What CVE-2026-84411 says about trusting perimeter assumptions on network devices The assumption under test Network devices are often treated as part of the perimeter rather than as assets inside it. The reasoning is that a device which enforces filtering is itself protected by that filtering.…
Assessing Real-World Risk From CVE-2026-78249 Without Overstating It Vulnerability overview CVE-2026-78249 is a path traversal vulnerability in multifunction printers from FUJIFILM Business Innovation Corp. and Sharp Corporation, disclosed by JPCERT/CC as JVNVU#90160989 on 2026-09-30. It is CWE-22…
oc-mirror CVE-2026-75939: A Signature Check That Runs in the Wrong Order Red Hat disclosed CVE-2026-75939 on 21 September 2026 with a CVSS v3.1 score of 7.4. The affected component is openshift4/oc-mirror-plugin-rhel9 in Red Hat OpenShift Container Platform 4. The tool that syncs release images…
Why vul.cve Returns Zero for CVE-2026-96365: Reading Exposure Data Honestly Vulnerability overview CVE-2026-96365 is one of 36 identifiers in CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026 and rated high risk. The advisory covers 16 contributed Drupal projects, with identifiers…
Attackers began exploiting CVE-2026-61500, a critical flaw in the Rejetto HFS file server, on October 3, 2026. That was one day after Horizon3.ai published how it works, The Register reports. The bug lets anyone forge an administrator login and then run code on the server. It was found with Mythos…
Cisco ISE CVE-2026-76460: When the Policy Engine Becomes the Weakest Link On September 16, 2026, Cisco published a batch of security advisories covering 77 CVEs. One of them, CVE-2026-76460, carries a CVSS 3.1 base score of 10.0 and affects Cisco Identity Services Engine (ISE) and the ISE Passive…
Cisco FMC CVE-2026-20079: a CVSS 10.0 management-plane bypass and the clusters behind it Opening A patch that shipped in March became an incident in September. Cisco first published the advisory for CVE-2026-20079, filed under the identifier cisco-sa-onprem-fmc-authbypass-5JPp45V2 , after an…
A patch plan for CVE-2026-88773 that accounts for FIPS, NDcPP and hybrid deployments The straightforward part CVE-2026-88773 is one of eight flaws fixed in Citrix bulletin CTX697096 for NetScaler ADC and Gateway. It is rated CVSS 9.3, requires HTTP functionality to be enabled, and requires no…
Finding Affected Check Point VPN Deployments: Version Scope and ZoomEye Exposure for CVE-2026-85102 Vulnerability overview CERT-In Vulnerability Note CIVN-2026-0459, dated September 16, 2026, rates multiple Check Point VPN vulnerabilities as CRITICAL. The note names CVE-2026-85102 and…