SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsISC provides a free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back against the most malicious attackers. https://isc.sans.edu/about.html
Apple Updates Everything
Published: 2026-09-14
Last Updated: 2026-09-14 18:33:44 UTC
by Johannes Ullrich (Version: 1)
Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases.
In addition to the major "27" version, Apple also released bug-fix-only releases for the 26 branch of its operating systems and for 15 (Sequoia) for macOS. None of the vulnerabilities is labeled as being exploited. Apple does not note a severity to individual vulnerabilities.
There are some reports about difficulties downloading iOS 27. Users instead see 26.7 downloaded, but iOS 27 may actually be installed. Also note that some security-relevant applications, such as Little Snitch, have recently released updates that must be applied before upgrading to macOS 27. The Objective-See utility BlockBlock released version 2.5.2 to improve macOS 27 compatibility ...
Read the full entry: https://isc.sans.edu/diary/Apple+Updates+Everything/33336/
The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access
Published: 2026-09-11
Last Updated: 2026-09-11 14:40:32 UTC
by Renato Marinho (Version: 1)
I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.
What I captured was not simply credential theft, but an inference supply chain — an agent harvesting, validating, and consolidating LLM access into infrastructure that serves it again through a unified API, which I watched come online.
None of the individual techniques is particularly novel. What is different is the feedback loop: the agent helps acquire new inference capacity, validates and consolidates it, and makes that capacity available to support further operations. The result is a partially self-expanding inference supply chain.
I reconstructed the operation across a series of captures from one of my AI honeypots, which the agent repeatedly selected as a free LLM backend.
The Capture
The honeypot emulates an OpenAI-compatible inference endpoint. When the operator's coding agent attempted to use it, the request exposed much more than an exploit payload.
Because this particular client embedded its operating instructions and session context in model requests, the honeypot received approximately 43 KB of material: a large AGENTS[.]md, an offensive playbook, infrastructure notes, reconnaissance scripts, collected API keys, previous targets, and parts of the agent's working history.
In effect, the agent sent me part of its own control plane.
One instruction even had the agent verify its proxy was active before attacking, and that step exposed the operator's direct, unproxied egress IP: the playbook itself contained that IP as a reference value for the agent to compare against the proxied connection.
The Operation
The captured workflow was straightforward ...
Read the full entry: https://isc.sans.edu/diary/The+SelfExpanding+Stolen+Inference+Supply+Chain+An+AI+Agent+Harvesting+and+ReServing+LLM+Access/33332/
MacOS 27 - First Boot
Published: 2026-09-15
Last Updated: 2026-09-15 15:23:45 UTC
by Johannes Ullrich (Version: 1)
I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:
I captured about 300 packets. This was likely inflated for this particular system as it connected via Wi-Fi and wired network interfaces. Each network interface will do its own DHCP/IP discovery during boot. I only used router advertisements for IPv6, not DHCPv6.
IPv6 Neighbor Discovery - Duplicate Address Discovery
As it is supposed to, macOS 27 does standard compliant duplicate address discovery before accepting an IPv6 address. It does use ICMPv6 nonces to prevent some spoofing DoS attacks ...
Read the full entry: https://isc.sans.edu/diary/MacOS+27+First+Boot/33340/
Redtail Payload Analysis [Guest Diary] (2026.09.09)
https://isc.sans.edu/diary/Redtail+Payload+Analysis+Guest+Diary/33326/
Scans for Proxmox Servers (2026.09.09)
The list is assembled by pulling recent vulnerabilities from NIST NVD, Microsoft, Twitter mentions of vulnerabilities, ISC Diaries and Podcast, and the CISA list of known exploited vulnerabilities. There are also some unscored, but significant, vulnerabilities at the end. This includes vulnerabilities that have not been added to the NVD yet.
CVE-2026-84869 - ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Product: ConnectWise ScreenConnect
CVSS Score: 9.9
** KEV since 2026-09-11 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84869
NVD References:
- https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869
- https://www.connectwise.com/company/trust/advisories
- https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869
CVE-2026-76461 - Cisco Secure Email Gateway SQL Injection Vulnerability
Product: Cisco AsyncOS
CVSS Score: 0
** KEV since 2026-09-14 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76461
ISC Podcast: https://isc.sans.edu/podcastdetail/10096
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461
CVE-2026-81963 - Windows Update Stack Elevation of Privilege Vulnerability
Product: Microsoft Windows Update Stack
CVSS Score: 7.8
** KEV since 2026-09-08 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-81963
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81963
CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Product: Microsoft Windows
CVSS Score: 7.8
** KEV since 2026-09-08 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85880
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85880
CVE-2026-87491 - Chromium CVE-2026-87491: Out of bounds write in V8
Product: Google Chromium V8
CVSS Score: 0
** KEV since 2026-09-09 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87491
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87491
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87491
CVE-2026-85046 - Chromium: CVE-2026-85046 Type confusion in V8
Product: Google Chromium V8
CVSS Score: 0
** KEV since 2026-09-04 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85046
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85046
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046
CVE-2026-65400 - Apple macOS Improper Authentication Vulnerability
Product: Apple macOS
CVSS Score: 0
** KEV since 2026-08-18 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-65400
ISC Diary: https://isc.sans.edu/diary/33336
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400
CVE-2026-85706 - GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Product: GitLab Community Edition and Enterprise Edition
CVSS Score: 0
** KEV since 2026-09-11 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85706
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706
CVE-2026-75650 - Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Product: Adobe Commerce and Magento
CVSS Score: 0
** KEV since 2026-09-08 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-75650
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650
CVE-2026-58704 - Google Pixel Cellular Modem is vulnerable to a permission bypass through a logic error, allowing for remote privilege escalation without user interaction.
Product: Google Pixel Cellular Modem
CVSS Score: 0
** KEV since 2026-09-16 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58704
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58704
CVE-2026-42016 - JFrog Artifactory Incorrect Authorization Vulnerability
Product: JFrog Artifactory
CVSS Score: 0
** KEV since 2026-09-11 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42016
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016
CVE-2026-42018 - JFrog Artifactory Improper Authentication Vulnerability
Product: JFrog Artifactory
CVSS Score: 0
** KEV since 2026-09-11 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42018
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018
CVE-2026-86060 - MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Product: MikroTik RouterOS
CVSS Score: 0
** KEV since 2026-09-10 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86060
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060
CVE-2026-67277 - MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
Product: MikroTik RouterOS
CVSS Score: 0
** KEV since 2026-09-10 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-67277
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67277
CVE-2026-19490 - Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Product: Citrix NetScaler
CVSS Score: 0
** KEV since 2026-09-09 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19490
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-19490
CVE-2026-86218 - N-able N-central Static Code Injection Vulnerability
Product: N-Able N-Central
CVSS Score: 0
** KEV since 2026-09-08 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86218
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86218
CVE-2026-82078 - PaperCut NG/MF Unsafe Reflection Vulnerability
Product: PaperCut NG/MF
CVSS Score: 0
** KEV since 2026-08-31 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-82078
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078
CVE-2026-81578 - PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
Product: PaperCut NG/MF
CVSS Score: 0
** KEV since 2026-08-31 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-81578
CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578
CVE-2026-65669 - Microsoft SQL Server Elevation of Privilege Vulnerability
Product: Microsoft SQL Server
CVSS Score: 9.6
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65669
CVE-2026-68839 - Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability
Product: Microsoft Windows USB Mass Storage Class Driver
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68839
CVE-2026-69276 - Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability
Product: Microsoft UxTheme Library
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69276
CVE-2026-69356 - Microsoft Exchange Server Spoofing Vulnerability
Product: Microsoft Exchange Server
CVSS Score: 9.3
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69356
CVE-2026-69641 - Microsoft Exchange Server Elevation of Privilege Vulnerability
Product: Microsoft Exchange Server
CVSS Score: 9.1
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69641
CVE-2026-69408 - Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Product: Microsoft Windows Media Foundation
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69408
CVE-2026-69431 - Telnet Client Remote Code Execution Vulnerability
Product: Telnet Client heap-based buffer overflow, unauthorized attacker
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69431
CVE-2026-69463 - Windows NTFS Remote Code Execution Vulnerability
Product: Windows NTFS
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69463
CVE-2026-69491 - Microsoft DirectMusic Remote Code Execution Vulnerability
Product: Microsoft DirectMusic
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69491
CVE-2026-69493 - Windows Event Logging Service Remote Code Execution Vulnerability
Product: Microsoft Windows Event Logging Service
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69493
CVE-2026-69496 - Windows Compressed Folder Remote Code Execution Vulnerability
Product: Microsoft Windows Compressed Folder
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69496
CVE-2026-69525 - Remote Desktop Services Remote Code Execution Vulnerability
Product: Microsoft Remote Desktop Services
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69525
CVE-2026-69579 - Windows Message Queuing Remote Code Execution Vulnerability
Product: Microsoft Windows Message Queuing
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69579
CVE-2026-69586 - Microsoft Windows PDF Remote Code Execution Vulnerability
Product: Microsoft Windows PDF
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69586
CVE-2026-69590 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Product: Microsoft Windows Routing and Remote Access Service (RRAS)
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69590
CVE-2026-69595 - Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Product: Microsoft Windows Services for NFS ONCRPC XDR Driver
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69595
CVE-2026-69715 - Windows Direct Show Remote Code Execution Vulnerability
Product: Microsoft Windows Direct Show
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69715
CVE-2026-69730 - Windows DNS Server Remote Code Execution Vulnerability
Product: Microsoft Windows DNS Server
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69730
CVE-2026-69768 - Windows RNDIS Remote Code Execution Vulnerability
Product: Microsoft Windows RNDIS
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69768
CVE-2026-69769 - Windows HTTP Print Provider Remote Code Execution Vulnerability
Product: Microsoft Windows HTTP Print Provider
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69769
CVE-2026-69819 - RPC Runtime Library Remote Code Execution Vulnerability
Product: RPC Runtime Library
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69819
CVE-2026-69824 - Microsoft Standard XPS Remote Code Execution Vulnerability
Product: Microsoft Standard XPS
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69824
CVE-2026-69829 - Windows Shell Remote Code Execution Vulnerability
Product: Microsoft Windows Shell
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69829
CVE-2026-69845 - Windows DHCP Server Remote Code Execution Vulnerability
Product: Microsoft Windows DHCP Server
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69845
CVE-2026-72979 - Windows DHCP Server Remote Code Execution Vulnerability
Product: Microsoft Windows DHCP Server
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72979
CVE-2026-69854 - Spring Cloud Azure Elevation of Privilege Vulnerability
Product: Spring Cloud Azure
CVSS Score: 9.0
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69854
CVE-2026-69910 - Windows Hyper-V Remote Code Execution Vulnerability
Product: Microsoft Windows Hyper-V
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69910
CVE-2026-70296 - Windows Imaging Component Remote Code Execution Vulnerability
Product: Microsoft Windows Imaging Component
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70296
CVE-2026-72982 - Windows Netlogon Remote Code Execution Vulnerability
Product: Microsoft Windows Netlogon
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72982
CVE-2026-72983 - Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Product: Microsoft indows Internet Connection Sharing (ICS)
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72983
CVE-2026-73009 - Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Product: Microsoft Windows Secure Socket Tunneling Protocol (SSTP)
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73009
CVE-2026-73010 - Microsoft Failover Cluster Remote Code Execution Vulnerability
Product: Microsoft Windows Failover Cluster
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73010
CVE-2026-73025 - Windows iSCSI Security Feature Bypass Vulnerability
Product: Microsoft Windows iSCSI
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73025
CVE-2026-77493 - Windows Graphics Component Remote Code Execution Vulnerability
Product: Microsoft Windows Graphics Component
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77493
CVE-2026-78445 - Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Product: Microsoft Windows Services for NFS ONCRPC XDR Driver
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78445
CVE-2026-78509 - Microsoft Office Outlook Remote Code Execution Vulnerability
Product: Microsoft Office Outlook
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78509
CVE-2026-78510 - Microsoft Word Remote Code Execution Vulnerability
Product: Microsoft Word
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78510
CVE-2026-81376 - Visual Studio Code Security Feature Bypass Vulnerability
Product: Microsoft Visual Studio Code
CVSS Score: 9.6
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81376
CVE-2026-66302 - Skype for Business Remote Code Execution Vulnerability
Product: Skype for Business
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66302
CVE-2026-0310 - Palo Alto Networks PAN-OS® software is susceptible to a buffer overflow vulnerability in its XML processing functionality, allowing unauthenticated attackers to execute arbitrary code with root privileges or cause a denial of service on VM-Series firewalls.
Product: Palo Alto Networks PAN-OS®
CVSS Score: 0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-0310
ISC Podcast: https://isc.sans.edu/podcastdetail/10092
CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, CVE-2026-12650, CVE-2026-12744, CVE-2026-12745 - Multiple vulnerabilities in Ivanti Neurons for ITSM before 2026.2
Product: Ivanti Neurons for ITSM
CVSS Scores: 9.8 - 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-12645 (missing authorization)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-12646 (missing authorization)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-12647 (missing authorization)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-12650 (deserialization of untrusted data)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-12744 (deserialization of untrusted data)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-12745 (deserialization of untrusted data_
NVD References: https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US
CVE-2026-48273 - Adobe ColdFusion is vulnerable to an Eval Injection flaw, allowing a low-privileged attacker to execute arbitrary code without user interaction, resulting in a change in scope.
Product: Adobe ColdFusion
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48273
NVD References: https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html
CVE-2026-75746 - Adobe ColdFusion is vulnerable to an SQL Injection flaw allowing attackers to execute arbitrary code without user interaction and escalate privileges.
Product: Adobe ColdFusion
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-75746
NVD References: https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html
CVE-2026-82004 - Adobe Campaign Classic (ACC) is susceptible to OS Command Injection which allows for the execution of arbitrary code without user interaction, potentially resulting in unauthorized access.
Product: Adobe Campaign 7.4.4
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-82004
NVD References: https://helpx.adobe.com/security/products/campaign/apsb26-142.html
CVE-2026-19232 - Adobe Experience Manager is vulnerable to an Incorrect Authorization flaw that allows for arbitrary code execution and potential account takeovers without user interaction.
Product: Adobe Experience Manager
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19232
NVD References: https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html
CVE-2026-76200, CVE-2026-76201 - Adobe Commerce is impacted by stored XSS vulnerabilities allowing attackers to inject malicious scripts into form fields, potentially gaining control over victim's accounts.
Product: Adobe Commerce
CVSS Score: 9.3
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76200
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76201
NVD References: https://helpx.adobe.com/security/products/magento/apsb26-138.html
CVE-2026-85506 - ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
Product: FreeIPMI ipmi-oem
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85506
CVE-2026-85507 - ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
Product: FreeIPMI ipmi-oem
CVSS Score: 9.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85507
CVE-2026-41869 - Apache Nutch Server (Nutch REST API) is vulnerable to Missing Authorization, Improper Resource Shutdown, and Job Interruption, impacting versions 1.10 through 1.22.
Product: Apache Nutch
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-41869
NVD References: https://lists.apache.org/thread/ps4yhlvo6kdgmksdgb9lv1h4p0oy5fdj
CVE-2026-41871 - Apache Nutch server is vulnerable to Missing Authorization allowing for unsafe reflection in the Nutch REST API, impacting versions 1.10 through 1.22.
Product: Apache Nutch
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-41871
NVD References: https://lists.apache.org/thread/rbr63fx8vlrhzrfknq2l0mg0d0blsl54
CVE-2026-75156 - Apache Airflow FAB provider versions 3.7.3 through 3.8.0 have a vulnerability that allows anyone with the ability to register an Azure tenant to authenticate to the Airflow UI with an attacker-controlled token.
Product: Apache Airflow FAB provider
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-75156
NVD References: https://lists.apache.org/thread/n3l6z4jfdxj4p0t8l7m6olkq6xsc6f76
CVE-2026-56207 - Apache Impala's hs2-http interface in versions <4.5.2 is vulnerable to unauthorized user impersonation by not verifying the signature of the Bearer token in the last step of SAML2 authentication.
Product: Apache Impala
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56207
NVD References: https://lists.apache.org/thread/20cov78py0zqzx7dyq39ktythkwn91zs
CVE-2026-50093 - Siveillance Control Pro V3.0, V4.0, and Siveillance Control V3.0, V4.0 are vulnerable to arbitrary file uploads that can lead to root access and compromise of the OIS environment.
Product: Siemens Siveillance Control Pro, Siveillance Control
CVSS Score: 9.0
NVD References: https://cert-portal.siemens.com/productcert/html/ssa-254516.html
CVE-2026-62645 - Reyrolle 7SR5 (All versions < V2.70) is vulnerable to unauthorized access due to information exposure in the web interface allowing an attacker to bypass authentication.
Product: Reyrolle 7SR5
CVSS Score: 9.8
NVD References: https://cert-portal.siemens.com/productcert/html/ssa-142885.html
CVE-2026-26084 - Fortinet FortiSandbox versions 4.4.0 through 4.4.8, 5.0.0 through 5.0.5, and Cloud/PaaS 5.0.4 through 5.0.5 are susceptible to improper access control, enabling attackers to retrieve sensitive data through malicious HTTP requests.
Product: Fortinet FortiSandbox
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-26084
NVD References: https://fortiguard.fortinet.com/psirt/FG-IR-26-166
CVE-2026-78234 - The flaw in hawtio-operator allows any user with edit access to obtain a Service-CA-signed certificate with an arbitrary subject, posing a risk of impersonation in-cluster.
Product: Red Hat hawtio-operator
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-78234
NVD References: https://access.redhat.com/security/cve/CVE-2026-78234
CVE-2026-82533 - The DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability allowing unauthenticated access to its local HTTP agent-control API.
Product: DeepSeek Harness
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-82533
NVD References: https://www.ox.security/blog/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape/
CVE-2026-44756 - Extended Passport Protocol (EPP) processing library contains a memory safety vulnerability that could allow an unauthenticated attacker to exploit a crafted network request and cause abnormal program termination.
Product: Extended Passport Protocol (EPP) processing library
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44756
NVD References: https://url.sap/sapsecuritypatchday
CVE-2026-58240 - SAP NetWeaver Message Server allows unauthenticated attackers to register unauthorized components and gain access to confidential data, compromising system integrity and availability.
Product: SAP NetWeaver Message Server
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58240
NVD References: https://url.sap/sapsecuritypatchday
CVE-2026-66768 - SAP GUI for Java is vulnerable to arbitrary command execution due to improper trust level enforcement, enabling low-privileged attackers to compromise system confidentiality, integrity, and availability.
Product: SAP GUI for Java
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-66768
NVD References: https://url.sap/sapsecuritypatchday
CVE-2026-76969 - @sap/cds-mtxs NPM library lacks necessary security checks, potentially allowing unauthenticated attackers to access sensitive credentials in multitenant CAP applications with extensibility enabled, resulting in a high impact on availability, integrity, and confidentiality of business data.
Product: SAP @sap/cds-mtxs NPM library
CVSS Score: 9.4
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76969
NVD References: https://url.sap/sapsecuritypatchday
CVE-2026-77089 - Command Center API had an authentication bypass issue impacting privilege management, prompting software customers to upgrade to the resolved maintenance release and update Command Center.
Product: Commvault Command Center API
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-77089
NVD References: https://documentation.commvault.com/securityadvisories/CV_2026_07_1.html
CVE-2026-77092 - Content Extractor is vulnerable to a deserialization of untrusted data issue affecting privilege management, software customers should upgrade to the resolved maintenance release to address the issue.
Product: Commvault Content Extractor
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-77092
NVD References: https://documentation.commvault.com/securityadvisories/CV_2026_07_6.html
CVE-2026-77098 - Private Metrics Server is vulnerable to SQL injection, requiring customers to upgrade to the latest maintenance release for resolution.
Product: Commvault Private Metrics Server
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-77098
NVD References: https://documentation.commvault.com/securityadvisories/CV_2026_08_2.html
CVE-2026-28606 - AdapterService in handleBondStateChanged in AdapterService.java allows for potential pairing skipping, leading to remote privilege escalation without user consent or additional privileges required for exploitation.
Product: Google Android
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-28606
NVD References: https://source.android.com/docs/security/bulletin/2026/2026-09-01
CVE-2026-49921 - The vulnerable product has a heap buffer overflow vulnerability in the SDP server where an oversized attribute could be serialized into a fixed
400-byte allocation during partial attribute responses.
Product: Google Android
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-49921
NVD References: https://source.android.com/docs/security/bulletin/2026/2026-09-01
CVE-2026-58822 - ftsmooth.c contains a memory safety issue that could enable remote code execution without requiring additional privileges or user interaction.
Product: Notepad++ ftsmooth.c
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58822
NVD References: https://source.android.com/docs/security/bulletin/2026/2026-09-01
CVE-2026-85982 - The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) due to improper HTML encoding of data in search results and updater logs, allowing authenticated users to execute malicious scripts.
Product: Auth0 AD/LDAP Connector
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85982
NVD References: https://trust.okta.com/security-advisories/stored-cross-site-scripting-xss-in-auth0-ad-ldap-connector-cve-2026-85982
CVE-2026-53581 - OPNsense is vulnerable to a path traversal attack in the NTP configuration module, allowing an attacker to overwrite arbitrary files on the system as the root user.
Product: OPNsense NTP configuration module
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53581
NVD References: https://github.com/opnsense/core/security/advisories/GHSA-872g-g543-j37m
CVE-2026-87438 - Google Chrome on Android prior to 153.0.8010.36 allowed remote attackers to execute arbitrary code via a crafted HTML page.
Product: Google Chrome
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87438
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
CVE-2026-87464 - Google Chrome WebGL vulnerability (CVE-2022-0996) allowed remote attackers to execute arbitrary code through a specially crafted HTML page.
Product: Google Chrome
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87464
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
CVE-2026-87488 - Google Chrome on Android prior to version 153.0.8010.36 was vulnerable to a use after free exploit in WebGL that allowed remote code execution via a malicious HTML page.
Product: Google Chrome
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87488
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
CVE-2026-87520 - Google Chrome on Android prior to 153.0.8010.36 allowed remote code execution due to a use after free vulnerability in Dawn.
Product: Google Chrome
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87520
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
CVE-2026-87534 - Google Chrome on Android prior to version 153.0.8010.36 allowed a remote attacker to bypass system access restrictions through crafted network traffic.
Product: Google Chrome
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87534
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
CVE-2026-87595 - Google Chrome Mobile prior to version 153.0.8010.36 is vulnerable to an SSRF issue that allowed a remote attacker to bypass system access restrictions through social engineering.
Product: Google Chrome
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87595
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
CVE-2026-87607 - Google Chrome on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.
Product: Google Chrome
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87607
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
CVE-2026-87643 - Google Chrome on Android prior to version 153.0.8010.36 allowed remote attackers to potentially execute arbitrary code outside the sandbox due to an integer overflow in the GPU.
Product: Google Chrome
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87643
NVD References: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
CVE-2026-21095 - libimagecodec.quram.so is vulnerable to a heap-based buffer overflow in its DNG decoder, allowing remote attackers to execute arbitrary code.
Product: Samsung Android 17.0
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-21095
NVD References: https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09
CVE-2026-21096 - libimagecodec.quram.so has a heap-based buffer overflow in its JPEG decoder, allowing remote attackers to execute arbitrary code.
Product: Samsung Android 17.0
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-21096
NVD References: https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09
CVE-2026-80172 - Dell SCG 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively, are vulnerable to unauthorized access due to Insufficient Verification of Data Authenticity, potentially allowing an unauthenticated attacker to gain ADMIN access and refresh tokens indefinitely.
Product: Dell Secure Connect Gateway
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-80172
NVD References: https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
*NO CUSTOMER ACTION REQUIRED*
CVE-2026-83941 - Entra ID Elevation of Privilege Vulnerability
Product: Microsoft Entra ID
CVSS Score: 9.9
NO CUSTOMER ACTION REQUIRED
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83941
CVE-2026-62916 - Microsoft Entra ID Elevation of Privilege Vulnerability
Product: Microsoft Entra ID
CVSS Score: 9.1
NO CUSTOMER ACTION REQUIRED
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62916
CVE-2026-70352 - Azure AI Language Elevation of Privilege Vulnerability
Product: Microsoft Azure AI Language
CVSS Score: 10.0
NO CUSTOMER ACTION REQUIRED
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70352
CVE-2026-83711 - Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
Product: Microsoft Azure Active Directory B2C
CVSS Score: 10.0
NO CUSTOMER ACTION REQUIRED
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83711
CVE-2026-80098 - Copilot Studio Elevation of Privilege Vulnerability
Product: Microsoft Copilot Studio
CVSS Score: 9.3
NO CUSTOMER ACTION REQUIRED
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80098
Prompt Injection Incident Response Playbook AI agents now hold IAM roles, reach databases, and run automated workflows. That makes them high-impact targets: a single prompt injection can turn an agent's own access into data exfiltration or deleted cloud resources. See how to detect, contain, and recover from injection attacks with unified visibility across agents, models, and cloud infrastructure.
SANS Research | The State of Cybersecurity at the Human Edge Survey | Share your perspective in this short survey and help shape the insights the community relies on.
Webinar | From Framework to Action: Applying the SANS AI Security Maturity Model | Wednesday, September 16 | Watch now to turn the SANS AI Security Maturity Model into a real action plan.
Webinar | SANS 2026 Exposure Management Survey Insights: Cyber Exposure at a Crossroads | Wednesday, October 7 | New global survey data reveals how security leaders are (and aren't) turning exposure visibility into risk-based decisions their business can act on. See where your program's maturity really stands.