426,677 titles against 12,055 fingerprints: locating the Tenda gateways behind CVE-2026-104610 CVE-2026-104610 affects the Tenda HG7, HG9 and HG10 fibre gateways. Finding them from outside is harder than the headline severity suggests, because the obvious query and the accurate query return very…
Docker Sandboxes CVE-2026-77179 and CVE-2026-79994: when the agent VM can still reach the host Docker Sandboxes is the feature that runs an AI coding agent inside a purpose-built virtual machine, so that whatever the agent does stays out of the developer's environment. In September 2026 Docker…
CVE-2026-94293 (CVSS 9.8) — Murrelektronik's Software AAS Edge Client exposes an unauthenticated REST API on TCP port 18000 bound to all interfaces. Any network-reachable attacker can read all AAS submodel data via GET and overwrite it via PATCH — no credentials, no user interaction, no exploit…
OpenCTI Case Creation Flaw CVE-2026-76822: A Permission Model Postmortem Vulnerability overview CVE-2026-76822 is a moderate authorization flaw in OpenCTI, the open-source cyber threat intelligence platform maintained by Filigran. GitHub advisory GHSA-w45v-76pj-xggm scores it 4.3, credits…
CVE-2026-5430: the JWT validator that skipped signature checking when it met an algorithm it did not know A patched authentication bypass is easier to ignore than an unpatched one. WSO2 fixed CVE-2026-5430 in April 2026, published an advisory in May, and saw exploitation in the wild in September…
After CVE-2026-104286: A Compromise Assessment Plan for FortiMail Start from the exploitation window CVE-2026-104286 is a CVSS 9.8 path traversal in Fortinet FortiMail that allows unauthenticated file writes through crafted HTTP or HTTPS requests. Fortinet reports exploitation in the wild, and CISA…
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed Citrix published fixes for two NetScaler flaws on 2026-09-27 after watchTowr reported unpatched remote code execution bugs under active exploitation. Both flaws are rated 9.5 under CVSS v4. The two…
An authenticated tenant with basic namespace permissions can break out to the host control plane in OpenShift clusters running Multicluster Engine with HyperShift. CVE-2026-101919 (CVSS 3.1 8.8, Red Hat: Important) is an improper input validation flaw in the hypershift-rhel9-operator. The…