Tuesday, October 6, 2026 · generated · about 5 min read
Morning Brief
Patch today vendors with the most new CVEs today
- makeplane 4 critical 35
- Google 27
- Red Hat 26
- Unknown 1 critical 25
- TryGhost 19
- WordPress 17
- Qualcomm 15
- Microsoft 2 critical 12
- penpot 1 critical 12
- moby 10
Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.
Top developments ranked by cross-source trending
-
Image: The Hacker News Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are
Also in Bleeping Computer Cyber Security News Malwarebytes Labs +3
-
Meta and Microsoft are Actively Cutting Employee Use of Claude AI
Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own coding tools, according to an October 5 report by The Information . The changes focus on internal spending and staff workflows, rather than ending customer access to Claude through Microsoft’s products. The shift highlights growing pressure to control AI costs as coding assistants become part of daily software work. Both companies remain major Anthropic customers, but they also compete with it. Their decisions show how AI spending, product strategy, and control over developer tools are becoming…
Also in CCCS Alerts & Advisories The Hacker News Bleeping Computer +3
-
ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access
ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access. Rather than simply infecting routers and cameras, it turns compromised equipment into remotely controlled proxy nodes that can relay traffic and run commands. The campaign targets known security flaws across multiple vendors, expanding its attack methods as it evolves. Unpatched firmware, unsupported hardware, and exposed services create openings for infections that can survive device restarts and conceal their activity from routine checks. Fortinet researchers identified…
Also in The Register Security Dark Reading The Register Security +2
-
Citrix NetScaler security snafus get even worse amid more 0-day reports
The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was…
Also in CyberScoop The Record Infosecurity Magazine +2
-
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge
Also in SecurityWeek Schneier on Security
-
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to
Also in Sophos Threat Research Bleeping Computer CISA Alerts & Advisories
-
Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products
Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589, the flaw has a CVSS score of 9.3. It lets unauthenticated attackers access specific files in an affected application’s web root directory. The advisory, published on October 5, 2026, covers Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges customers running affected installations to patch…
Also in The Hacker News The Register Security
-
Need for Speed: AI-Driven Attacks Are Changing Security Strategies
AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.
Also in Wiz Research The Hacker News
-
Cybersecurity M&A Roundup: 39 Deals Announced in September 2026
Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind.
Also in CCCS Alerts & Advisories
-
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and
Also in Bleeping Computer SecurityWeek
Vulnerability watch what to look at, most urgent first
| Details | CVE | Product | Severity | CVSS | EPSS | KEV | Fix | In the news | |
|---|---|---|---|---|---|---|---|---|---|
| Highest scoring today 10new CVEs, highest CVSS first | |||||||||
| CVE-2026-105284 | A3002MUTotolink | Critical | 10.0 | 0.8% | — | None linked | — | EPSS 0.8%CVSS 10.0No fix linked | |
What it isA weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization… Attack
Exploitation
|
|||||||||
| CVE-2026-105285 | A3002MUTotolink | Critical | 10.0 | 1% | — | None linked | — | EPSS 1%CVSS 10.0No fix linked | |
What it isA security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_nam… Attack
Exploitation
|
|||||||||
| CVE-2026-105484 | X6000RTOTOLINK | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isA security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the … Attack
Exploitation
|
|||||||||
| CVE-2026-105636 | planemakeplane | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isPlane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() … Attack
Exploitation
|
|||||||||
| CVE-2026-105691 | penpotpenpot | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isPenpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec.… Attack
Exploitation
|
|||||||||
| CVE-2026-105697 | langflowlangflow-ai | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isLangflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3)… Attack
Exploitation
|
|||||||||
| CVE-2026-105740 | langflowlangflow-ai | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isLangflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The use… Attack
Exploitation
|
|||||||||
| CVE-2026-105778 | AC5Tenda | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isA vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based b… Attack
Exploitation
|
|||||||||
| CVE-2026-88395 | Unknown | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isGouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter. Attack
Exploitation
|
|||||||||
| CVE-2026-105639 | planemakeplane | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isPlane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can ca… Attack
Exploitation
|
|||||||||
Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed
Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.
Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.