Attackers began exploiting CVE-2026-61500, a critical flaw in the Rejetto HFS file server, on October 3, 2026. That was one day after Horizon3.ai published how it works, The Register reports. The bug lets anyone forge an administrator login and then run code on the server. It was found with Mythos…
Cisco ISE CVE-2026-76460: When the Policy Engine Becomes the Weakest Link On September 16, 2026, Cisco published a batch of security advisories covering 77 CVEs. One of them, CVE-2026-76460, carries a CVSS 3.1 base score of 10.0 and affects Cisco Identity Services Engine (ISE) and the ISE Passive…
Cisco FMC CVE-2026-20079: a CVSS 10.0 management-plane bypass and the clusters behind it Opening A patch that shipped in March became an incident in September. Cisco first published the advisory for CVE-2026-20079, filed under the identifier cisco-sa-onprem-fmc-authbypass-5JPp45V2 , after an…
A patch plan for CVE-2026-88773 that accounts for FIPS, NDcPP and hybrid deployments The straightforward part CVE-2026-88773 is one of eight flaws fixed in Citrix bulletin CTX697096 for NetScaler ADC and Gateway. It is rated CVSS 9.3, requires HTTP functionality to be enabled, and requires no…
Finding Affected Check Point VPN Deployments: Version Scope and ZoomEye Exposure for CVE-2026-85102 Vulnerability overview CERT-In Vulnerability Note CIVN-2026-0459, dated September 16, 2026, rates multiple Check Point VPN vulnerabilities as CRITICAL. The note names CVE-2026-85102 and…
A CVE published yesterday afternoon says the Python sandbox in CrewAI, a widely used agent framework, blocked nine module names and still lost. The record's wording is blunt for a CVE: the blocklist "operates at the wrong level of abstraction." The escape it describes never uses an import statement…
Detection and verification limits for CVE-2026-96364 on a live Drupal estate Vulnerability overview CVE-2026-96364 is listed in CERT-BUND WID-SEC-2026-3554, published 23 September 2026, covering 36 identifiers and 16 contributed Drupal projects. The advisory is rated high, flagged remotely…
CVSS 3.1: 9.8 (Critical) / CVSS 4.0: 9.3 / CWE-338 (Use of a cryptographically weak PRNG) Rejetto HFS (HTTP File Server) versions 3.0.0 through 3.2.0 ship a bug that lets an unauthenticated attacker forge an administrator session and, from there, execute arbitrary code on the server through HFS's…
GitLab CVE-2026-85706: When a Path Traversal Lands in the Software Delivery Chain Path traversal is one of the oldest bug classes in web application security, and that familiarity is exactly why a CVSS 10.0 rating for one gets dismissed as an inflated score. The rating makes more sense when you…
CVE-2026-84411 in MikroTik RouterOS: why a pre-authentication integer underflow reaches root The vulnerability in one paragraph MikroTik RouterOS before 7.24 carries an integer underflow (CWE-191) in the web management service. CISA documented it as ICSA-26-272-06 on September 29, 2026 and rated it…