{"date_iso":"2026-09-27","date_human":"Sunday, September 27, 2026","generated_utc":"2026-09-27 17:39 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory","link":"https://cybersecuritynews.com/windows-process-injection-evades-edr/","reason":"Windows","category":"News","sources":["Cyber Security News","Malwarebytes Labs","Microsoft Security","SecurityWeek","The Register Security"],"coverage":5,"cve_ids":["CVE-2026-85921"],"summary":"A Windows process injection method disclosed by security researcher Two Seven One Three sidesteps two APIs closely associated with remote code injection: VirtualAllocEx and WriteProcessMemory . Dubbed console named-pipe\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Windows-Process-Injection-Evades-EDR.webp","description":"A Windows process injection method disclosed by security researcher Two Seven One Three sidesteps two APIs closely associated with remote code injection: VirtualAllocEx and WriteProcessMemory . Dubbed console named-pipe injection, the technique delivers payload bytes through a child console process\u2019s redirected standard input and repurposes memory Windows has already populated. It can disrupt detections built around the familiar allocate-write-execute sequence. Process injection executes arbitrary code inside another process, potentially masking activity behind a legitimate application. MITRE\u2026","related":[{"title":"Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection","link":"https://cybersecuritynews.com/local-ai-bypasses-edr/","source":"Cyber Security News","date_rel":"26 Sep"},{"title":"New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining","link":"https://www.securityweek.com/new-x47-c-windows-botnet-weaponizes-xai-grok-ai-api-draining/","source":"SecurityWeek","date_rel":"26 Sep"},{"title":"Crooks use fake desktop apps to fool HR staff into giving them remote access","link":"https://www.theregister.com/security/2026/09/25/crooks-use-fake-desktop-apps-to-fool-hr-staff-into-giving-them-remote-access/5299226","source":"The Register Security","date_rel":"25 Sep"},{"title":"Kothamine malware uses Tailscale\u2019s tailcat to evade network detection","link":"https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection","source":"Malwarebytes Labs","date_rel":"25 Sep"},{"title":"Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems","link":"https://cybersecuritynews.com/samsung-flaw/","source":"Cyber Security News","date_rel":"25 Sep"},{"title":"CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921","source":"Microsoft Security","date_rel":"25 Sep"}]},{"title":"Citrix Confirms NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attack","link":"https://cybersecuritynews.com/citrix-confirms-netscaler-0-day/","reason":"Citrix","category":"News","sources":["Bleeping Computer","Cyber Security News","Tenable Blog","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-88771","CVE-2026-88772"],"summary":"Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming that attackers are exploiting two critical remote code execution vulnerabilities against unmitigated appliances\u2026","source":"Cyber Security News","date_rel":"57m ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Citrix-Confirms-NetScaler-0-Day.webp","description":"Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming that attackers are exploiting two critical remote code execution vulnerabilities against unmitigated appliances. The flaws, CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4.0 score of 9.5 and can let remote, unauthenticated adversaries execute code, placing internet-facing gateways at immediate risk. Because these appliances sit at the network edge and broker trusted traffic, successful exploitation may provide a powerful foothold for lateral movement and credential theft. The\u2026","related":[{"title":"Citrix confirms two NetScaler RCE zero-days exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities","link":"https://www.tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities","source":"Tenable Blog","date_rel":"8h ago"},{"title":"Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation","link":"https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html","source":"The Hacker News","date_rel":"9h ago"},{"title":"Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks","link":"https://cybersecuritynews.com/citrix-netscaler-0-day-rce-2/","source":"Cyber Security News","date_rel":"13h ago"}]},{"title":"SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild","link":"https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing\u2026","source":"The Hacker News","date_rel":"26 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHEPamtRBBEzltsUWnj-F8umrMf4eUUhTmGUJdhHlrvWZamHWpBtXcrpQKDArTziRiiIWv8psX4DTZyN9kLBtcAyLOPJma9_M7sYKgYz6WBISbOhJrRlfByfCKfTTMdBqaYUp-0nskrt2ndt3poUFLDGegEFJojS0EzEvwAqzaUNtvX26jZopYE4zA4S3K/s1600/share-kev.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint","related":[{"title":"Microsoft pauses KB5002907 update after Office license deactivations","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-365-kb5002907-update-paused-after-office-license-deactivations/","source":"Bleeping Computer","date_rel":"26 Sep"},{"title":"16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records","link":"https://cybersecuritynews.com/microsoft-auth-vulnerability-expose-records/","source":"Cyber Security News","date_rel":"26 Sep"},{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 4","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"25 Sep"},{"title":"Podcast: OpenAI Admits AI is Killing the Internet","link":"https://www.404media.co/podcast-openai-admits-ai-is-killing-the-internet/","source":"404 Media","date_rel":"25 Sep"}]},{"title":"Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link","link":"https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html","reason":"Wordpress","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","CISA Alerts & Advisories","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-87902"],"summary":"Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control\u2026","source":"The Hacker News","date_rel":"26 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoCsmpn_im_gimeko6yEdebgucFfzjRrTH0Hmvl1triNXT64w_JdoBIqCrFEApRZ9mmKBYfJQ1fqgfubPH3ZRaWW7SJ2HSr18mBsjSdFE6AwVl362SwcdzHp0EtlL2qoVuYARkSKmOqQaORUjjYVAM-PCT9Itvvkgb69lyVLttezAFtAuCw86RpPu3lAo4/s1600/wordpress-ele.jpg","description":"Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions","related":[{"title":"WordPress security advisory (AV26-952) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-952","source":"CCCS Alerts & Advisories","date_rel":"25 Sep"},{"title":"Elementor WordPress flaw lets attackers create admin accounts","link":"https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/","source":"Bleeping Computer","date_rel":"25 Sep"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"25 Sep"}]},{"title":"F-Droid 2.0 Released After 10 years With Major Redesign to Transform Open-Source Android App Discovery","link":"https://cybersecuritynews.com/f-droid-2-0-released/","reason":"Android","category":"News","sources":["Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"F-Droid has released version 2.0 of its official Android app, delivering its largest client update in a decade. The open-source Android app repository said the release follows more than a year of development and 14 test\u2026","source":"Cyber Security News","date_rel":"26 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/F-Droid-2.0-Released-After-10-years-With-Major-Redesign-to-Transform-Open-Source-Android-App-Discovery.webp","description":"F-Droid has released version 2.0 of its official Android app, delivering its largest client update in a decade. The open-source Android app repository said the release follows more than a year of development and 14 test builds, with a staged rollout planned over the coming weeks. Unlike a basic visual refresh, F-Droid 2.0 rebuilds major parts of the app with Kotlin and Jetpack Compose. The change modernizes the codebase, aligns the interface more closely with Android\u2019s Material Design patterns, and is intended to make future maintenance, testing, and feature development easier. The redesigned\u2026","related":[{"title":"OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services","link":"https://cybersecuritynews.com/oneplus-15-flaws-zero-permission-apps/","source":"Cyber Security News","date_rel":"25 Sep"},{"title":"Windows, Linux, Android File Notification Systems Leak User Activity","link":"https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/","source":"SecurityWeek","date_rel":"25 Sep"},{"title":"RemControl Banking Trojan Gives Attackers Remote Control of Android Devices","link":"https://www.infosecurity-magazine.com/news/banking-trojan-remote-control/","source":"Infosecurity Magazine","date_rel":"25 Sep"},{"title":"Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions","link":"https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html","source":"The Hacker News","date_rel":"24 Sep"}]},{"title":"Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks","link":"https://www.securityweek.com/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks/","reason":"CVE-2026-65660","category":"News","sources":["CISA Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-65660","CVE-2026-67279"],"summary":"CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.","source":"SecurityWeek","date_rel":"8h ago","thumbnail":"","description":"","related":[{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"25 Sep"}]},{"title":"Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials","link":"https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html","reason":"Cloudflare","category":"News","sources":["Bleeping Computer","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjlKEfNLMvV7mEVtxmw1nS48l0bWRxvhvRH5MHdn20FjDTm6B0_5okfLjQ49AamYo9DPVC1aV1O2bl11Vd8776ziWsV96tcxQviDK0RjOnGK_Dyx_Zs2e2VBjgChf91_H2cHH0u_UoyAGlGlJkKnozWFqf-sxmXNW0QlnfY3Ilgdkg3p4qG7p3Z0SmdnJMq/s1600/stealer-malware.jpg","description":"The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. \"The attack chain begins with a fake CAPTCHA page and","related":[{"title":"Cloudflare fixes Containers cross-tenant flaw exposing customer data","link":"https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data","link":"https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html","source":"The Hacker News","date_rel":"25 Sep"}]},{"title":"Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells","link":"https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html","reason":"Google","category":"News","sources":["Dark Reading","The Hacker News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the\u2026","source":"The Hacker News","date_rel":"26 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYN2VWIT2g8mQkV0GeZWzYErKcubb0-baI8J__2nmdElucECc7HrLkdPsR1dz93qjMBI5sr_dL8yPWHf2bwWCBXa3YfutHAeJ-70UCSMuJrHhyOB3RO4OkuDjuw7gxRLXUnK-CeK9jZO0uOJRy-N3w-rV7uZ4t1FnFIWNjEsKtSYQINUvPX31mKzV_5Ert/s1600/oracle-flaw.jpg","description":"Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day","related":[{"title":"Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script","link":"https://www.theregister.com/security/2026/09/25/fake-google-security-team-ad-says-no-script-reading-in-voice-phishing-then-prints-the-script/5299264","source":"The Register Security","date_rel":"25 Sep"},{"title":"What We Missed: Google Gemini Joins the AI Escape Party","link":"https://www.darkreading.com/cyber-risk/what-we-missed-google-gemini-ai-escape-party","source":"Dark Reading","date_rel":"25 Sep"}]},{"title":"Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing","link":"https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958","reason":"Salesforce","category":"News","sources":["Dark Reading","Infosecurity Magazine","SecurityWeek","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents\u2019 identities. Zenity Labs uncovered\u2026","source":"The Register Security","date_rel":"24 Sep","thumbnail":"https://image.theregister.com/?imageId=5223048&width=800","description":"Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents\u2019 identities. Zenity Labs uncovered the three vulnerabilities, collectively called SalesBleed, and reported them to Salesforce, which worked with the AI agent security provider to fix the issues. While these attack chains no longer work, Zenity co-founder and CTO Michael Bargury told The Register that the vulnerabilities highlight the difficulties in controlling what agents can access - and what happens if and\u2026","related":[{"title":"Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk","link":"https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/","source":"Infosecurity Magazine","date_rel":"25 Sep"},{"title":"\u2018SalesBleed\u2019 Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration","link":"https://www.securityweek.com/salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration/","source":"SecurityWeek","date_rel":"25 Sep"},{"title":"'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing","link":"https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing","source":"Dark Reading","date_rel":"24 Sep"}]},{"title":"WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV","link":"https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html","reason":"Adobe","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-5430"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based\u2026","source":"The Hacker News","date_rel":"25 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqTAzyCx7Cezy4z5oRz-uAHvdvW1IZDrQlfIqT_ZDJ22Hvarb4lmYWkjqBDI_CngiSy2wuot68b2CgMS_0CWVZS93lYo5wqJsd5-WdFQgO3dieodXpVQiizcFjQsPzUOlVrs32zkBaHAwOyD7S4GCZ3b1d-Jyt4-ZTaMltfU0jG5dwBw5cxj880D4Cx8W0/s1600/ADOBE-CISA.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,","related":[{"title":"CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"25 Sep"},{"title":"Adobe security advisory (AV26-808) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-808","source":"CCCS Alerts & Advisories","date_rel":"24 Sep"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-100706","vendor":"kyverno","product":"kyverno","severity":"CRITICAL","score":9.9,"description":"kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAcc\u2026","cwe":"CWE-441","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100706"},{"id":"CVE-2026-100716","vendor":"froxlor","product":"froxlor","severity":"CRITICAL","score":9.9,"description":"Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\\FileDir::makeCorrectDir() contains an off-b\u2026","cwe":"CWE-59","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100716"},{"id":"CVE-2026-100717","vendor":"F5","product":"froxlor","severity":"CRITICAL","score":9.9,"description":"froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the u\u2026","cwe":"CWE-93","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100717"},{"id":"CVE-2026-100740","vendor":"D-Link","product":"DIR-895L","severity":"CRITICAL","score":9.9,"description":"A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack ma\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100740"},{"id":"CVE-2026-85984","vendor":"WordPress","product":"miniOrange OTP Login, Verification and SMS Notifications","severity":"CRITICAL","score":9.8,"description":"The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-int\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85984"},{"id":"CVE-2026-82901","vendor":"WordPress","product":"Ultra Addons for Contact Form 7","severity":"CRITICAL","score":9.8,"description":"The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes \u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82901"},{"id":"CVE-2026-100741","vendor":"Microsoft","product":"hMailServer","severity":"CRITICAL","score":9.8,"description":"Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process\u2026","cwe":"CWE-95","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100741"},{"id":"CVE-2026-100715","vendor":"froxlor","product":"froxlor","severity":"CRITICAL","score":9.6,"description":"Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed\u2026","cwe":"CWE-59","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100715"},{"id":"CVE-2026-100714","vendor":"froxlor","product":"froxlor","severity":"CRITICAL","score":9.1,"description":"Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into\u2026","cwe":"CWE-88","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100714"},{"id":"CVE-2026-100721","vendor":"HashiCorp","product":"vm2","severity":"CRITICAL","score":9.0,"description":"vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100721"}],"vendor_spikes":[{"vendor":"WordPress","count":22,"critical_count":2},{"vendor":"Cap-go","count":18,"critical_count":0},{"vendor":"Microsoft","count":16,"critical_count":1},{"vendor":"Elastic","count":12,"critical_count":0},{"vendor":"froxlor","count":11,"critical_count":3},{"vendor":"AzuraCast","count":11,"critical_count":0},{"vendor":"netty","count":10,"critical_count":0},{"vendor":"siyuan-note","count":9,"critical_count":0},{"vendor":"heymrun","count":8,"critical_count":0},{"vendor":"budibase","count":7,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":12,"new_cve_count":224,"has_news_data":true,"has_cve_data":true}