The week in one view25 CVEs qualified. 17 have CISA-confirmed exploitation and 19 have a verified patch reference or fixed release in BlackTree’s retained evidence.
How records qualifyNewly published this week, or newly actionable because exploitation was confirmed, public exploit evidence appeared, verified remediation became available, or severity increased.How they are rankedConfirmed exploitation, ransomware linkage, unauthenticated network reachability, public exploit evidence, operational urgency, remediation, EPSS, CVSS, then recency.What is excludedOrdinary source refreshes, replaced links and affected-version churn do not qualify by themselves. An older CVE appears only when it gains a new action trigger this week.
1CVE-2023-27532Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function VulnerabilityVeeam · Backup & ReplicationSelected for: New verified remediation · CISA KEV · Ransomware-linked · Unauthenticated network pathCritical⌄
Published High 7.5 · EPSS 81.33%
- What changed
- Remediation status changed from Awaiting fix to Patch available. Remediation status changed from Awaiting fix to Patch available. Remediation status changed from Awaiting fix to Patch available.
- Why it matters
- CISA confirms exploitation in the wild and lists 2023-09-12 as the remediation due date.
- Patch action
- Patch available. Apply the fixed release for the affected product branch as recorded by Veeam. Validate the exact product and build in the linked advisory before deployment.
- Fixed version
- 11a (build 11.0.1.1261 P20230227); 12 (build 12.0.0.1420 P20230223)
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →2CVE-2026-63077JetBrains TeamCity Deserialization of Untrusted Data VulnerabilityJetBrains · TeamCitySelected for: New CISA KEV confirmation · CISA KEV · Ransomware-linked · Unauthenticated network pathCritical⌄
Published Critical 9.8 · EPSS 89.57%
- What changed
- CISA KEV now confirms exploitation in the wild.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-08-08 as the remediation due date.
- Patch action
- Mitigation available. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Fixed version
- No fixed version is explicitly recorded in the structured CVE data.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →3CVE-2026-67279Mikrotik RouterOS Improper Enforcement of Behavioral Workflow VulnerabilityMikrotik · RouterOSSelected for: New ENISA known-exploited evidence · CISA KEV · Public exploit evidence · Unauthenticated network pathCritical⌄
Published Medium 6.9 · EPSS 1.03%
- What changed
- ENISA EUVD now records this CVE in its known-exploited dataset.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-28 as the remediation due date.
- Patch action
- Mitigation available. Apply the mitigation in the linked authoritative guidance while planning the vendor's permanent fix.
- Fixed version
- No fixed version is explicitly recorded in the structured CVE data.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →4CVE-2026-71362Adobe Commerce and Magento Incorrect Authorization Vulnerability Adobe · Commerce and MagentoSelected for: New ENISA known-exploited evidence · CISA KEV · Unauthenticated network path · Verified patchCritical⌄
Published Critical 9.1 · EPSS 87.51%
- What changed
- ENISA EUVD now records this CVE in its known-exploited dataset.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-27 as the remediation due date.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- Adobe Commerce: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug; Adobe Commerce B2B: 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug; Magento Open Source: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →5CVE-2026-93616Check Point Multiple Products Path Traversal VulnerabilityCheck Point · Multiple ProductsSelected for: Published this week · New ENISA known-exploited evidence · New verified remediation · CISA KEVCritical⌄
Published Critical 9.8 · EPSS 19.65%
- What changed
- ENISA EUVD now records this CVE in its known-exploited dataset. Remediation status changed from Awaiting fix to Patch available. Remediation status changed from Awaiting fix to Mitigation available.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-25 as the remediation due date.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →6CVE-2026-85102Check Point Multiple Products Improper Certificate Validation VulnerabilityCheck Point · Multiple ProductsSelected for: New ENISA known-exploited evidence · New verified remediation · CISA KEV · Unauthenticated network pathCritical⌄
Published Critical 9.8 · EPSS 7.55%
- What changed
- ENISA EUVD now records this CVE in its known-exploited dataset. Remediation status changed from Awaiting fix to Patch available. Remediation status changed from Awaiting fix to Mitigation available.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-25 as the remediation due date.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →7CVE-2026-94127F5 BIG-IP APM Heap-based Buffer Overflow VulnerabilityF5 · BIG-IP APMSelected for: Published this week · New ENISA known-exploited evidence · New verified remediation · New CISA KEV confirmationCritical⌄
Published Critical 9.3 · EPSS 2.23%
- What changed
- ENISA EUVD now records this CVE in its known-exploited dataset. Remediation status changed from Awaiting fix to Patch available. CISA KEV now confirms exploitation in the wild.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-25 as the remediation due date.
- Patch action
- Patch available. Apply the fixed release for the affected product branch as recorded by Canadian Centre for Cyber Security. Validate the exact product and build in the linked advisory before deployment.
- Fixed version
- The Cyber Centre strongly recommends that organizations running affected F5 BIG‑IP APM deployments upgrade to the following vendor-supported fixed hotfix releases:
Affected product
Affected versions
Fixed Versions
BIG IP APM
Versions 17.1.0 prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Version 17.1.0 Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
BIG IP APM
Versions 17.5.0 prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
Version 17.5.0 Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
BIG IP APM
Versions 21.1.0 prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
Version 21.1.0 Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
The Cyber Centre also recommends organizations to:
Identify vulnerable BIG IP systems that have both an APM access policy and an OAuth profile configured on a virtual server.
Apply the vendor-provided iRule (contact F5 Support to obtain the iRule) Footnote 1 .
Review access logs for indicators of compromise (IoC), particularly OAuth authentication failures especially in rapid succession or large volume Footnote 1 . Also review administrative accounts, access policies for any signs of suspicious activity.
Upgrade to a vendor-supported fixed software version as soon as possible.
Ensure management interfaces are restricted to trusted administrative networks.
Follow F5 guidance for vulnerability remediation and validation following patch deployment.
Note: Organizations operating Common Criteria Footnote 5 evaluated configurations should review F5's advisory Footnote 1 and apply the recommended updates in accordance with their change management and certification requirements.
In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions Footnote 6 with an emphasis on the following topics:
Consolidating, monitoring, and defending Internet gateways
Patch operating systems and applications
Harden operating systems and applications
Isolate web-facing applications
Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal , or email contact@cyber.gc.ca .
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →8CVE-2026-93952Arista VeloCloud Orchestrator Improper Input Validation VulnerabilityArista · VeloCloud OrchestratorSelected for: Published this week · New ENISA known-exploited evidence · New CISA KEV confirmation · CISA KEVCritical⌄
Published Critical 9.5 · EPSS 1.06%
- What changed
- ENISA EUVD now records this CVE in its known-exploited dataset. CISA KEV now confirms exploitation in the wild.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-25 as the remediation due date.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- The recommended resolution is to upgrade to a remediated VCO software version at your earliest convenience. These vulnerabilities have been fixed in the following releases:; - VCO 5.2.3.16 and later in the 5.2.3 train; - VCO 6.4.2.8 and later in the 6.4.2 train; Releases in other release trains that fix this will be added over time. For VCOs not on a supported release train, customers can contact TAC to discuss possible upgrade options.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →9CVE-2026-5430WSO2 Multiple Products Path Traversal Vulnerability WSO2 · Multiple ProductsSelected for: New ENISA known-exploited evidence · CISA KEV · Unauthenticated network path · Verified patchCritical⌄
Published Critical 10.0 · EPSS 0.59%
- What changed
- ENISA EUVD now records this CVE in its known-exploited dataset.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-27 as the remediation due date.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- WSO2 Carbon API Manager Rest API Utility: 9.33.106 ≤ *
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →10CVE-2026-87902WordPress Core Remote File Inclusion VulnerabilityWordPress · CoreSelected for: Published this week · New verified remediation · New ENISA known-exploited evidence · CISA KEVCritical⌄
Published High 8.1 · EPSS 22.49%
- What changed
- Remediation status changed from Awaiting fix to Mitigation available. ENISA EUVD now records this CVE in its known-exploited dataset. Remediation status changed from Awaiting fix to Mitigation available.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-28 as the remediation due date.
- Patch action
- Mitigation available. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Fixed version
- No fixed version is explicitly recorded in the structured CVE data.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →11CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityMicrosoft · Internet Key Exchange (IKE) Service ExtensionsSelected for: New verified remediation · CISA KEV · Unauthenticated network path · Verified patchCritical⌄
Published Critical 9.8 · EPSS 1.62%
- What changed
- Remediation status changed from Awaiting fix to Mitigation available. Remediation status changed from Awaiting fix to Mitigation available.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-08-21 as the remediation due date.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →12CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityCitrix · NetScalerSelected for: Published this week · New verified remediation · New ENISA known-exploited evidence · New CISA KEV confirmationCritical⌄
Published Critical 9.5 · EPSS 1.24%
- What changed
- Remediation status changed from Awaiting fix to Mitigation available. ENISA EUVD now records this CVE in its known-exploited dataset. CISA KEV now confirms exploitation in the wild.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-30 as the remediation due date.
- Patch action
- Mitigation available. On September 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Fixed version
- No fixed version is explicitly recorded in the structured CVE data.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →13CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityCitrix · NetScalerSelected for: Published this week · New verified remediation · New ENISA known-exploited evidence · New CISA KEV confirmationCritical⌄
Published Critical 9.5 · EPSS 1.03%
- What changed
- Remediation status changed from Awaiting fix to Mitigation available. ENISA EUVD now records this CVE in its known-exploited dataset. CISA KEV now confirms exploitation in the wild.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-30 as the remediation due date.
- Patch action
- Mitigation available. On September 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Fixed version
- No fixed version is explicitly recorded in the structured CVE data.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →14CVE-2008-4128Cisco IOS Cross-Site Request Forgery VulnerabilityCisco · IOSSelected for: Published severity increased · CVSS increased · CISA KEV · Public exploit evidenceCritical⌄
Published High 8.1 · EPSS 33.87%
- What changed
- Severity changed from Medium to High. CVSS score changed from 4.3 (CVSS 3.1 · CISA ADP · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) to 8.1 (CVSS 3.1 · CISA ADP · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-07-16 as the remediation due date.
- Patch action
- Awaiting fix. No verified patch reference is present in the current structured sources. Check the vendor advisory before making a change.
- Fixed version
- No fixed version is explicitly recorded in the structured CVE data.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →15CVE-2026-65660Microsoft SharePoint Code Injection VulnerabilityMicrosoft · SharePointSelected for: New ENISA known-exploited evidence · New CISA KEV confirmation · CISA KEV · Verified patchCritical⌄
Published High 8.8 · EPSS 2.10%
- What changed
- ENISA EUVD now records this CVE in its known-exploited dataset. CISA KEV now confirms exploitation in the wild.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-28 as the remediation due date.
- Patch action
- Patch available. 16.0.5565.1001:Security Update:https://support.microsoft.com/help/5002905
- Fixed version
- Microsoft SharePoint Enterprise Server 2016 16.0.5565.1001; Microsoft SharePoint Server 2019 16.0.10417.20198; Microsoft SharePoint Server Subscription Edition 16.0.19725.20522
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →16CVE-2025-39964Linux Kernel Race Condition VulnerabilityLinux · KernelSelected for: New verified remediation · CISA KEV · Verified patchCritical⌄
Published High 7.8 · EPSS 1.00%
- What changed
- Remediation status changed from Mitigation available to Patch available.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-09-21 as the remediation due date.
- Patch action
- Patch available. To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
- Fixed version
- cluster-md-kmp-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; dlm-kmp-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; gfs2-kmp-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-64kb-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-64kb-devel-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-default-base-6.4.0-150600.23.135.1.150600.12.62.4 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-default-devel-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-devel-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-docs-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-macros-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-obs-build-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-source-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-syms-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; kernel-zfcpdump-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; ocfs2-kmp-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; reiserfs-kmp-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server 15 SP6-LTSS; cluster-md-kmp-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; dlm-kmp-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; gfs2-kmp-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; kernel-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; kernel-default-base-6.4.0-150600.23.135.1.150600.12.62.4 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; kernel-default-devel-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; kernel-devel-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; kernel-docs-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; kernel-macros-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; kernel-obs-build-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; kernel-source-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; kernel-syms-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; ocfs2-kmp-default-6.4.0-150600.23.135.1 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6; and 3 more
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →17CVE-2026-3909Google Skia Out-of-Bounds Write VulnerabilityGoogle · SkiaSelected for: New verified remediation · CISA KEV · Verified patchCritical⌄
Published High 8.8 · EPSS 0.70%
- What changed
- Remediation status changed from Awaiting fix to Patch available.
- Why it matters
- CISA confirms exploitation in the wild and lists 2026-03-27 as the remediation due date.
- Patch action
- Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
- Fixed version
- webkit2gtk3-0:2.54.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-0:2.54.0-1.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-0:2.54.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-0:2.54.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-0:2.54.0-1.el9_8.src as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-0:2.54.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debuginfo-0:2.54.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debuginfo-0:2.54.0-1.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debuginfo-0:2.54.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debuginfo-0:2.54.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debuginfo-0:2.54.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debugsource-0:2.54.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debugsource-0:2.54.0-1.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debugsource-0:2.54.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debugsource-0:2.54.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-debugsource-0:2.54.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-0:2.54.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-0:2.54.0-1.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-0:2.54.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-0:2.54.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-0:2.54.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-debuginfo-0:2.54.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-debuginfo-0:2.54.0-1.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-debuginfo-0:2.54.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-debuginfo-0:2.54.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-devel-debuginfo-0:2.54.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-jsc-0:2.54.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-jsc-0:2.54.0-1.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-jsc-0:2.54.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9); webkit2gtk3-jsc-0:2.54.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9); and 16 more
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →18CVE-2026-43641Softaculous Virtualizor OS Command Injection via Billing Module HandlerSoftaculous · VirtualizorSelected for: Published this week · New public exploit evidence · Public exploit evidence · Unauthenticated network pathCritical⌄
Published Critical 9.3 · EPSS 3.03%
- What changed
- Public exploit evidence changed from No public exploit to Public exploit reference.
- Why it matters
- Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- Virtualizor: 3.0.0
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →19CVE-2026-77521MaxKB: Prompt-injectable agent can lead to command execution1Panel-dev · MaxKBSelected for: New public exploit evidence · Public exploit evidence · Unauthenticated network path · Verified patchCritical⌄
Published Critical 10.0 · EPSS 1.05%
- What changed
- Public exploit evidence changed from No public exploit to Public exploit reference.
- Why it matters
- Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- 2.10.5-lts.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →20CVE-2026-19931Negotiate ambient user conn reusecurl · curlSelected for: New verified remediation · Public exploit evidence · Unauthenticated network path · Verified patchCritical⌄
Published Critical 9.8 · EPSS 0.75%
- What changed
- Remediation status changed from Mitigation available to Patch available.
- Why it matters
- Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.
- Patch action
- Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
- Fixed version
- cargo-0:1.98.0-1.hum1@aarch64 as a component of Red Hat Hardened Images; cargo-0:1.98.0-1.hum1@x86_64 as a component of Red Hat Hardened Images; clippy-0:1.98.0-1.hum1@aarch64 as a component of Red Hat Hardened Images; clippy-0:1.98.0-1.hum1@x86_64 as a component of Red Hat Hardened Images; curl-0:8.22.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; curl-0:8.22.0-0.1.hum1@src as a component of Red Hat Hardened Images; curl-0:8.22.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; libcurl-0:8.22.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; libcurl-0:8.22.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; libcurl-devel-0:8.22.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; libcurl-devel-0:8.22.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; libcurl-minimal-0:8.22.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images; libcurl-minimal-0:8.22.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images; rust-0:1.98.0-1.hum1@aarch64 as a component of Red Hat Hardened Images; rust-0:1.98.0-1.hum1@src as a component of Red Hat Hardened Images; rust-0:1.98.0-1.hum1@x86_64 as a component of Red Hat Hardened Images; rust-analyzer-0:1.98.0-1.hum1@aarch64 as a component of Red Hat Hardened Images; rust-analyzer-0:1.98.0-1.hum1@x86_64 as a component of Red Hat Hardened Images; rust-debugger-common-0:1.98.0-1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images; rust-debugger-common-0:1.98.0-1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images; rust-doc-0:1.98.0-1.hum1@aarch64 as a component of Red Hat Hardened Images; rust-doc-0:1.98.0-1.hum1@x86_64 as a component of Red Hat Hardened Images; rust-gdb-0:1.98.0-1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images; rust-gdb-0:1.98.0-1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images; rust-lldb-0:1.98.0-1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images; rust-lldb-0:1.98.0-1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images; rust-src-0:1.98.0-1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images; rust-src-0:1.98.0-1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images; rust-std-static-0:1.98.0-1.hum1@aarch64 as a component of Red Hat Hardened Images; rust-std-static-0:1.98.0-1.hum1@x86_64 as a component of Red Hat Hardened Images; and 18 more
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →21CVE-2026-93603vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Functionpatriksimek · vm2Selected for: New public exploit evidence · Public exploit evidence · Unauthenticated network path · Verified patchCritical⌄
Published Critical 10.0 · EPSS 0.73%
- What changed
- Public exploit evidence changed from No public exploit to Public exploit reference.
- Why it matters
- Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- vm2: 3.12.1
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →22CVE-2026-54670WeGIA: Unauthenticated Auth Bypass + Local File InclusionLabRedesCefetRJ · WeGIASelected for: New public exploit evidence · Public exploit evidence · Unauthenticated network path · Verified patchCritical⌄
Published Critical 9.1 · EPSS 0.69%
- What changed
- Public exploit evidence changed from No public exploit to Public exploit reference.
- Why it matters
- Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- 3.8.5.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →23CVE-2026-77254MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentialssooperset · mcp-atlassianSelected for: Published this week · New public exploit evidence · Public exploit evidence · Unauthenticated network pathCritical⌄
Published Critical 9.1 · EPSS 0.61%
- What changed
- Public exploit evidence changed from Public exploit reference to Public exploit reference.
- Why it matters
- Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- 0.22.0.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →24CVE-2026-96757orval before 8.29.0 Code Injection via unescaped OpenAPI media-typeorval-labs · orvalSelected for: Published this week · New public exploit evidence · Public exploit evidence · Unauthenticated network pathCritical⌄
Published Critical 9.3 · EPSS 0.57%
- What changed
- Public exploit evidence changed from No public exploit to Public exploit reference.
- Why it matters
- Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- orval: 8.29.0
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →25CVE-2026-46649Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpointlaurent22 · joplinSelected for: New public exploit evidence · Public exploit evidence · Unauthenticated network path · Verified patchCritical⌄
Published Critical 9.1 · EPSS 0.56%
- What changed
- Public exploit evidence changed from No public exploit to Public exploit reference.
- Why it matters
- Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.
- Patch action
- Patch available. Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
- Fixed version
- 3.7.2.
Mitigate: Within 3 days · Remediate: Within 90 days
Open the complete evidence →