Skip to content
BLACKMESA.CA Brief

Saturday, October 3, 2026 · generated · about 5 min read

Morning Brief

Patch today vendors with the most new CVEs today

Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.

Top developments ranked by cross-source trending

  1. Image: Cyber Security News

    Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel

    News Cyber Security News23h ago9 sources

    Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users. The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code collection, and preparation to access additional systems. The investigation did not establish how the attackers first entered the environment or identify a named malware family. The available records describe a toolkit rather than…

    Also in Infosecurity Magazine The Record SecurityWeek +3

    View on Security Feed

  2. Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks

    News Cyber Security News9h ago4 sources

    GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9 and affects self-hosted deployments used to support GitLab Duo AI features. The company released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue. GitLab strongly recommends that customers running affected self-hosted gateways upgrade immediately. It also contacted self-hosted AI Gateway customers before publishing its security advisory to provide early…

    Also in CCCS Alerts & Advisories The Hacker News Bleeping Computer

    CVE-2026-90970 ↗View on Security Feed

  3. Citrix NetScaler Keeps Rebooting Following the 0-Day Patch

    News Cyber Security News10h ago4 sources

    Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency update released for two zero-day flaws under active attack. The failures appear linked to crafted SAML authentication traffic that crashes the nsaaad service. Citrix says its engineering and support teams are tracking a newly seen SAML issue and plan to release a fresh security bulletin and fixed build. The key point is that the reboot reports do not yet prove attackers have bypassed the September patch. Build 14.1-73.37 remains Citrix’s fixed 14.1 release for CVE-2026-88771…

    Also in Dark Reading The Hacker News Palo Alto Unit 42

    CVE-2026-88771 ↗CVE-2026-88772 ↗View on Security Feed

  4. Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Escalation Attacks

    News Cyber Security News11h ago3 sources

    Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaws that could allow privilege escalation, denial of service, and information leaks. The fixes are available for Debian’s stable release, Trixie, in Linux source package version 6.12.111-1. Security team member Salvatore Bonaccorso published advisory DSA-6528-1 on September 29, 2026. Debian recommends upgrading the affected linux packages. Importantly, the update prevents potential attacks; the advisory does not say that installing it causes security problems or that attackers have exploited…

    Also in Dark Reading Rapid7 Blog

    View on Security Feed

  5. Fortinet sounds the alarm over actively exploited FortiMail zero-day

    News The Register Security2 Oct4 sources

    Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing…

    Also in SecurityWeek Bleeping Computer CISA Alerts & Advisories

    CVE-2026-104286 ↗View on Security Feed

  6. Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control

    News Cyber Security News9h ago3 sources

    Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Modules, including flaws that could allow unauthenticated remote attackers to take full administrative control of affected storage environments. Organizations using vulnerable Dell CSM deployments should upgrade immediately, as Dell stated that no workarounds or mitigations are available. The advisory affects Dell Container Storage Modules versions before 1.17.0, with fixes available in 1.18.0 and later, covering CSM Authorization, CSM Operator, CSI components, and third-party…

    Also in The Hacker News Bleeping Computer

    View on Security Feed

  7. CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

    News The Hacker News1 Oct4 sources

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with

    Also in Infosecurity Magazine CCCS Alerts & Advisories The Hacker News +1

    CVE-2026-76504 ↗View on Security Feed

  8. Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

    News The Hacker News1 Oct4 sources

    Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,

    Also in CCCS Alerts & Advisories Dark Reading Infosecurity Magazine

    View on Security Feed

  9. Apple changes full-disk access permissions to curb abuse from AI agents

    Media Ars Technica Security14h ago2 sources

    Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories. Friday's announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to…

    Also in The Hacker News

    CVE-2026-86950 ↗View on Security Feed

  10. RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail

    News Dark Reading17h ago2 sources

    The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.

    Also in Microsoft Security Blog

    View on Security Feed

Vulnerability watch what to look at, most urgent first

Details CVEProductSeverity CVSSEPSS KEVFixIn the news
Highest scoring today 10new CVEs, highest CVSS first
CVE-2026-104610 HG7Tenda Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-103956 loomAWS Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-90970 GitLab AI GatewayGitLab Critical 9.9 — — None linked story 2, 4 sources CVSS 9.9No fix linkedin the news
CVE-2026-82041 UTMStackUTMStack Critical 9.9 — — None linked — CVSS 9.9No fix linked
CVE-2026-105080 ConvertXC4illin Critical 9.9 — — None linked — CVSS 9.9No fix linked
CVE-2026-97637 JSON API AuthWordPress Critical 9.8 0.6% — None linked — EPSS 0.6%CVSS 9.8No fix linked
CVE-2026-94541 WPMobile.App – Android and iOS App BuilderApple Critical 9.8 0.5% — None linked — EPSS 0.5%CVSS 9.8No fix linked
CVE-2026-19652 Divi MembershipWordPress Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-104846 serovallxsmnsyc Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2023-54405 CVMH3C Critical 9.8 — — None linked — CVSS 9.8No fix linked

Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed

Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.

Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.