{"date_iso":"2026-10-05","date_human":"Monday, October 5, 2026","generated_utc":"2026-10-05 23:53 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks","link":"https://cybersecuritynews.com/cisa-citrix-netscaler-vulnerability-exploited/","reason":"CVE-2026-88779","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","Cyber Security News","SecurityWeek","Sophos Threat Research"],"coverage":5,"cve_ids":["CVE-2026-88779"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency has added a Citrix NetScaler vulnerability, tracked as CVE-2026-88779 , to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/CISA-Warns-of-Citrix-NetScaler-Vulnerability-Actively-Exploited-in-Attacks-1.webp","description":"The U.S. Cybersecurity and Infrastructure Security Agency has added a Citrix NetScaler vulnerability, tracked as CVE-2026-88779 , to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw affects Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer issue, classified under CWE-119. The vulnerability could allow an attacker to trigger a denial-of-service condition on affected NetScaler appliances, potentially disrupting\u2026","related":[{"title":"Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier","link":"https://www.securityweek.com/exploitation-of-citrix-netscaler-zero-day-hits-appliances-patched-days-earlier/","source":"SecurityWeek","date_rel":"12h ago"},{"title":"Citrix NetScaler vulnerability (CVE-2026-88779) in active exploitation","link":"https://www.sophos.com/en-us/blog/citrix-netscaler-vulnerability-cve-2026-88779-in-active-exploitation","source":"Sophos Threat Research","date_rel":"17h ago"},{"title":"Citrix patches NetScaler SAML zero-day exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"19h ago"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"4 Oct"}]},{"title":"Google Gemini Will Soon Get Full Access Permission to Use Your Computer","link":"https://cybersecuritynews.com/google-gemini-computer-access/","reason":"Google","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek"],"coverage":5,"cve_ids":[],"summary":"Google\u2019s Gemini Desktop app may soon introduce a \u201cFull Access\u201d permission that would let the AI assistant read files, control applications, access network services, and take action across a user\u2019s Mac. The capability\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Google-Gemini-Will-Soon-get-Full-Access-Permission-to-Use-Your-Computer-1.webp","description":"Google\u2019s Gemini Desktop app may soon introduce a \u201cFull Access\u201d permission that would let the AI assistant read files, control applications, access network services, and take action across a user\u2019s Mac. The capability appears to be part of a hidden \u201cAdditional sandbox options\u201d setting discovered in a recent version of the Gemini Desktop app . The reported feature would significantly expand Gemini\u2019s computer-use capabilities beyond its existing role as a conversational AI assistant. If enabled, the permissions could let Gemini interact with a user\u2019s local environment in ways normally reserved\u2026","related":[{"title":"Google pauses open source bug bounty program after rise in AI submissions","link":"https://www.malwarebytes.com/blog/news/2026/10/google-pauses-open-source-bug-bounty-program-after-rise-in-ai-submissions","source":"Malwarebytes Labs","date_rel":"2h ago"},{"title":"Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports","link":"https://www.securityweek.com/google-narrows-open-source-bug-bounty-amid-wave-of-invalid-automated-reports/","source":"SecurityWeek","date_rel":"2h ago"},{"title":"Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports","link":"https://www.infosecurity-magazine.com/news/google-suspends-opensource-bug/","source":"Infosecurity Magazine","date_rel":"6h ago"},{"title":"Google halts open-source bug bounty program amid AI spam surge","link":"https://www.bleepingcomputer.com/news/google/google-halts-open-source-bug-bounty-program-amid-ai-spam-surge/","source":"Bleeping Computer","date_rel":"8h ago"},{"title":"Google Gemini could soon get full access to your Mac\u2019s files, apps and the web","link":"https://www.bleepingcomputer.com/news/google/google-gemini-could-soon-get-full-access-to-your-macs-files-apps-and-the-web/","source":"Bleeping Computer","date_rel":"3 Oct"}]},{"title":"Need for Speed: AI-Driven Attacks Are Changing Security Strategies","link":"https://www.darkreading.com/cyber-risk/ai-attacks-security-strategies","reason":"Teams","category":"News","sources":["Dark Reading","The Hacker News","Wiz Research"],"coverage":3,"cve_ids":[],"summary":"AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.","source":"Dark Reading","date_rel":"4h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt805a291660c85e6c/6abfd753b06065c7488d51a1/fighterjet-Asanka_Ratnayake-GettyImages-2207309883.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"What\u2019s New in Wiz Service Catalog: Smarter Discovery, Governance, and Service-Level Context","link":"https://www.wiz.io/blog/wiz-service-catalog-updates","source":"Wiz Research","date_rel":"1h ago"},{"title":"The Credential Layer Is Expanding Faster Than Security Teams Can See It","link":"https://thehackernews.com/2026/10/the-credential-layer-is-expanding.html","source":"The Hacker News","date_rel":"5h ago"},{"title":"RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail","link":"https://www.darkreading.com/cybersecurity-operations/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail","source":"Dark Reading","date_rel":"2 Oct"}]},{"title":"New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline","link":"https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html","reason":"Citrix","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-88771","CVE-2026-88772"],"summary":"Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as\u2026","source":"The Hacker News","date_rel":"10h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhV4of0Q-gWaIOffgWXdEfAxmI1ENcyrpDSSDjBurAHSpUuAI8lASQI5wrUvL3Evb0iqA31rRywo51olFOzoWe_lQ9cwN7Sp5QQw_2h-y44n0Va4vwlRQZipZ5fkm98BRmTOoVDPTs8pUMW_ClnH2GlPobgQQ33rNzL8EBnBW84aacH3dLXdyyLW9bBEqG5/s1600/citrix-offline.jpg","description":"Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. \"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to","related":[{"title":"Citrix NetScaler Targeted Via New Zero Day","link":"https://www.infosecurity-magazine.com/news/citrix-netscaler-zero-day/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Citrix security advisory (AV26-996)","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-996","source":"CCCS Alerts & Advisories","date_rel":"5h ago"},{"title":"AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway \u2013 CVE-2026-88771 and CVE-2026-88772 \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772","source":"CCCS Alerts & Advisories","date_rel":"3 Oct"}]},{"title":"RemoveMacAI Free Up 12GB of Data by Removing Apple Intelligence Models","link":"https://cybersecuritynews.com/removemacai-removes-ai-models/","reason":"Apple","category":"News","sources":["Ars Technica Security","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"RemoveMacAI, an open-source tool on GitHub, lets Mac users disable Apple Intelligence, remove its downloaded models, and block future downloads. The utility can recover roughly 10GB to 12GB of storage, depending on\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/RemoveMacAI-Removes-AI-Models.webp","description":"RemoveMacAI, an open-source tool on GitHub, lets Mac users disable Apple Intelligence, remove its downloaded models, and block future downloads. The utility can recover roughly 10GB to 12GB of storage, depending on which models are present. Its changes are reversible, and the removal process leaves macOS System Integrity Protection enabled. The tool addresses a storage problem in macOS 27. According to its developer, Apple removed the single switch for turning off Apple Intelligence, while disabling individual features leaves their models on disk. RemoveMacAI combines feature restrictions\u2026","related":[{"title":"Apple Tightens macOS Full Disk Access as AI Agents Become More Powerful","link":"https://cybersecuritynews.com/apple-tightens-macos-full-disk-access/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access","link":"https://thehackernews.com/2026/10/apple-plans-tighter-macos-full-disk.html","source":"The Hacker News","date_rel":"6h ago"},{"title":"Apple changes full-disk access permissions to curb abuse from AI agents","link":"https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/","source":"Ars Technica Security","date_rel":"2 Oct"}]},{"title":"Debian's latest kernel security update has 1,313 reasons to patch","link":"https://www.theregister.com/os-platforms/2026/10/05/debians-latest-kernel-security-update-has-1313-reasons-to-patch/5301124","reason":"Linux","category":"News","sources":["Infosecurity Magazine","SecurityWeek","The Register Security"],"coverage":3,"cve_ids":[],"summary":"The age of LLM-assisted security vulnerability discovery is really starting to bite. Debian's latest Linux kernel security update comes with a formidable reading list of 1,313 CVE identifiers. The DSA-6528-1 Linux\u2026","source":"The Register Security","date_rel":"1h ago","thumbnail":"https://image.theregister.com/?imageId=246104&width=800","description":"The age of LLM-assisted security vulnerability discovery is really starting to bite. Debian's latest Linux kernel security update comes with a formidable reading list of 1,313 CVE identifiers. The DSA-6528-1 Linux security advisory, published on September 29, covers kernel package version 6.12.111-1 for Debian 13, codenamed Trixie. Debian 13.7 was released on September 12, before upstream kernel 6.12.111 arrived nine days later. The Debian security tracker links to descriptions of the individual issues. We have not examined every entry. If we had, this article would not appear until after\u2026","related":[{"title":"New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic","link":"https://www.infosecurity-magazine.com/news/smtp-linux-backdoors-network-edge/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws","link":"https://www.securityweek.com/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/","source":"SecurityWeek","date_rel":"4h ago"}]},{"title":"ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache","link":"https://cybersecuritynews.com/clickfix-fake-captcha-attack/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-69267"],"summary":"A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/ClickFix-Fake-CAPTCHA-Attack-Executes-Malware-Hidden-Inside-Browser-Cache.webp","description":"A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter. The instruction looks simple, but it makes the victim run the attacker\u2019s command. The campaign is concerning because its main script is placed on the computer before that step, hiding in the browser cache rather than arriving as an obvious download. Microsoft Threat Intelligence identified the activity in a cluster of compromised websites. Microsoft described in its\u2026","related":[{"title":"CVE-2026-69267 Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69267","source":"Microsoft Security","date_rel":"3h ago"}]},{"title":"Data breach at Denmark\u2019s national population register exposes 8.8 million people","link":"https://therecord.media/denmark-breach-register-cyberattack","reason":"Population Million People","category":"News","sources":["Bleeping Computer","The Record"],"coverage":2,"cve_ids":[],"summary":"Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register.","source":"The Record","date_rel":"5h ago","thumbnail":"http://cms.therecord.media/uploads/Denmark_people_59c08e94e5.jpg","description":"","related":[{"title":"Denmark population registry data breach affects 8.8 million people","link":"https://www.bleepingcomputer.com/news/security/denmark-population-registry-data-breach-affects-88-million-people/","source":"Bleeping Computer","date_rel":"1h ago"}]},{"title":"China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing","link":"https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal\u2026","source":"The Hacker News","date_rel":"4 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgR69JnEBkz8N6_Nd5K75adIWh8xVmxW8FB21gsKinx9HBzgXQSLWL5sYdKMe9d-cbTSrgc45ZtYhmvhLZJII1H-tPXKn4AiRvj4KrU8ayeZskmMCfiV-mUc2pz10MumKyXKH6ybJ2RsVj9ZZ67l-4u0Y2f5Dl3kX7PLEzCAqogMfHTSfD7gM7QypHi-yos/s1600/china-ms.jpg","description":"A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a","related":[{"title":"tenfold CE: Our free Identity Governance tool just got 2 new features","link":"https://www.bleepingcomputer.com/news/security/tenfold-ce-our-free-identity-governance-tool-just-got-2-new-features/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Microsoft: Windows KB5124010 update crashes some games and apps","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-kb5124010-update-crashes-some-games-and-apps/","source":"Bleeping Computer","date_rel":"7h ago"},{"title":"Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware","link":"https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html","source":"The Hacker News","date_rel":"3 Oct"}]},{"title":"Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE","link":"https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html","reason":"CVE-2026-61500","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-61500"],"summary":"A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTCvFj7lVSH1eLS0oYdxqBa4wQkNQvuemuCAL5XqwKueywAUl8Fg6zY-5UT9cdx3fZZ81DHX_emE9JXthW_OfH-axyWn3bE5CpCp4CDs4HREWjv_1uBtt5iJE947S-Bkn-4Mn1Shwt1kV9FF4RO9Wa7_4jmUtvbWrx2zs4-cdSg-FkUtxW-erVx2CXKhU3/s1600/hfs-rce-main.jpg","description":"A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and","related":[{"title":"Exploitation Hits Rejetto HFS Vulnerability Discovered by AI","link":"https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/","source":"SecurityWeek","date_rel":"6h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-105207","vendor":"zitadel","product":"zitadel","severity":"CRITICAL","score":9.8,"description":"ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/zitadel/zitadel/security/advisories/GHSA-g8gj-gq47-xgf4","https://www.vulncheck.com/advisories/zitadel-before-4.17.3-account-takeover-via-external-idp-linking"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105207"},{"id":"CVE-2026-105209","vendor":"zitadel","product":"zitadel","severity":"CRITICAL","score":9.6,"description":"ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's or\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","fix":false,"fix_url":"","refs":["https://github.com/zitadel/zitadel/security/advisories/GHSA-pq2q-2c6r-75c4","https://www.vulncheck.com/advisories/zitadel-before-3.4.15-and-4.17.1-cross-organization-account-takeover-via-passkey-enrollment"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105209"},{"id":"CVE-2026-103355","vendor":"Unlimited Elements","product":"Unlimited Elements For Elementor (Free Widgets, Addons, Templates)","severity":"CRITICAL","score":9.3,"description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL In\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0025,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-2-0-20-sql-injection-vulnerability-2?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-103355"},{"id":"CVE-2026-105215","vendor":"zitadel","product":"zitadel","severity":"CRITICAL","score":9.1,"description":"ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP c\u2026","cwe":"CWE-290","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","fix":false,"fix_url":"","refs":["https://github.com/zitadel/zitadel/security/advisories/GHSA-738m-7888-jfv8","https://www.vulncheck.com/advisories/zitadel-before-4.16.2-account-pre-hijacking-via-forged-external-idp-callback"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105215"},{"id":"CVE-2026-105086","vendor":"WWBN","product":"AVideo","severity":"HIGH","score":8.7,"description":"WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding \u2026","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","fix":false,"fix_url":"","refs":["https://github.com/WWBN/AVideo/commit/c4b6ca95a0ae3efa09919a98879870086cff150e","https://github.com/WWBN/AVideo/security/advisories/GHSA-q62w-927x-vhhf","https://www.vulncheck.com/advisories/wwbn-avideo-12.4-through-29.2.0-stored-xss-via-double-encoded-video-title"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105086"},{"id":"CVE-2026-105089","vendor":"WWBN","product":"AVideo","severity":"HIGH","score":8.7,"description":"WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates an\u2026","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","fix":false,"fix_url":"","refs":["https://github.com/WWBN/AVideo/commit/c4adfde13d1f18e3a415722471efdcd8ab480035","https://github.com/WWBN/AVideo/security/advisories/GHSA-6wfr-c7fw-4xvw","https://www.vulncheck.com/advisories/wwbn-avideo-through-29.2.0-stored-xss-via-trailer1-in-youphpflix2-templates"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105089"},{"id":"CVE-2026-105210","vendor":"zitadel","product":"zitadel","severity":"HIGH","score":8.2,"description":"ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verifi\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","fix":false,"fix_url":"","refs":["https://github.com/zitadel/zitadel/security/advisories/GHSA-72q5-mv5c-vxv4","https://www.vulncheck.com/advisories/zitadel-before-4.17.1-unauthenticated-mfa-enrollment-via-login-v1-init-handlers"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105210"},{"id":"CVE-2026-105213","vendor":"zitadel","product":"zitadel","severity":"HIGH","score":8.2,"description":"ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","fix":false,"fix_url":"","refs":["https://github.com/zitadel/zitadel/security/advisories/GHSA-558c-v5wc-9w4q","https://www.vulncheck.com/advisories/zitadel-before-4.17.1-authentication-bypass-via-login-v2-for-deactivated-organizations"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105213"},{"id":"CVE-2026-105211","vendor":"zitadel","product":"zitadel","severity":"HIGH","score":8.1,"description":"ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victi\u2026","cwe":"CWE-200","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/zitadel/zitadel/security/advisories/GHSA-3gwm-5wx8-4gm6","https://www.vulncheck.com/advisories/zitadel-before-4.17.1-authentication-bypass-via-login-v2-otp-returncode"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105211"},{"id":"CVE-2026-105293","vendor":"Legcord","product":"Legcord","severity":"HIGH","score":8.1,"description":"Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such \u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/Legcord/Legcord","https://github.com/Legcord/Legcord/blob/v1.3.0/src/common/themes.ts#L269-L276","https://github.com/Legcord/Legcord/blob/v1.3.0/src/discord/ipc.ts#L201-L206"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105293"}],"vendor_spikes":[{"vendor":"MediaTek, Inc.","count":31,"critical_count":0},{"vendor":"kishor-23","count":11,"critical_count":0},{"vendor":"zitadel","count":10,"critical_count":3},{"vendor":"Unknown","count":8,"critical_count":0},{"vendor":"itsourcecode","count":7,"critical_count":0},{"vendor":"SourceCodester","count":6,"critical_count":0},{"vendor":"Red Hat","count":3,"critical_count":0},{"vendor":"WordPress","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":12,"new_cve_count":123,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-88779":{"anchor":"#dev-1","rank":1,"coverage":5},"CVE-2026-88771":{"anchor":"#dev-4","rank":4,"coverage":3},"CVE-2026-88772":{"anchor":"#dev-4","rank":4,"coverage":3},"CVE-2026-69267":{"anchor":"#dev-7","rank":7,"coverage":2},"CVE-2026-61500":{"anchor":"#dev-10","rank":10,"coverage":2}}}