CVE-2026-102795 in Apache Traffic Server: building a version inventory before you patch Vulnerability overview Apache Traffic Server is affected by CVE-2026-102795, an improper access control flaw that the Apache Software Foundation disclosed on 2 October 2026 as part of a batch of eight CVEs…
CVE-2026-95675: Unauthenticated Root Command Injection in D-Link DAP-1360 Firmware Vulnerability overview CVE-2026-95675 is a critical OS command injection flaw in the web management interface of the D-Link DAP-1360, a long-retired wireless access point and range extender. The vulnerability is…
426,677 titles against 12,055 fingerprints: locating the Tenda gateways behind CVE-2026-104610 CVE-2026-104610 affects the Tenda HG7, HG9 and HG10 fibre gateways. Finding them from outside is harder than the headline severity suggests, because the obvious query and the accurate query return very…
Docker Sandboxes CVE-2026-77179 and CVE-2026-79994: when the agent VM can still reach the host Docker Sandboxes is the feature that runs an AI coding agent inside a purpose-built virtual machine, so that whatever the agent does stays out of the developer's environment. In September 2026 Docker…
CVE-2026-94293 (CVSS 9.8) — Murrelektronik's Software AAS Edge Client exposes an unauthenticated REST API on TCP port 18000 bound to all interfaces. Any network-reachable attacker can read all AAS submodel data via GET and overwrite it via PATCH — no credentials, no user interaction, no exploit…
OpenCTI Case Creation Flaw CVE-2026-76822: A Permission Model Postmortem Vulnerability overview CVE-2026-76822 is a moderate authorization flaw in OpenCTI, the open-source cyber threat intelligence platform maintained by Filigran. GitHub advisory GHSA-w45v-76pj-xggm scores it 4.3, credits…
CVE-2026-5430: the JWT validator that skipped signature checking when it met an algorithm it did not know A patched authentication bypass is easier to ignore than an unpatched one. WSO2 fixed CVE-2026-5430 in April 2026, published an advisory in May, and saw exploitation in the wild in September…
After CVE-2026-104286: A Compromise Assessment Plan for FortiMail Start from the exploitation window CVE-2026-104286 is a CVSS 9.8 path traversal in Fortinet FortiMail that allows unauthenticated file writes through crafted HTTP or HTTPS requests. Fortinet reports exploitation in the wild, and CISA…