{"date_iso":"2026-10-04","date_human":"Sunday, October 4, 2026","generated_utc":"2026-10-04 14:19 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing","link":"https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News","The Record","The Register Security"],"coverage":7,"cve_ids":[],"summary":"A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgR69JnEBkz8N6_Nd5K75adIWh8xVmxW8FB21gsKinx9HBzgXQSLWL5sYdKMe9d-cbTSrgc45ZtYhmvhLZJII1H-tPXKn4AiRvj4KrU8ayeZskmMCfiV-mUc2pz10MumKyXKH6ybJ2RsVj9ZZ67l-4u0Y2f5Dl3kX7PLEzCAqogMfHTSfD7gM7QypHi-yos/s1600/china-ms.jpg","description":"A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a","related":[{"title":"Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware","link":"https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html","source":"The Hacker News","date_rel":"23h ago"},{"title":"Microsoft: AI Cuts Post-Compromise Attack Time to Minutes","link":"https://www.infosecurity-magazine.com/news/microsoft-ai-attack-time-minutes/","source":"Infosecurity Magazine","date_rel":"2 Oct"},{"title":"'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries","link":"https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks","source":"The Record","date_rel":"2 Oct"},{"title":"Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel","link":"https://cybersecuritynews.com/hackers-turned-a-microsoft-sql-server/","source":"Cyber Security News","date_rel":"2 Oct"},{"title":"Crypto Scammers Hijack Microsoft\u2019s Official X Account","link":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/","source":"SecurityWeek","date_rel":"2 Oct"},{"title":"Microsoft\u2019s X account hacked in crypto pump-and-dump scheme","link":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/","source":"Bleeping Computer","date_rel":"2 Oct"}]},{"title":"Citrix NetScaler Keeps Rebooting Following the 0-Day Patch","link":"https://cybersecuritynews.com/citrix-netscaler-0-day-patch/","reason":"Citrix","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","Dark Reading"],"coverage":3,"cve_ids":["CVE-2026-88771","CVE-2026-88772"],"summary":"Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency update released for two zero-day flaws under active attack. The failures appear linked to crafted SAML\u2026","source":"Cyber Security News","date_rel":"3 Oct","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Citrix-NetScaler-0-Day-Patch.webp","description":"Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency update released for two zero-day flaws under active attack. The failures appear linked to crafted SAML authentication traffic that crashes the nsaaad service. Citrix says its engineering and support teams are tracking a newly seen SAML issue and plan to release a fresh security bulletin and fixed build. The key point is that the reboot reports do not yet prove attackers have bypassed the September patch. Build 14.1-73.37 remains Citrix\u2019s fixed 14.1 release for CVE-2026-88771\u2026","related":[{"title":"AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway \u2013 CVE-2026-88771 and CVE-2026-88772 \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772","source":"CCCS Alerts & Advisories","date_rel":"18h ago"},{"title":"Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response","link":"https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response","source":"Dark Reading","date_rel":"2 Oct"}]},{"title":"Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks","link":"https://cybersecuritynews.com/gitlab-ai-gateway-vulnerability/","reason":"Gitlab","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-90970"],"summary":"GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9\u2026","source":"Cyber Security News","date_rel":"3 Oct","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/GitLab-AI-Gateway-Vulnerability.webp","description":"GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9 and affects self-hosted deployments used to support GitLab Duo AI features. The company released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue. GitLab strongly recommends that customers running affected self-hosted gateways upgrade immediately. It also contacted self-hosted AI Gateway customers before publishing its security advisory to provide early\u2026","related":[{"title":"GitLab security advisory (AV26-994)","link":"https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-994","source":"CCCS Alerts & Advisories","date_rel":"2 Oct"},{"title":"GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers","link":"https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html","source":"The Hacker News","date_rel":"2 Oct"},{"title":"GitLab warns of critical RCE vulnerability in AI Gateway service","link":"https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/","source":"Bleeping Computer","date_rel":"2 Oct"}]},{"title":"ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members","link":"https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html","reason":"Shinyhunters Reportedly Detained","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A suspected member of the ShinyHunters digital extortion group, who goes by the online alias \"Rey,\" has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkLNgAfzHHwGX_2W-2iGuIMpKX_ZOPM0xFYMFDUp5kxBp3XfaRHV0EUwHsbvh45q8wVSYvblXfru1NzEKovvRqXHDNA82iWx6IbY_ihCrucvF5Bkr1JU8bVJ9KDzUi0wG1GRYvyPNb-1LcXTWzBhqLS5kRo9o2zf3DnqqcTNqk5gTtfbdC57w5SZnomx5U/s1600/shinyhunters-arrested.jpg","description":"A suspected member of the ShinyHunters digital extortion group, who goes by the online alias \"Rey,\" has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif \u200cal-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and","related":[{"title":"ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers","link":"https://cybersecuritynews.com/shinyhunters-hacker-helping-fbi/","source":"Cyber Security News","date_rel":"20h ago"}]},{"title":"Google Gemini could soon get full access to your Mac\u2019s files, apps and the web","link":"https://www.bleepingcomputer.com/news/google/google-gemini-could-soon-get-full-access-to-your-macs-files-apps-and-the-web/","reason":"Google","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories"],"coverage":2,"cve_ids":[],"summary":"Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time.","source":"Bleeping Computer","date_rel":"15h ago","thumbnail":"","description":"","related":[{"title":"Google security advisory (AV26-984)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-984","source":"CCCS Alerts & Advisories","date_rel":"1 Oct"}]},{"title":"Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Escalation Attacks","link":"https://cybersecuritynews.com/debian-1313-security-flaws/","reason":"Linux","category":"News","sources":["Cyber Security News","Dark Reading","Rapid7 Blog"],"coverage":3,"cve_ids":[],"summary":"Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaws that could allow privilege escalation, denial of service, and information leaks. The fixes are available for Debian\u2019s\u2026","source":"Cyber Security News","date_rel":"3 Oct","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Debian-security-flaws.webp","description":"Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaws that could allow privilege escalation, denial of service, and information leaks. The fixes are available for Debian\u2019s stable release, Trixie, in Linux source package version 6.12.111-1. Security team member Salvatore Bonaccorso published advisory DSA-6528-1 on September 29, 2026. Debian recommends upgrading the affected linux packages. Importantly, the update prevents potential attacks; the advisory does not say that installing it causes security problems or that attackers have exploited\u2026","related":[{"title":"Malicious Linux Implants Mimic Asian Mail Security Products","link":"https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security","source":"Dark Reading","date_rel":"2 Oct"},{"title":"SMTP is the key: BPFDoor and AVERAT hitting the network edge","link":"https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge","source":"Rapid7 Blog","date_rel":"2 Oct"}]},{"title":"Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control","link":"https://cybersecuritynews.com/critical-dell-container-storage-flaws/","reason":"Dell","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Modules, including flaws that could allow unauthenticated remote attackers to take full administrative\u2026","source":"Cyber Security News","date_rel":"3 Oct","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Critical-Dell-Container-Storage-Flaws-Let-Unauthenticated-Attackers-Gain-Full-Administrative-Control-1.webp","description":"Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Modules, including flaws that could allow unauthenticated remote attackers to take full administrative control of affected storage environments. Organizations using vulnerable Dell CSM deployments should upgrade immediately, as Dell stated that no workarounds or mitigations are available. The advisory affects Dell Container Storage Modules versions before 1.17.0, with fixes available in 1.18.0 and later, covering CSM Authorization, CSM Operator, CSI components, and third-party\u2026","related":[{"title":"Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes","link":"https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html","source":"The Hacker News","date_rel":"2 Oct"},{"title":"Dell asks admins to patch max severity CSM flaws as soon as possible","link":"https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/","source":"Bleeping Computer","date_rel":"2 Oct"}]},{"title":"Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw","link":"https://cybersecuritynews.com/microsoft-reissues-exchange-server-update/","reason":"Exchange","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-96940"],"summary":"Microsoft has released September 2026 V2 security updates to fix an Exchange Server flaw that lets authenticated attackers access other users\u2019 mailboxes within the same organization. Tracked as CVE-2026 \u2013 96940 , the\u2026","source":"Cyber Security News","date_rel":"23h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Microsoft-Reissues-Exchange-Server-Update.webp","description":"Microsoft has released September 2026 V2 security updates to fix an Exchange Server flaw that lets authenticated attackers access other users\u2019 mailboxes within the same organization. Tracked as CVE-2026 \u2013 96940 , the vulnerability could expose email messages and attachments, making it a serious concern for businesses running Exchange on-premises. The flaw involves weak authorization, allowing an attacker with authenticated access to gain privileges over a network. Public vulnerability records list a CVSS score of 8.8. Unlike attacks that require someone to open a malicious file, exploitation\u2026","related":[{"title":"CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940","source":"Microsoft Security","date_rel":"2 Oct"}]},{"title":"Fortinet sounds the alarm over actively exploited FortiMail zero-day","link":"https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803","reason":"CVE-2026-104286","category":"News","sources":["Bleeping Computer","SecurityWeek","The Register Security"],"coverage":3,"cve_ids":["CVE-2026-104286"],"summary":"Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a\u2026","source":"The Register Security","date_rel":"2 Oct","thumbnail":"https://image.theregister.com/?imageId=5300807&width=800","description":"Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing\u2026","related":[{"title":"Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action","link":"https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/","source":"SecurityWeek","date_rel":"2 Oct"},{"title":"Fortinet warns of critical FortiMail flaw exploited in zero-day attacks","link":"https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/","source":"Bleeping Computer","date_rel":"1 Oct"}]},{"title":"Apple changes full-disk access permissions to curb abuse from AI agents","link":"https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/","reason":"Macos","category":"Media","sources":["Ars Technica Security","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories. Friday's announcement comes two weeks after tech columnist Jason Aten said that\u2026","source":"Ars Technica Security","date_rel":"2 Oct","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2026/02/gatekeeping-ai-agents-500x500.jpg","description":"Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories. Friday's announcement comes two weeks after tech columnist Jason Aten said that Meta\u2019s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to\u2026","related":[{"title":"macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor","link":"https://www.securityweek.com/macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor/","source":"SecurityWeek","date_rel":"2 Oct"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-105134","vendor":"Ahsay","product":"AhsayCBS","severity":"CRITICAL","score":10.0,"description":"A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://vuldb.com/cve/CVE-2026-105134","https://vuldb.com/submit/942743","https://vuldb.com/vuln/413351"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105134"},{"id":"CVE-2026-105135","vendor":"InternLM","product":"MindSearch","severity":"CRITICAL","score":10.0,"description":"A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code inj\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://gist.github.com/DReazer/7ad46df9da73d0cf414276e4195b2183","https://vuldb.com/cve/CVE-2026-105135","https://vuldb.com/submit/943315"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105135"},{"id":"CVE-2026-105105","vendor":"NASA-AMMOS","product":"AIT-Core","severity":"CRITICAL","score":9.8,"description":"CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message \u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/Mothra-1","https://github.com/NASA-AMMOS/AIT-Core/","https://github.com/NASA-AMMOS/AIT-Core/security/advisories/GHSA-ccw5-g774-3683"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105105"},{"id":"CVE-2026-92084","vendor":"WordPress","product":"Beaver Builder Page Builder \u2013 Drag and Drop Website Builder","severity":"CRITICAL","score":9.1,"description":"The The Beaver Builder Page Builder \u2013 Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0053,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","fix":false,"fix_url":"","refs":["https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.11.0.5/classes/class-fl-builder-module.php#L143","https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.11.0.5/classes/class-fl-builder.php#L2139","https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.11.0.5/classes/class-fl-builder.php#L2264"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-92084"},{"id":"CVE-2026-96451","vendor":"Ultimate Member","product":"Ultimate Member","severity":"HIGH","score":8.8,"description":"Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/ultimate-member/vulnerability/wordpress-ultimate-member-plugin-2-13-1-privilege-escalation-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-96451"},{"id":"CVE-2026-105123","vendor":"vincent-peugnet","product":"wcms","severity":"HIGH","score":8.8,"description":"W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .p\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/vincent-peugnet/wcms","https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Controllerapimedia.php#L24-L44","https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Media.php#L98"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105123"},{"id":"CVE-2026-105115","vendor":"OpenIdentityPlatform","product":"OpenAM","severity":"HIGH","score":8.6,"description":"OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxr\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","fix":false,"fix_url":"","refs":["https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-wxmx-q96f-w4gw","https://www.vulncheck.com/advisories/openam-before-16.1.3-unauthenticated-arbitrary-class-instantiation-via-jax-rpc-interface"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105115"},{"id":"CVE-2026-103065","vendor":"Themeum","product":"Kirki","severity":"HIGH","score":8.2,"description":"Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.","cwe":"CWE-1284","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/kirki/vulnerability/wordpress-kirki-plugin-6-3-1-arbitrary-code-execution-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-103065"},{"id":"CVE-2026-105133","vendor":"Ahsay","product":"AhsayCBS","severity":"HIGH","score":7.3,"description":"A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in imprope\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","fix":false,"fix_url":"","refs":["https://vuldb.com/cve/CVE-2026-105133","https://vuldb.com/submit/942688","https://vuldb.com/vuln/413350"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105133"},{"id":"CVE-2026-105126","vendor":"laradashboard","product":"laradashboard","severity":"HIGH","score":7.2,"description":"LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/laradashboard/laradashboard","https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L144","https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L180"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105126"}],"vendor_spikes":[{"vendor":"Legion of the Bouncy Castle Inc.","count":9,"critical_count":0},{"vendor":"OpenIdentityPlatform","count":9,"critical_count":0},{"vendor":"WordPress","count":8,"critical_count":1},{"vendor":"laradashboard","count":5,"critical_count":0},{"vendor":"Omega Solution","count":4,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":13,"new_cve_count":54,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-88771":{"anchor":"#dev-2","rank":2,"coverage":3},"CVE-2026-88772":{"anchor":"#dev-2","rank":2,"coverage":3},"CVE-2026-90970":{"anchor":"#dev-3","rank":3,"coverage":4},"CVE-2026-96940":{"anchor":"#dev-8","rank":8,"coverage":2},"CVE-2026-104286":{"anchor":"#dev-9","rank":9,"coverage":3}}}