SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsISC provides a free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back against the most malicious attackers. https://isc.sans.edu/about.html
September 2026 Microsoft Patch Tuesday
Published: 2026-09-08
Last Updated: 2026-09-08 19:20:30 UTC
by Johannes Ullrich (Version: 1)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
A few vulnerabilities worth mentioning:
Windows Update Stack Elevation of Privilege Vulnerability (CVE-2026-81963)
Microsoft reports that CVE-2026-81963 is being exploited, though it was not publicly disclosed before Patch Tuesday. This Important-severity Windows Update Stack elevation of privilege vulnerability has a CVSS score of 7.8 and affects Windows 11 and Windows Server 2025 systems. The flaw involves improper link resolution before file access, allowing a local, authenticated attacker with low privileges to abuse link-following behavior and elevate to SYSTEM privileges. Administrators should prioritize applying the Windows security updates for affected Windows 11 and Windows Server 2025 systems, including Server Core installations.
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability (CVE-2026-85880)
Microsoft lists CVE-2026-85880 as exploited in the wild, although it was not publicly disclosed before Patch Tuesday and is not currently in CISA’s Known Exploited Vulnerabilities catalogue. This Important-severity Windows ALPC elevation of privilege vulnerability has a CVSS score of 7.8 and affects Windows 10 and multiple Windows Server releases, including Server 2012, 2016, 2019, and 2022. The flaw is a heap-based buffer overflow that can be exploited locally by an attacker who can run code in a low-privilege AppContainer; no user interaction is required. Successful exploitation allows the attacker to escape the sandbox and gain SYSTEM privileges on the affected host. Given Microsoft’s exploited-in-the-wild assessment, prioritize deployment of the applicable Windows security updates, especially on multi-user systems, exposed workstations, and servers where local code execution paths are available.
Skype for Business Remote Code Execution Vulnerability (CVE-2026-66302)
Microsoft reports that CVE-2026-66302 is not being exploited in the wild and was not publicly disclosed before Patch Tuesday. This is a Critical remote code execution vulnerability in Skype for Business Server with a CVSS score of 9.8, affecting Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1. The flaw involves external control of a file name or path, allowing an unauthenticated attacker to send a specially crafted network request that writes an attacker-controlled file to an arbitrary location on the affected server; successful exploitation could allow code execution on the target server without authentication or user interaction. Administrators should prioritize applying Microsoft’s updates for affected Skype for Business Server installations and review exposed deployments, logging, and access controls for signs of suspicious file writes or unexpected server-side code execution.
Windows Message Queuing Remote Code Execution Vulnerability (CVE-2026-69579)
Microsoft reports that CVE-2026-69579 is not known to be exploited in the wild and was not publicly disclosed before Patch Tuesday. This Critical remote code execution vulnerability carries a CVSS score of 9.8 and is a use-after-free flaw in Windows Message Queuing affecting supported Windows client and server releases. An unauthenticated attacker could exploit it remotely by sending a specially crafted packet to an affected Message Queuing service, with no user interaction required, potentially allowing code execution on the target system with high impact to confidentiality, integrity, and availability. Systems running MSMQ should be prioritized for patching; where Message Queuing is not needed, disabling the service or restricting network access to it, including limiting exposure of MSMQ traffic such as TCP port 1801, can reduce risk until updates are applied.
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVE-2026-69590)
CVE-2026-69590 is not listed by Microsoft as exploited in the wild and has not been publicly disclosed; it is a Critical remote code execution vulnerability in Windows RRAS with a CVSS score of 9.8. An unauthenticated remote attacker could exploit the flaw by sending a specially crafted packet to an affected RRAS service over the network, with no user interaction required, potentially allowing code execution on the target system with serious confidentiality, integrity, and availability impact. Affected platforms include supported Windows 10, Windows 11, and Windows Server releases. Organizations should apply the Microsoft security update promptly, especially on systems running RRAS, and reduce exposure by disabling RRAS where it is not needed, restricting network access to the service with firewalls or VPN controls, and monitoring for unexpected traffic to RRAS-enabled hosts.
This was a summary of Microsoft’s monthly updates highlighting key vulnerabilities. Prioritize the exploited Important Windows EOP flaws, CVE-2026-81963 and CVE-2026-85880, then patch exposed Skype for Business, MSMQ, and RRAS systems vulnerable to Critical unauthenticated RCE.
A detailed list of this month's vulnerabilities follows below. To search and filter them, visit my dashboard: https://patchlens.io
Read the full entry: https://isc.sans.edu/diary/September+2026+Microsoft+Patch+Tuesday/33320/
Critical MikroTik Vulnerability - Patch Now
Published: 2026-09-06
Last Updated: 2026-09-06 21:43:17 UTC
by Johannes Ullrich (Version: 1)
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.
The patch will attempt to detect compromise and set the "Flagged" status.
Details: https://mikrotik.com/supportsec/september-2026-vulnerability
Read the full entry: https://isc.sans.edu/diary/Critical+MikroTik+Vulnerability+Patch+Now/33314/
numbat - AI agent observability
Published: 2026-09-04
Last Updated: 2026-09-05 03:39:52 UTC
by Russ McRee (Version: 1)
Enterprises face an unmanaged crisis of AI agent and MCP server sprawl, characterized by rapid, decentralized proliferation of autonomous agents, protocol connections operating with excessive privilege, opaque execution paths, and identity blind spots.
Absent agent-aware governance, modern enterprises struggle to prevent, detect, or contain multi-hop autonomous exploits, leaving environments vulnerable to lateral movement, shadow collaboration, and unauthorized data exfiltration.
More succinctly, in light of the recent OpenAI/Hugging Face incident, monitoring clearly lags behind agent capability. The tooling to observe what agents are actually doing, in real time, is not yet standard practice, even at the labs building the agents.
To that end, Perplexity AI’s open source numbat offers excellent observability and visibility to supported desktop, CLI, IDE, and gateway agents through local hooks and plugins, OTLP/HTTP logs, and on-disk session artifacts ...
Read the full entry: https://isc.sans.edu/diary/numbat+AI+agent+observability/33312/
Scans for Proxmox Servers (2026.09.09)
https://isc.sans.edu/diary/Scans+for+Proxmox+Servers/33324/
Honeypot-Omaha and batch.py [Guest Diary] (2026.09.02)
https://isc.sans.edu/diary/HoneypotOmaha+and+batchpy+Guest+Diary/33306/
The list is assembled by pulling recent vulnerabilities from NIST NVD, Microsoft, Twitter mentions of vulnerabilities, ISC Diaries and Podcast, and the CISA list of known exploited vulnerabilities. There are also some unscored, but significant, vulnerabilities at the end. This includes vulnerabilities that have not been added to the NVD yet.
CVE-2026-81963 - Windows Update Stack Elevation of Privilege Vulnerability
Product: Microsoft Windows Update Stack
CVSS Score: 7.8
** KEV since 2026-09-08 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-81963
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81963
CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Product: Microsoft Windows
CVSS Score: 7.8
** KEV since 2026-09-08 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85880
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85880
CVE-2026-83548 - SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Product: SonicWall SMA1000
CVSS Score: 10.0
** KEV since 2026-09-02 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-83548
NVD References: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548
CVE-2026-83549 - SonicWall SMA1000 Appliances OS Command Injection Vulnerability
Product: SonicWall SMA1000
CVSS Score: 7.8
** KEV since 2026-09-02 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-83549
NVD References: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83549
CVE-2026-78327, CVE-2026-78328, CVE-2026-81939 - Multiple vulnerabilities in SonicWall Network Security Manager (NSM) On-Prem
Product: SonicWall Network Security Manager (NSM) On-Prem
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-78327 (OS Command Injection)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-78328 (missing authorization)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-81939 (Zip Slip)
NVD References: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0015
CVE-2026-86218 - N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Product: N-Able N-Central
CVSS Score: 9.8
** KEV since 2026-09-08 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86218
NVD References: https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86218
CVE-2026-9586 - Sangoma Switchvox SQL Injection Vulnerability
Product: Sangoma Switchvox
CVSS Score: 0
** KEV since 2026-09-02 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9586
ISC Podcast: https://isc.sans.edu/podcastdetail/10082
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9586
CVE-2026-85046 - Google Chromium V8 Type Confusion Vulnerability
Product: Google Chrome
CVSS Score: 8.8
** KEV since 2026-09-04 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85046
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046
CVE-2026-75650 - Adobe Commerce is vulnerable to an arbitrary code execution flaw that could be exploited by an attacker without user interaction, allowing for potential code execution in the current user's context.
Product: Adobe Commerce
CVSS Score: 0
** KEV since 2026-09-08 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-75650
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650
CVE-2026-49869 - Kestra OSS OS Command Injection Vulnerability
Product: Kestra
CVSS Score: 0
** KEV since 2026-09-02 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-49869
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-49869
CVE-2026-82329 - JFrog Artifactory Improper Authentication Vulnerability
Product: Jfrog Artifactory
CVSS Score: 0
** KEV since 2026-09-02 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-82329
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82329
CVE-2026-59822 - BerriAI LiteLLM Improper Authentication Vulnerability
Product: LiteLLM
CVSS Score: 0
** KEV since 2026-09-02 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-59822
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59822
CVE-2026-66302 - Skype for Business Remote Code Execution Vulnerability
Product: Microsoft Skype for Business
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-66302
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66302
CVE-2026-69579 - Windows Message Queuing Remote Code Execution Vulnerability
Product: Microsoft Windows Message Queuing
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-69579
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69579
CVE-2026-69590 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Product: Microsoft Windows Routing and Remote Access Service (RRAS)
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-69590
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69590
CVE-2026-85504, CVE-2026-85506 through CVE-2026-85509 - Stack-based buffer overflow vulnerabilities in FreeIPMI before 1.6.19
Product: FreeIPMI
CVSS Score: 9.8
MSFT Details:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85504
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85506
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85507
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85508
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85509
CVE-2026-34182 - CMS AuthEnvelopedData Processing May Accept Forged Messages
Product: CMS AuthEnvelopedData
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-34182
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34182
CVE-2026-72649 - Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
Product: Elastic Elasticsearch 9.5.0
CVSS Score: 8.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-72649
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72649
NVD References: https://discuss.elastic.co/t/elasticsearch-8-19-20-9-4-5-9-5-1-security-update-esa-2026-114/390087
CVE-2026-84838 - Rpm: command injection in rpmuncompress via unescaped filenames passed to popen()
Product: Red Hat rpmuncompress
CVSS Score: 7.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84838
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84838
NVD References: https://access.redhat.com/security/cve/CVE-2026-84838
NVD References: https://bugzilla.redhat.com/show_bug.cgi?id=2462222
CVE-2026-73701, CVE-2026-19766, CVE-2026-73700, CVE-2026-76657, CVE-2026-76658 - Multiple vulnerabilities in HPE Networking Fabric Composer
Product: HPE Aruba Networking Fabric Composer
CVSS Scores: 9.0 - 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-73701 (unauthenticated remote code execution)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19766 (authentication bypass)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-73700 (authenticated stored cross-site scripting)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76657 (authentication bypass)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76658 (unauthenticated remote code execution)
NVD References: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US
CVE-2026-73749 - AOS-CX daemon is vulnerable to remote code execution due to improper handling of malformed input, allowing unauthenticated attackers to exploit the issue with specially crafted packets.
Product: HPE Aruba Networking ArubaOS-CX (AOS-CX)
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-73749
NVD References: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US
CVE-2026-20212 - Cisco Nexus 9000 Series Switches are vulnerable to an unauthenticated, remote code execution exploit that could grant root privileges to the attacker.
Product: Cisco Nexus 9000 Series Switches
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-20212
NVD References: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
CVE-2026-20274, CVE-2026-20279 - Vulnerabilities in Cisco IOS XR Software
Product: Cisco IOS XR Software
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-20274 (improper control of a resource through its lifetime)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-20279 (improper access control)
NVD References: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
CVE-2026-18658 - IBM Operational Decision Manager versions 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is susceptible to SQL injection, allowing unauthenticated attackers to execute malicious SQL commands and potentially achieve remote code execution by creating a web shell in the application web root.
Product: IBM Operational Decision Manager
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18658
NVD References: https://www.ibm.com/support/pages/node/7286196
CVE-2026-19274 - IBM Observability with Instana vulnerability allows authenticated Kubernetes tenants to hijack or destroy another tenant's cluster-level RBAC permissions.
Product: IBM Observability With Instana Agent
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19274
NVD References: https://www.ibm.com/support/pages/node/7286070
CVE-2026-58400 - GeoNetwork allows arbitrary command execution due to insecure Saxon XSLT processor configurations in versions prior to 4.4.12 and 4.2.17.
Product: GeoNetwork Saxon XSLT Processor
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58400
NVD References:
- https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-x898-729x-cc3r
- https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html
CVE-2026-75604 - Next.js is a React framework that allows for building full-stack web applications, but versions from 13.4.0 to 15.5.24 and 16.3.3 on Windows servers can expose private build data and encryption keys, leading to potential remote code execution.
Product: Next.js
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-75604
NVD References: https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36
CVE-2026-66786 - Submariner allows for remote code execution as root on the gateway node due to improper validation in cert-auth mode.
Product: Submariner
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-66786
CVE-2026-85672 - Zerox 1.1.20 is vulnerable to OS command injection through malicious file extensions in document URLs, allowing attackers to execute arbitrary commands during document processing.
Product: Zerox 1.1.20
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85672
NVD References: https://github.com/getomni-ai/zerox/issues/206
CVE-2026-85684 - Marker through 2.0.0 has a path traversal vulnerability in the /marker/upload handler, allowing unauthenticated attackers to write or delete files from any location on the system by manipulating the file.filename parameter.
Product: Marker through 2.0.0
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85684
NVD References: https://github.com/datalab-to/marker/issues/1047
CVE-2026-85696 - SadTalker is vulnerable to OS command injection during video muxing, allowing attackers to execute arbitrary system commands by uploading audio filenames with shell metacharacters.
Product: SadTalker
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85696
NVD References: https://github.com/OpenTalker/SadTalker/issues/1043
CVE-2026-44402 - Voltronic Power SNMP Web Pro 1.1 has a remote code execution vulnerability enabling attackers to execute commands as root by uploading a crafted tar archive.
Product: Voltronic Power SNMP Web Pro 1.1
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44402
NVD References: https://www.vulncheck.com/advisories/voltronic-power-snmp-web-pro-unauthenticated-rce-via-upload-cgi
CVE-2026-86121 - Cua computer-server versions before 0.3.42 are vulnerable to unauthenticated attackers executing arbitrary commands through TCP port 8000.
Product: Cua computer-server
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86121
NVD References: https://github.com/trycua/cua/issues/1892
CVE-2026-86124 - AutoAgent is vulnerable to unauthenticated remote code execution through the TCP server, allowing attackers to execute commands as root and gain access to host directories.
Product: AutoAgent
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86124
NVD References: https://github.com/HKUDS/AutoAgent/issues/96
CVE-2026-84200 - Kyverno versions v1.9.0 through v1.12.7 have a policy exception handling flaw that allows attackers to bypass policies by exploiting less restrictive exceptions, fixed in v1.13.0.
Product: Kyverno
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84200
NVD References: https://github.com/kyverno/kyverno/security/advisories/GHSA-gg4x-fgg2-h9w9
CVE-2026-79687 - Dell PowerStore SDNAS is vulnerable to Missing Authentication for Critical Function, which can allow remote attackers to gain filesystem access.
Product: Dell PowerStore SDNAS
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-79687
NVD References: https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities
CVE-2026-19593 - OpenAI Codex Desktop for Windows and macOS allows attackers to run malicious programs with the signed-in user's privileges by exploiting Git metadata and workspace settings.
Product: OpenAI Codex Desktop
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19593
CVE-2023-54391 - Proxmox Virtual Environment (VE) 7.0 through 8.0 is vulnerable to an authentication bypass flaw in libpve-access-control, allowing unauthenticated attackers to masquerade as any enabled user without a configured second factor by supplying a specific value in the API login endpoint.
Product: Proxmox Virtual Environment (VE)
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2023-54391
NVD References: https://www.vulncheck.com/advisories/proxmox-ve-authentication-bypass-via-tfa-challenge-parameter
CVE-2026-84372 - Predis versions from 3.0.0-RC1 to 3.3.0 allow attacker-controlled keys or values to be interpreted as additional commands due to a vulnerability in pipeline handling.
Product: Predis Redis and Valkey Client
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84372
NVD References: https://github.com/predis/predis/security/advisories/GHSA-w6f5-v2h6-g786
CVE-2026-84699 - Team Password Manager before version 14.184.308 allows unauthenticated attackers to reset local account passwords and gain unauthorized access.
Product: Team Password Manager
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84699
CVE-2026-84795 - Craft CMS before 5.10.11 has an admin flag validation vulnerability during user registration, enabling attackers to inherit administrator privileges by registering with a deactivated admin's email address when public registration and disabled email verification are set up.
Product: Craft CMS
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84795
NVD References: https://github.com/craftcms/cms/security/advisories/GHSA-242m-9wq7-vhwq
CVE-2026-73475 - Drupal Commerce PayPal has an Incorrect Authorization vulnerability that enables Forceful Browsing on versions ranging from 0.0.0 to 1.12.0, and from 2.0.0 to 2.1.3.
Product: Drupal Commerce PayPal
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-73475
NVD References: https://www.drupal.org/sa-contrib-2026-095
CVE-2026-85181 - CAT vulnerably uses Java String.hashCode as the only integrity check for session cookies, enabling attackers to forge valid checksums and create admin sessions with full access.
Product: CAT Java String
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85181
NVD References: https://github.com/dianping/cat/issues/2384
CVE-2026-85183 - Taipy configures its socket.io server in a vulnerable way, enabling attackers to establish credentialed WebSocket connections and manipulate state variables without CSRF protection.
Product: Taipy
CVSS Score: 9.3
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85183
NVD References: https://github.com/Avaiga/taipy/issues/2890
CVE-2026-85394 - Python-jose through 3.5.0 overlooks validating asymmetric keys in HMAC initialization, allowing attackers with the service's public key to craft HS256 tokens that pass verification.
Product: Python-jose through 3.5.0
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85394
NVD References: https://github.com/mpdavis/python-jose/issues/414
CVE-2026-80181 - Apache Allura is vulnerable to SSRF through version 1.20.0, and users should upgrade to 1.21.0 for a fix.
Product: Apache Allura
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-80181
NVD References: https://lists.apache.org/thread/v4nplqchsmdg9sdhp91f8hn03rlq8y7s
CVE-2026-85085 - Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView, potentially enabling a threat actor to communicate with Canva using the user's session.
Product: Canva Android App
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85085
CVE-2026-85661 - excel-mcp-server 0.1.8 allows attackers to read and write arbitrary files by overriding path confinement in stdio mode when EXCEL_FILES_PATH is not set.
Product: excel-mcp-server 0.1.8
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85661
NVD References: https://github.com/haris-musa/excel-mcp-server/issues/149
CVE-2026-85663 - Aim 3.29.1 remote tracking server allows unauthenticated attackers to manipulate data and delete runs by failing to authenticate requests and validate method invocations.
Product: Aim 3.29.1
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85663
NVD References: https://github.com/aimhubio/aim/issues/3412
CVE-2026-85667 - Xiaobei through 5.5.2 allows unauthenticated attackers to inject arbitrary messages into the agent pipeline by failing to implement authentication on webhook endpoints.
Product: Xiaobei 5.5.2
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85667
NVD References: https://github.com/TeamWiseFlow/xiaobei/issues/440
CVE-2026-85688 - TEN Framework 0.11.71 allows attackers to read or write arbitrary files and execute malicious code through unauthenticated API endpoints.
Product: TEN Framework
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85688
NVD References: https://github.com/TEN-framework/ten-framework/issues/2187
CVE-2026-85695 - FastChat has an authentication bypass vulnerability in the /register_worker endpoint, enabling unauthenticated attackers to perform server-side request forgery by registering arbitrary worker addresses.
Product: FastChat
CVSS Score: 9.4
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85695
NVD References: https://github.com/lm-sys/FastChat/issues/3886
CVE-2026-84119, CVE-2026-84121, CVE-2026-84129, CVE-2026-84133, CVE-2026-84134, CVE-2026-84135, CVE-2026-84140 through CVE-2026-84143, CVE-2026-84637, CVE-2026-84639 - Multiple vulnerabilities in Mozilla Firefox, Thunderbird, and their ESR versions
Product: Mozilla Firefox, Thunderbird, and their ESR versions
CVSS Scores: 9.1 - 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84119
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84121
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84129
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84133
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84134
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84135
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84140
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84141
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84142
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84143
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84637
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84639
NVD References:
- https://www.mozilla.org/security/advisories/mfsa2026-82/
- https://www.mozilla.org/security/advisories/mfsa2026-83/
- https://www.mozilla.org/security/advisories/mfsa2026-84/
- https://www.mozilla.org/security/advisories/mfsa2026-85/
- https://www.mozilla.org/security/advisories/mfsa2026-86/
- https://www.mozilla.org/security/advisories/mfsa2026-87/
- https://www.mozilla.org/security/advisories/mfsa2026-88/
CVE-2026-84333 - Google Chrome on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Product: Google Chrome on Android
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84333
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
CVE-2026-84352 - Google Chrome on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Product: Google Chrome on Android
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84352
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
CVE-2026-85042 - Google Chrome's vulnerability in DevTools before version 152.0.7977.82 allowed remote attackers to run code outside the sandbox using a malicious HTML page.
Product: Google Chrome
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85042
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
CVE-2026-85043 - Google Chrome prior to 152.0.7977.82 allowed remote attackers to bypass system access restrictions by not fully cleaning up the network, posing a high security risk.
Product: Google Chrome
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85043
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
CVE-2026-85047 - Google Chrome on iOS version prior to 152.0.7977.82 is vulnerable to arbitrary code execution via a crafted HTML page due to improper input validation in Transactions Platform.
Product: Google Chrome on iOS
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85047
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
CVE-2026-85050 - Google Chrome on Android prior to version 152.0.7977.82 allowed remote attackers to execute arbitrary code through WebGL, posing a high security risk.
Product: Google Chrome on Android
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85050
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
CVE-2026-85424 - MOOS core-moos through 10.4.0 allows unauthenticated clients to connect with full privileges, leading to potential data loss and unauthorized access.
Product: MOOS core-moos
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85424
NVD References: https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-missing-authentication-for-moosdb-publish-subscribe-and-db-clear
CVE-2026-85425 - MOOS-IvP iSay through 24.8.1 allows remote code execution via unsanitized text in the SAY_MOOS variable handler.
Product: MOOS-IvP iSay
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85425
NVD References: https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-isay-command-injection-via-say-moos
CVE-2026-85426 - MOOS-IvP uMemWatch through 24.8.1 allows attackers to execute arbitrary commands by injecting shell metacharacters into client names.
Product: MOOS-IvP uMemWatch
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85426
NVD References: https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-umemwatch-command-injection-via-moos-client-names
CVE-2026-85428 - MOOS core-moos through 10.4.0 allows unauthenticated clients to modify variables in the MOOSDB HTTP server without authentication.
Product: MOOS core-moos through 10.4.0
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85428
NVD References: https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-http-server-unauthenticated-variable-write
CVE-2026-85430 - MOOS essential-moos through 10.0.1 has an authentication bypass vulnerability in pShare that allows attackers to inject messages with spoofed identities or crash the process by sending crafted UDP datagrams.
Product: MOOS essential-moos
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85430
NVD References: https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pshare-unauthenticated-udp-datagram-republishing
CVE-2026-85437 - MOOS-IvP through 24.8.1 contains buffer overflow vulnerabilities in string decoders, allowing remote code execution via crafted encoded strings.
Product: MOOS-IvP
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85437
NVD References: https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-buffer-overflow-in-ivp-function-string-decoders
CVE-2026-85440 - MOOS core-moos through 10.4.0 is vulnerable to a pre-authentication heap overflow that allows remote attackers to write arbitrary data by manipulating packet length declarations.
Product: MOOS core-moos
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85440
NVD References: https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-pre-authentication-heap-overflow-via-negative-packet-length
CVE-2026-85433 - MOOS essential-moos pShare through 10.0.1 allows attackers to reconfigure network routes by sending unauthorized PSHARE_CMD messages.
Product: MOOS essential-moos pShare
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85433
NVD References: https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pshare-unauthorized-runtime-route-reconfiguration
CVE-2026-85434 - MOOS-IvP uFldShoreBroker allows attackers to redirect bridged variables by sending crafted NODE_BROKER_PING messages.
Product: MOOS-IvP uFldShoreBroker
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85434
NVD References: https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-ufldshorebroker-bridge-route-injection-via-unverified-node-ping
CVE-2026-85435 - MOOS-IvP uFldNodeBroker fails to authenticate TRY_SHORE_HOST messages on the vehicle bus, enabling attackers to enroll and manipulate shore routes.
Product: MOOS-IvP uFldNodeBroker
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85435
NVD References: https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-ufldnodebroker-unauthenticated-shore-route-enrollment
CVE-2026-85438 - MOOS-IvP through 24.8.1 is vulnerable to a buffer overflow in StringToIvPFunction() that allows attackers to execute code by supplying crafted BHV_IPF payloads with mismatched dimension values.
Product: MOOS-IvP IvP through 24.8.1
CVSS Score: 9.8
GitHub Stars: 90
Exploitability: 0 %
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85438
NVD References: https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-out-of-bounds-write-via-unvalidated-ivp-payload-counts
**NO CUSTOMER ACTION REQUIRED**
CVE-2026-62916 - Microsoft Entra ID Elevation of Privilege Vulnerability
Product: Microsoft Entra ID
CVSS Score: 9.1
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-62916
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62916
CVE-2026-70352 - Azure AI Language Elevation of Privilege Vulnerability
Product: Microsoft Azure AI Language
CVSS Score: 10.0
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-70352
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70352
CVE-2026-83711 - Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
Product: Microsoft Azure Active Directory B2C
CVSS Score: 10.0
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-83711
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83711
CVE-2026-80098 - Copilot Studio Elevation of Privilege Vulnerability
Product: Microsoft Copilot Studio
CVSS Score: 9.3
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-80098
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80098
CVE-2026-62906 - Microsoft Discovery Studio Information Disclosure Vulnerability
Product: Microsoft Discovery Studio
CVSS Score: 7.4
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-62906
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62906
CVE-2026-65818 - Power Automate Elevation of Privilege Vulnerability
Product: Microsoft Power Platform
CVSS Score: 8.5
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-65818
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65818
CVE-2026-69857 - Azure Cosmos DB Spoofing Vulnerability
Product: Microsoft Azure Cosmos DB
CVSS Score: 8.5
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-69857
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69857
CVE-2026-70178 - Microsoft Fabric Elevation of Privilege Vulnerability
Product: Microsoft Fabric
CVSS Score: 8.5
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-70178
ISC Diary: https://isc.sans.edu/diary/33320
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70178
The State of Cloud Risk 2026 is a Wiz Research report based on telemetry from real enterprise cloud environments, including over 50% of the Fortune 100. It shows where exploitable risk concentrates in practice. Readers get evidence on context-driven prioritization, exposure-led attack paths, and a 13-tier model built for action. Get the report for the data, benchmarks, and defense strategies security teams can put to work immediately.
Webinar | SANS 2026 Exposure Management Survey Insights: Cyber Exposure at a Crossroads | Wednesday, October 7 | Jonathan Risto
Webinar | DFIR Solutions Track | Thursday, October 15 | Operationalize advanced DFIR tooling, cloud-native investigation techniques, and automation-driven triage.
Webinar | Ransomware Solutions Track | Friday, October 16 | Learn practical strategies for ransomware detection, containment, identity protection, and resilient recovery.