{"date_iso":"2026-10-03","date_human":"Saturday, October 3, 2026","generated_utc":"2026-10-03 13:39 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel","link":"https://cybersecuritynews.com/hackers-turned-a-microsoft-sql-server/","reason":"Microsoft","category":"News","sources":["Ars Technica Security","Bleeping Computer","Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News","The Record","The Register Security","Zero Day Initiative"],"coverage":9,"cve_ids":[],"summary":"Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools\u2026","source":"Cyber Security News","date_rel":"23h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Hackers-Turned-a-Microsoft-SQL-Server-Into-a-Command-and-Data-Exfiltration-Channel.webp","description":"Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users. The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code collection, and preparation to access additional systems. The investigation did not establish how the attackers first entered the environment or identify a named malware family. The available records describe a toolkit rather than\u2026","related":[{"title":"Microsoft: AI Cuts Post-Compromise Attack Time to Minutes","link":"https://www.infosecurity-magazine.com/news/microsoft-ai-attack-time-minutes/","source":"Infosecurity Magazine","date_rel":"23h ago"},{"title":"'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries","link":"https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks","source":"The Record","date_rel":"23h ago"},{"title":"Crypto Scammers Hijack Microsoft\u2019s Official X Account","link":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/","source":"SecurityWeek","date_rel":"2 Oct"},{"title":"Microsoft\u2019s X account hacked in crypto pump-and-dump scheme","link":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/","source":"Bleeping Computer","date_rel":"2 Oct"},{"title":"Microsoft says threat actors are ahead in the early AI race","link":"https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/","source":"Bleeping Computer","date_rel":"1 Oct"},{"title":"Microsoft catches hackers exploiting Zimbra bug before disclosure","link":"https://www.theregister.com/security/2026/10/01/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/5300543","source":"The Register Security","date_rel":"1 Oct"}]},{"title":"Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks","link":"https://cybersecuritynews.com/gitlab-ai-gateway-vulnerability/","reason":"Gitlab","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-90970"],"summary":"GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9\u2026","source":"Cyber Security News","date_rel":"9h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/GitLab-AI-Gateway-Vulnerability.webp","description":"GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9 and affects self-hosted deployments used to support GitLab Duo AI features. The company released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue. GitLab strongly recommends that customers running affected self-hosted gateways upgrade immediately. It also contacted self-hosted AI Gateway customers before publishing its security advisory to provide early\u2026","related":[{"title":"GitLab security advisory (AV26-994)","link":"https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-994","source":"CCCS Alerts & Advisories","date_rel":"19h ago"},{"title":"GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers","link":"https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html","source":"The Hacker News","date_rel":"20h ago"},{"title":"GitLab warns of critical RCE vulnerability in AI Gateway service","link":"https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/","source":"Bleeping Computer","date_rel":"21h ago"}]},{"title":"Citrix NetScaler Keeps Rebooting Following the 0-Day Patch","link":"https://cybersecuritynews.com/citrix-netscaler-0-day-patch/","reason":"Citrix","category":"News","sources":["Cyber Security News","Dark Reading","Palo Alto Unit 42","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-88771","CVE-2026-88772"],"summary":"Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency update released for two zero-day flaws under active attack. The failures appear linked to crafted SAML\u2026","source":"Cyber Security News","date_rel":"10h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Citrix-NetScaler-0-Day-Patch.webp","description":"Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency update released for two zero-day flaws under active attack. The failures appear linked to crafted SAML authentication traffic that crashes the nsaaad service. Citrix says its engineering and support teams are tracking a newly seen SAML issue and plan to release a fresh security bulletin and fixed build. The key point is that the reboot reports do not yet prove attackers have bypassed the September patch. Build 14.1-73.37 remains Citrix\u2019s fixed 14.1 release for CVE-2026-88771\u2026","related":[{"title":"Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response","link":"https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response","source":"Dark Reading","date_rel":"20h ago"},{"title":"Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs","link":"https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html","source":"The Hacker News","date_rel":"1 Oct"},{"title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","link":"https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/","source":"Palo Alto Unit 42","date_rel":"30 Sep"}]},{"title":"Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Escalation Attacks","link":"https://cybersecuritynews.com/debian-1313-security-flaws/","reason":"Linux","category":"News","sources":["Cyber Security News","Dark Reading","Rapid7 Blog"],"coverage":3,"cve_ids":[],"summary":"Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaws that could allow privilege escalation, denial of service, and information leaks. The fixes are available for Debian\u2019s\u2026","source":"Cyber Security News","date_rel":"11h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Debian-security-flaws.webp","description":"Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaws that could allow privilege escalation, denial of service, and information leaks. The fixes are available for Debian\u2019s stable release, Trixie, in Linux source package version 6.12.111-1. Security team member Salvatore Bonaccorso published advisory DSA-6528-1 on September 29, 2026. Debian recommends upgrading the affected linux packages. Importantly, the update prevents potential attacks; the advisory does not say that installing it causes security problems or that attackers have exploited\u2026","related":[{"title":"Malicious Linux Implants Mimic Asian Mail Security Products","link":"https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security","source":"Dark Reading","date_rel":"2 Oct"},{"title":"SMTP is the key: BPFDoor and AVERAT hitting the network edge","link":"https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge","source":"Rapid7 Blog","date_rel":"2 Oct"}]},{"title":"Fortinet sounds the alarm over actively exploited FortiMail zero-day","link":"https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803","reason":"CVE-2026-104286","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","SecurityWeek","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-104286"],"summary":"Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a\u2026","source":"The Register Security","date_rel":"2 Oct","thumbnail":"https://image.theregister.com/?imageId=5300807&width=800","description":"Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing\u2026","related":[{"title":"Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action","link":"https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/","source":"SecurityWeek","date_rel":"2 Oct"},{"title":"Fortinet warns of critical FortiMail flaw exploited in zero-day attacks","link":"https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/","source":"Bleeping Computer","date_rel":"1 Oct"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"1 Oct"}]},{"title":"Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control","link":"https://cybersecuritynews.com/critical-dell-container-storage-flaws/","reason":"Dell","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Modules, including flaws that could allow unauthenticated remote attackers to take full administrative\u2026","source":"Cyber Security News","date_rel":"9h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Critical-Dell-Container-Storage-Flaws-Let-Unauthenticated-Attackers-Gain-Full-Administrative-Control-1.webp","description":"Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Modules, including flaws that could allow unauthenticated remote attackers to take full administrative control of affected storage environments. Organizations using vulnerable Dell CSM deployments should upgrade immediately, as Dell stated that no workarounds or mitigations are available. The advisory affects Dell Container Storage Modules versions before 1.17.0, with fixes available in 1.18.0 and later, covering CSM Authorization, CSM Operator, CSI components, and third-party\u2026","related":[{"title":"Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes","link":"https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html","source":"The Hacker News","date_rel":"20h ago"},{"title":"Dell asks admins to patch max severity CSM flaws as soon as possible","link":"https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/","source":"Bleeping Computer","date_rel":"2 Oct"}]},{"title":"CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV","link":"https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","Rapid7 Blog","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-76504"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following\u2026","source":"The Hacker News","date_rel":"1 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8jgm3LMY2zr1S1DmXnvVEPDiTKYR5FXHW7q_6duG1lVPhzbW2ZfJwRM9glqAJrQhBX3HAAiksz-tUpRN4pfT9VWHUksa-1SgHZmKcNUd1tJfsyFiwhtezZN_zBM_cEmqjkECI_2gfWhnqZ1ry2hgDou-qQCB21zbl1RzYN9JB0bRjqzhB2m6gBomg-ow9/s1600/cisa-wan.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with","related":[{"title":"Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation","link":"https://www.infosecurity-magazine.com/news/critical-cisco-catalyst-sdwan/","source":"Infosecurity Magazine","date_rel":"1 Oct"},{"title":"Cisco security advisory (AV26-978)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-978","source":"CCCS Alerts & Advisories","date_rel":"1 Oct"},{"title":"Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager","link":"https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html","source":"The Hacker News","date_rel":"30 Sep"},{"title":"Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)","link":"https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504","source":"Rapid7 Blog","date_rel":"30 Sep"}]},{"title":"Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version","link":"https://thehackernews.com/2026/10/google-rolls-out-gemini-4-argon-to.html","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Dark Reading","Infosecurity Magazine","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. \"It delivers\u2026","source":"The Hacker News","date_rel":"1 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYk4zu5KwFghyphenhyphenGNFmUKfmtScZfRpYSwO3huCn6VYY6EiFZH7t7zWwr6Agn-AqOHA19-uc6wQMnoOHXGY3V8F2ZWfxoTNiTp8VV1ePAvDGYlW3ocD8tXLN-tPuqvzwf7YRX9CXl1_Zj2b0ZcMqbZAo_5Ut3uG3gTTEXTCVxJyyTtcUlbfwXkdqCu8PpY4l6/s1600/gemini-4.jpg","description":"Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. \"It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense,\" Koray Kavukcuoglu,","related":[{"title":"Google security advisory (AV26-984)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-984","source":"CCCS Alerts & Advisories","date_rel":"1 Oct"},{"title":"Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure","link":"https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure","source":"Dark Reading","date_rel":"30 Sep"},{"title":"AI-Found Vulnerabilities More Likely to Enable RCE, Google Says","link":"https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/","source":"Infosecurity Magazine","date_rel":"30 Sep"}]},{"title":"Apple changes full-disk access permissions to curb abuse from AI agents","link":"https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/","reason":"Apple","category":"Media","sources":["Ars Technica Security","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-86950"],"summary":"Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories. Friday's announcement comes two weeks after tech columnist Jason Aten said that\u2026","source":"Ars Technica Security","date_rel":"14h ago","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2026/02/gatekeeping-ai-agents-500x500.jpg","description":"Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories. Friday's announcement comes two weeks after tech columnist Jason Aten said that Meta\u2019s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to\u2026","related":[{"title":"Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path","link":"https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html","source":"The Hacker News","date_rel":"1 Oct"}]},{"title":"RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail","link":"https://www.darkreading.com/cybersecurity-operations/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail","reason":"Teams","category":"News","sources":["Dark Reading","Microsoft Security Blog"],"coverage":2,"cve_ids":[],"summary":"The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.","source":"Dark Reading","date_rel":"17h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltf31fc70ff522da98/6ac0148dfc9ca54499deca08/GettyImages-2207912388.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Insights from the 2026 Microsoft Digital Defense Report","link":"https://www.microsoft.com/en-us/security/blog/2026/10/01/insights-from-the-2026-microsoft-digital-defense-report/","source":"Microsoft Security Blog","date_rel":"1 Oct"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-104610","vendor":"Tenda","product":"HG7","severity":"CRITICAL","score":10.0,"description":"A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads \u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/Expl0rer-Ct/CVE/issues/1","https://vuldb.com/cve/CVE-2026-104610","https://vuldb.com/submit/962541"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-104610"},{"id":"CVE-2026-103956","vendor":"AWS","product":"loom","severity":"CRITICAL","score":10.0,"description":"Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading store\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://aws.amazon.com/security/security-bulletins/2026-124-aws/","https://github.com/awslabs/loom/releases/tag/v1.6.1","https://github.com/awslabs/loom/security/advisories/GHSA-vgmj-998f-r8mp"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-103956"},{"id":"CVE-2026-90970","vendor":"GitLab","product":"GitLab AI Gateway","severity":"CRITICAL","score":9.9,"description":"GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an au\u2026","cwe":"CWE-1336","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://gitlab.com/gitlab-org/gitlab/-/work_items/628842"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-90970"},{"id":"CVE-2026-82041","vendor":"UTMStack","product":"UTMStack","severity":"CRITICAL","score":9.9,"description":"UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied bef\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/UTMStack/UTMStack/releases/tag/v11.2.16","https://github.com/utmstack/UTMStack/commit/4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd","https://www.vulncheck.com/advisories/utmstack-missing-authorization-via-command-websocket"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-82041"},{"id":"CVE-2026-105080","vendor":"C4illin","product":"ConvertX","severity":"CRITICAL","score":9.9,"description":"In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.","cwe":"CWE-829","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/C4illin/ConvertX/commit/0ca17dad7fa65e2e34823b59b95dd00bb1066b66","https://github.com/C4illin/ConvertX/releases/tag/v0.19.0","https://github.com/C4illin/ConvertX/security/advisories/GHSA-m4hh-rqmf-c8hw"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105080"},{"id":"CVE-2026-97637","vendor":"WordPress","product":"JSON API Auth","severity":"CRITICAL","score":9.8,"description":"The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin ca\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0064,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://plugins.trac.wordpress.org/browser/json-api-auth/tags/3.1.2/controllers/Auth.php#L104","https://plugins.trac.wordpress.org/browser/json-api-auth/tags/3.1.2/controllers/Auth.php#L28","https://plugins.trac.wordpress.org/browser/json-api-auth/tags/3.1.2/controllers/Auth.php#L66"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-97637"},{"id":"CVE-2026-94541","vendor":"Apple","product":"WPMobile.App \u2013 Android and iOS App Builder","severity":"CRITICAL","score":9.8,"description":"The WPMobile.App \u2013 Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an a\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0049,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/api/push.php#L467","https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/api/read_enhanced.php#L171","https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/common/deeplinking.php#L249"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-94541"},{"id":"CVE-2026-19652","vendor":"WordPress","product":"Divi Membership","severity":"CRITICAL","score":9.8,"description":"The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress role\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://diviengine.com/divi-membership-changelog/","https://diviengine.com/product/divi-membership/","https://www.wordfence.com/threat-intel/vulnerabilities/id/81d46c7a-dfe4-4991-99cc-66e5c6d3e3c8?source=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-19652"},{"id":"CVE-2026-104846","vendor":"lxsmnsyc","product":"seroval","severity":"CRITICAL","score":9.8,"description":"Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing\u2026","cwe":"CWE-843","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/lxsmnsyc/seroval/commit/f1ffcc96d259f9b5b3d71feb262b58240c90e7b7","https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-p6vx-979v-rg4c"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-104846"},{"id":"CVE-2023-54405","vendor":"H3C","product":"CVM","severity":"CRITICAL","score":9.8,"description":"H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary fil\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://blog.csdn.net/qq_41904294/article/details/134697278","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/other/h3c-cvm-arbitrary-file-upload.yaml","https://www.h3c.com/en/Support/Resource_Center/EN/Cloud_Computing/Catalog/H3C_CAS/H3C_CAS/Technical_Documents/Configure___Deploy/User_Manuals/H3C_CAS_CVM_UG_E0785-21554/?CHID=1087104"],"url":"https://cve.blackmesa.ca/?q=CVE-2023-54405"}],"vendor_spikes":[{"vendor":"WordPress","count":80,"critical_count":2},{"vendor":"Apache","count":69,"critical_count":1},{"vendor":"YesWiki","count":35,"critical_count":0},{"vendor":"Legion of the Bouncy Castle Inc.","count":16,"critical_count":0},{"vendor":"Repasat","count":16,"critical_count":0},{"vendor":"ZcashFoundation","count":15,"critical_count":0},{"vendor":"Unknown","count":14,"critical_count":0},{"vendor":"Google","count":11,"critical_count":1},{"vendor":"Microsoft","count":9,"critical_count":0},{"vendor":"HashiCorp","count":7,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":19,"new_cve_count":407,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-90970":{"anchor":"#dev-2","rank":2,"coverage":4},"CVE-2026-88771":{"anchor":"#dev-3","rank":3,"coverage":4},"CVE-2026-88772":{"anchor":"#dev-3","rank":3,"coverage":4},"CVE-2026-104286":{"anchor":"#dev-5","rank":5,"coverage":4},"CVE-2026-76504":{"anchor":"#dev-7","rank":7,"coverage":4},"CVE-2026-86950":{"anchor":"#dev-9","rank":9,"coverage":2}}}