  
What to do: ** Monitor Samsung's web page for any future patch releases. See vendor advisory link below.</description>
    </item>
    <item>
      <title>Quest KACE Systems Management Appliance's Improper Authentication Allows Attackers to Impersonate Legitimate Users Without Valid Credentials; CISA's May 4th KEV Deadline Has Passed</title>
      <link>https://ot-advisories.com/advisories/CVE-2025-32975/</link>
      <guid isPermaLink="true">https://ot-advisories.com/advisories/CVE-2025-32975/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <description>[KEV]  
CVSS 10.0 Critical  
Affected: Quest  
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.  
What to do: ** Monitor Quest's web page for any future patch releases.</description>
    </item>
  </channel>
</rss>
