{"date_iso":"2026-09-20","date_human":"Sunday, September 20, 2026","generated_utc":"2026-09-20 16:45 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"An undercover Google analyst infiltrated a notorious supply-chain hacking gang","link":"https://arstechnica.com/security/2026/09/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/","reason":"Google","category":"Media","sources":["Ars Technica Security","CCCS Alerts & Advisories","Cyber Security News","The Hacker News","Wired Security"],"coverage":5,"cve_ids":[],"summary":"Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs\u2026","source":"Ars Technica Security","date_rel":"5h ago","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2026/09/GettyImages-2216350484-500x500.jpg","description":"Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune -themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies. Now Google\u2019s threat intelligence group has revealed that during a key moment of TeamPCP\u2019s rampage, the company\u2019s own undercover researcher had infiltrated\u2026","related":[{"title":"Google Gemini AI Hacked 3 Real Companies during a Cybersecurity Test","link":"https://cybersecuritynews.com/google-gemini-ai-hacked-3-real-companies/","source":"Cyber Security News","date_rel":"19 Sep"},{"title":"Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up","link":"https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html","source":"The Hacker News","date_rel":"19 Sep"},{"title":"An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang","link":"https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/","source":"Wired Security","date_rel":"18 Sep"},{"title":"Google security advisory (AV26-939)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-939","source":"CCCS Alerts & Advisories","date_rel":"18 Sep"}]},{"title":"CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks","link":"https://cybersecuritynews.com/linux-kernel-vulnerabilities-actively-exploited/","reason":"Linux","category":"News","sources":["CISA Alerts & Advisories","Cyber Security News","The Hacker News","Zero Day Initiative"],"coverage":4,"cve_ids":["CVE-2025-39682","CVE-2025-39964","CVE-2026-53266"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting three Linux kernel vulnerabilities, creating an urgent patching and investigation deadline. CISA added\u2026","source":"Cyber Security News","date_rel":"19 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Linux-Kernel-Vulnerabilities-Actively-Exploited.webp","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting three Linux kernel vulnerabilities, creating an urgent patching and investigation deadline. CISA added CVE-2025-39682 , CVE-2026-53266 , and CVE-2025-39964 to its Known Exploited Vulnerabilities catalog on September 18, 2026, with remediation required by September 21 under Binding Operational Directive 26-04. The KEV catalog tracks vulnerabilities exploited in real-world attacks, while BOD 26-04 requires covered federal civilian agencies to accelerate remediation based on\u2026","related":[{"title":"CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild","link":"https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html","source":"The Hacker News","date_rel":"19 Sep"},{"title":"Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root","link":"https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html","source":"The Hacker News","date_rel":"18 Sep"},{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"18 Sep"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"18 Sep"},{"title":"ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-715/","source":"Zero Day Initiative","date_rel":"18 Sep"}]},{"title":"TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories","link":"https://cybersecuritynews.com/tanstack-supply-chain-attack/","reason":"Github","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"CrowdSec has disclosed that attackers copied about 170 private GitHub repositories after a former employee\u2019s account was compromised through May\u2019s TanStack npm supply chain attack. The May 22 theft remained undetected\u2026","source":"Cyber Security News","date_rel":"19 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/TanStack-Supply-Chain-Attack.webp","description":"CrowdSec has disclosed that attackers copied about 170 private GitHub repositories after a former employee\u2019s account was compromised through May\u2019s TanStack npm supply chain attack. The May 22 theft remained undetected until stolen source code appeared on a cybercrime forum on September 16, showing how a poisoned dependency can outlive its infection window and undermine developer identities. Data Leak Claim The incident traces to CVE-2026-45321 , the compromise of TanStack\u2019s Router and Start ecosystem. On May 11, the threat actor chained an unsafe pull_request_target workflow, GitHub Actions\u2026","related":[{"title":"CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories","link":"https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html","source":"The Hacker News","date_rel":"19 Sep"},{"title":"Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2","link":"https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html","source":"The Hacker News","date_rel":"18 Sep"},{"title":"Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer","link":"https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/","source":"Bleeping Computer","date_rel":"18 Sep"},{"title":"AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom","link":"https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335","source":"The Register Security","date_rel":"17 Sep"}]},{"title":"BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers","link":"https://cybersecuritynews.com/bragjack-ai-agent-hijacking/","reason":"Chrome","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A new attack technique dubbed \u201cBragJack\u201d allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. Rather than bypassing\u2026","source":"Cyber Security News","date_rel":"19 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/BragJack-Attack.webp","description":"A new attack technique dubbed \u201cBragJack\u201d allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. Rather than bypassing model guardrails or hiding instructions inside web content, the proof-of-concept attacks directly supplied commands to privileged browser components, turning an assistant into a tool for theft and unauthorized actions. Forever Security researcher Gal Weizman demonstrated the technique across all five Chromium-based environments using one extension with browser-specific rules\u2026","related":[{"title":"BragJack attacks hijack AI browser agents through malicious extensions","link":"https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/","source":"Bleeping Computer","date_rel":"19 Sep"},{"title":"WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage","link":"https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html","source":"The Hacker News","date_rel":"18 Sep"}]},{"title":"Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root","link":"https://thehackernews.com/2026/09/critical-check-point-management-server.html","reason":"Check Point","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is\u2026","source":"The Hacker News","date_rel":"17 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuFSb4LQQ7e_Iz1RS0JfQEDY9G9LcQZ23RM0h6ladr56GJ6nN3kPwVoZPpNVJUyJEBmLVEyMaIxytF2XqyQs8fGjIdd_ymPjwaZA8Q8R7JiXC-srMFj0_YBd-a94juv46HZm4ie72j7PTj45veyTgOBaeuN53HvktSH3JTgasvV_Mo-RwjsTPnRLlHFVk/s1600/cp-main.jpg","description":"A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw","related":[{"title":"New Check Point flaw lets hackers execute code with root privileges","link":"https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/","source":"Bleeping Computer","date_rel":"18 Sep"},{"title":"Check Point, Kaspersky, Tanium Patch Product Vulnerabilities","link":"https://www.securityweek.com/check-point-kaspersky-tanium-patch-product-vulnerabilities/","source":"SecurityWeek","date_rel":"18 Sep"},{"title":"Check Point security advisory (AV26-933)","link":"https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-933","source":"CCCS Alerts & Advisories","date_rel":"17 Sep"}]},{"title":"Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link","link":"https://cybersecuritynews.com/click2shell-wordpress-vulnerability/","reason":"Wordpress","category":"News","sources":["Cyber Security News","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins\u2026","source":"Cyber Security News","date_rel":"19 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Click2Shell-WordPress-Vulnerability.webp","description":"WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-selected theme from the official directory, then becomes a server compromise when chained with insecure pre-activation code in a theme. WordPress addressed the Core flaw in version 7.1.1 , released September 17, 2026, as part of an update containing 11 security fixes, 17 Core bug fixes, and 19 Block\u2026","related":[{"title":"New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution","link":"https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html","source":"The Hacker News","date_rel":"18 Sep"},{"title":"In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw","link":"https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/","source":"SecurityWeek","date_rel":"18 Sep"}]},{"title":"Cisco Zero-Day Highlights API Endpoint Authentication Issues","link":"https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues","reason":"CVE-2026-76460","category":"News","sources":["CCCS Alerts & Advisories","CyberScoop","Dark Reading"],"coverage":3,"cve_ids":["CVE-2026-20192","CVE-2026-76423","CVE-2026-76460"],"summary":"The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.","source":"Dark Reading","date_rel":"18 Sep","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt9b9202e55102d483/6aad857c8cb60c3268956114/api-saifulasmee_chede-Getty-2203607940.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Cisco alerts customers to second actively exploited zero-day in as many days","link":"https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/","source":"CyberScoop","date_rel":"17 Sep"},{"title":"AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460","link":"https://cyber.gc.ca/en/alerts-advisories/al26-021-vulnerabilities-impacting-cisco-identity-services-engine-ise-cisco-ise-passive-identity-connector-ise-pic-cve-2026-20192-cve-2026-76423-cve-2026-76460","source":"CCCS Alerts & Advisories","date_rel":"17 Sep"}]},{"title":"RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall","link":"https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html","reason":"Android","category":"News","sources":["Bleeping Computer","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control\u2026","source":"The Hacker News","date_rel":"18 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5Psm8tS3JWb6ev7nZoz7YQDPIgoHj9gwbNjgjxbokxICdzRIUb5YJI-XfDx0NQgm8afhayc-Zd51hjuxqi7Sk_XxCNXoTNt7nIZWpxCBcDMLjSm3uW38HRciOu3WNtaUT0a-2NSsOX91GbXpCScryNirImMMC4lkuVysHku58maTbm9XvAwJ0-X6O_wDE/s1600/1000109602.jpg","description":"Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. \"Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses","related":[{"title":"New Android malware uses AI to steal bank logins and PINs","link":"https://www.malwarebytes.com/blog/news/2026/09/new-android-malware-uses-ai-to-steal-bank-logins-and-pins","source":"Malwarebytes Labs","date_rel":"18 Sep"},{"title":"New RatHat Android malware uses AI to automate device control","link":"https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/","source":"Bleeping Computer","date_rel":"17 Sep"}]},{"title":"SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE","link":"https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html","reason":"Solarwinds","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The\u2026","source":"The Hacker News","date_rel":"19 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXW-SaTg898BaxxlrDjSCrcm6ZYDgxoeuYCBY4QNWs6Nt5RhyphenhyphenCf4iSIyodz-7jk8rTqUT8hjlMT74dIf6ZjL_pD5NmiNbAHhsZwzw2rakJUDaU1tVeEvKw7Az3tMf34Xwh3ffToJeI1tpTQ8rAR8AvVn2XTupFgfhehb9sHClHDDGeDd4Y9z4oUf5CYPoS/s1600/solar.jpg","description":"SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. \"SolarWinds","related":[{"title":"SolarWinds security advisory (AV26-941)","link":"https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-941","source":"CCCS Alerts & Advisories","date_rel":"18 Sep"}]},{"title":"Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges","link":"https://cybersecuritynews.com/microsoft-azure-ai-foundry-vulnerability/","reason":"Azure","category":"News","sources":["Cyber Security News","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications and agents, that could have allowed an unauthenticated attacker to\u2026","source":"Cyber Security News","date_rel":"18 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-Azure-AI-Foundry-Vulnerability.webp","description":"Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications and agents, that could have allowed an unauthenticated attacker to escalate privileges over the network without any user interaction. Tracked as CVE-2026-85889 , the vulnerability carries the highest possible CVSS score of 10.0, placing it among the most severe cloud security issues disclosed this year. According to Microsoft\u2019s advisory, published on September 17, 2026, the root cause is a missing authentication check for a critical function\u2026","related":[{"title":"Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation","link":"https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html","source":"The Hacker News","date_rel":"18 Sep"},{"title":"Microsoft Patches 18 Vulnerabilities in AI, Cloud Products","link":"https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/","source":"SecurityWeek","date_rel":"18 Sep"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-93985","vendor":"Openpanel-dev","product":"openpanel","severity":"CRITICAL","score":9.9,"description":"OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can crea\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93985"},{"id":"CVE-2026-78030","vendor":"HashiCorp","product":"","severity":"CRITICAL","score":9.8,"description":"DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.\n\nDBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a modul\u2026","cwe":"CWE-470","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78030"},{"id":"CVE-2026-94083","vendor":"OISF","product":"Suricata","severity":"CRITICAL","score":9.4,"description":"Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This r\u2026","cwe":"CWE-843","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94083"},{"id":"CVE-2026-94084","vendor":"OISF","product":"Suricata","severity":"CRITICAL","score":9.4,"description":"Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.","cwe":"CWE-416","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94084"},{"id":"CVE-2026-93958","vendor":"D-Link","product":"R95","severity":"CRITICAL","score":9.1,"description":"A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can \u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93958"},{"id":"CVE-2026-93993","vendor":"mistralai","product":"mistral-vibe","severity":"HIGH","score":8.8,"description":"Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes ar\u2026","cwe":"CWE-829","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93993"},{"id":"CVE-2026-86553","vendor":"ZTE","product":"SmartLife","severity":"HIGH","score":8.8,"description":"SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /a\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86553"},{"id":"CVE-2026-93962","vendor":"Unknown","product":"Kamailio","severity":"HIGH","score":8.3,"description":"A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead \u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93962"},{"id":"CVE-2026-93992","vendor":"GopeedLab","product":"gopeed","severity":"HIGH","score":8.1,"description":"Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing direct\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93992"},{"id":"CVE-2026-93991","vendor":"argoproj","product":"argo-workflows","severity":"HIGH","score":7.7,"description":"Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Atta\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93991"}],"vendor_spikes":[{"vendor":"WordPress","count":20,"critical_count":0},{"vendor":"aiyiyi121","count":7,"critical_count":0},{"vendor":"ZTE","count":5,"critical_count":0},{"vendor":"Openpanel-dev","count":4,"critical_count":1},{"vendor":"Unknown","count":4,"critical_count":0},{"vendor":"Exim","count":4,"critical_count":0},{"vendor":"SourceCodester","count":4,"critical_count":0},{"vendor":"Red Hat","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":13,"new_cve_count":74,"has_news_data":true,"has_cve_data":true}