{"date_iso":"2026-10-06","date_human":"Tuesday, October 6, 2026","generated_utc":"2026-10-06 14:19 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports","link":"https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html","reason":"Google","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the\u2026","source":"The Hacker News","date_rel":"3h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgCWoelMB7H9bFZJdDV7vP5M3a1ByvpHs8ub2SrBGOM1gz6r0Fg9cV1fplW5Q6mNBFtRlW99wDCSC-_6_sZBw0l4HsFvUDP5cCH2zmgcF4NK5wCOInv05K4hH2WMlKCA_G_psX4zB_hUcXid2MWx5fGDjaJvD1YjWBechwUdrhXK51dJYZ3PGsu0JQcT1U/s1600/google-bug-bounty.jpg","description":"Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are","related":[{"title":"Nikkei discloses breaches of employees\u2019 Microsoft, Google email accounts","link":"https://www.bleepingcomputer.com/news/security/nikkei-discloses-breaches-of-employees-microsoft-google-email-accounts/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks","link":"https://cybersecuritynews.com/google-adds-6-advanced-protection-features/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"Google pauses open source bug bounty program after rise in AI submissions","link":"https://www.malwarebytes.com/blog/news/2026/10/google-pauses-open-source-bug-bounty-program-after-rise-in-ai-submissions","source":"Malwarebytes Labs","date_rel":"21h ago"},{"title":"Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports","link":"https://www.securityweek.com/google-narrows-open-source-bug-bounty-amid-wave-of-invalid-automated-reports/","source":"SecurityWeek","date_rel":"22h ago"},{"title":"Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports","link":"https://www.infosecurity-magazine.com/news/google-suspends-opensource-bug/","source":"Infosecurity Magazine","date_rel":"5 Oct"},{"title":"Google halts open-source bug bounty program amid AI spam surge","link":"https://www.bleepingcomputer.com/news/google/google-halts-open-source-bug-bounty-program-amid-ai-spam-surge/","source":"Bleeping Computer","date_rel":"5 Oct"}]},{"title":"Meta and Microsoft are Actively Cutting Employee Use of Claude AI","link":"https://cybersecuritynews.com/meta-microsoft-claude-ai/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","CrowdStrike Blog","Cyber Security News","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"Meta and Microsoft are reducing employee use of Anthropic\u2019s Claude AI while pushing their own coding tools, according to an October 5 report by The Information . The changes focus on internal spending and staff\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Meta-Microsoft-Claude-AI.webp","description":"Meta and Microsoft are reducing employee use of Anthropic\u2019s Claude AI while pushing their own coding tools, according to an October 5 report by The Information . The changes focus on internal spending and staff workflows, rather than ending customer access to Claude through Microsoft\u2019s products. The shift highlights growing pressure to control AI costs as coding assistants become part of daily software work. Both companies remain major Anthropic customers, but they also compete with it. Their decisions show how AI spending, product strategy, and control over developer tools are becoming\u2026","related":[{"title":"Microsoft security advisory (AV26-1001)","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-av26-1001","source":"CCCS Alerts & Advisories","date_rel":"18h ago"},{"title":"Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes","link":"https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html","source":"The Hacker News","date_rel":"20h ago"},{"title":"tenfold CE: Our free Identity Governance tool just got 2 new features","link":"https://www.bleepingcomputer.com/news/security/tenfold-ce-our-free-identity-governance-tool-just-got-2-new-features/","source":"Bleeping Computer","date_rel":"23h ago"},{"title":"Microsoft: Windows KB5124010 update crashes some games and apps","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-kb5124010-update-crashes-some-games-and-apps/","source":"Bleeping Computer","date_rel":"5 Oct"},{"title":"Falcon Data Security for SaaS Secures Sensitive Data in Microsoft 365","link":"https://www.crowdstrike.com/en-us/blog/falcon-data-security-for-saas-secures-sensitive-data/","source":"CrowdStrike Blog","date_rel":"5 Oct"},{"title":"China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing","link":"https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html","source":"The Hacker News","date_rel":"4 Oct"}]},{"title":"ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access","link":"https://cybersecuritynews.com/clingstun-backdoor/","reason":"Linux","category":"News","sources":["Cyber Security News","Dark Reading","Infosecurity Magazine","SecurityWeek","The Register Security"],"coverage":5,"cve_ids":[],"summary":"ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access. Rather than simply infecting routers and cameras, it turns compromised equipment into remotely\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/ClingSTUN-Backdoor-Exploits-Multiple-IoT-Vulnerabilities-to-Gain-Persistent-Remote-Access.webp","description":"ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access. Rather than simply infecting routers and cameras, it turns compromised equipment into remotely controlled proxy nodes that can relay traffic and run commands. The campaign targets known security flaws across multiple vendors, expanding its attack methods as it evolves. Unpatched firmware, unsupported hardware, and exposed services create openings for infections that can survive device restarts and conceal their activity from routine checks. Fortinet researchers identified\u2026","related":[{"title":"Security researcher claims they found KVM guest-host escape flaw","link":"https://www.theregister.com/offbeat/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw/5301267","source":"The Register Security","date_rel":"10h ago"},{"title":"ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes","link":"https://www.darkreading.com/iot/clingstun-vulnerable-iot-devices-proxy-nodes","source":"Dark Reading","date_rel":"15h ago"},{"title":"Debian's latest kernel security update has 1,313 reasons to patch","link":"https://www.theregister.com/os-platforms/2026/10/05/debians-latest-kernel-security-update-has-1313-reasons-to-patch/5301124","source":"The Register Security","date_rel":"21h ago"},{"title":"New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic","link":"https://www.infosecurity-magazine.com/news/smtp-linux-backdoors-network-edge/","source":"Infosecurity Magazine","date_rel":"22h ago"},{"title":"Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws","link":"https://www.securityweek.com/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/","source":"SecurityWeek","date_rel":"23h ago"}]},{"title":"Citrix NetScaler security snafus get even worse amid more 0-day reports","link":"https://www.theregister.com/security/2026/10/05/citrix-netscaler-security-snafus-get-even-worse-amid-more-0-day-reports/5301232","reason":"Citrix","category":"News","sources":["CCCS Alerts & Advisories","CyberScoop","Infosecurity Magazine","The Record","The Register Security"],"coverage":5,"cve_ids":["CVE-2026-88771","CVE-2026-88772"],"summary":"The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch\u2026","source":"The Register Security","date_rel":"15h ago","thumbnail":"https://image.theregister.com/?imageId=259122&width=800","description":"The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was\u2026","related":[{"title":"Citrix discloses third actively exploited NetScaler zero-day in less than a week","link":"https://cyberscoop.com/citrix-netscaler-third-exploited-zero-day-vulnerability/","source":"CyberScoop","date_rel":"13h ago"},{"title":"US, Australia warn of latest Citrix vulnerability after NetScaler advisory","link":"https://therecord.media/us-australia-warn-of-latest-citrix-vulnerability","source":"The Record","date_rel":"19h ago"},{"title":"Citrix NetScaler Targeted Via New Zero Day","link":"https://www.infosecurity-magazine.com/news/citrix-netscaler-zero-day/","source":"Infosecurity Magazine","date_rel":"23h ago"},{"title":"Citrix security advisory (AV26-996)","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-996","source":"CCCS Alerts & Advisories","date_rel":"5 Oct"},{"title":"AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway \u2013 CVE-2026-88771 and CVE-2026-88772 \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772","source":"CCCS Alerts & Advisories","date_rel":"3 Oct"}]},{"title":"Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access","link":"https://thehackernews.com/2026/10/apple-plans-tighter-macos-full-disk.html","reason":"Apple","category":"News","sources":["Schneier on Security","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. \"Some developers are using Full\u2026","source":"The Hacker News","date_rel":"5 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDBg5lUcW7uXfKt2vo4Pq5MQUxOty2Xq3pApCIyhUAuSpTzu1jR_CGkNNS2UkAKxYvqk4KCyP1Ehr0PYcW6xVolcSuSdfRPx4rSDDnkuAKaCkgBii_l7kH-s9u7oEhyK2FpvAnaTRWDV48t9XBXEv-MpUIWhBaZYIBx3CFY_zSUXxdw-3C5rB_30Y0VEtf/s1600/macos-ai.jpg","description":"Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. \"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems\u2014including files, mail, messages, and even browsing history \u2013 without users' full knowledge","related":[{"title":"Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks","link":"https://www.securityweek.com/apple-to-tighten-full-disk-access-controls-in-macos-amid-ai-risks/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"Possible Vulnerability in Apple\u2019s Automatic Reboot","link":"https://www.schneier.com/blog/archives/2026/10/possible-vulnerability-in-apples-automatic-reboot.html","source":"Schneier on Security","date_rel":"1h ago"}]},{"title":"New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline","link":"https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html","reason":"CVE-2026-88779","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","Sophos Threat Research","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-88779"],"summary":"Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779\u2026","source":"The Hacker News","date_rel":"5 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhV4of0Q-gWaIOffgWXdEfAxmI1ENcyrpDSSDjBurAHSpUuAI8lASQI5wrUvL3Evb0iqA31rRywo51olFOzoWe_lQ9cwN7Sp5QQw_2h-y44n0Va4vwlRQZipZ5fkm98BRmTOoVDPTs8pUMW_ClnH2GlPobgQQ33rNzL8EBnBW84aacH3dLXdyyLW9bBEqG5/s1600/citrix-offline.jpg","description":"Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. \"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to","related":[{"title":"Citrix NetScaler vulnerability (CVE-2026-88779) in active exploitation","link":"https://www.sophos.com/en-us/blog/citrix-netscaler-vulnerability-cve-2026-88779-in-active-exploitation","source":"Sophos Threat Research","date_rel":"5 Oct"},{"title":"Citrix patches NetScaler SAML zero-day exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"4 Oct"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"4 Oct"}]},{"title":"Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products","link":"https://cybersecuritynews.com/atlassian-patches-critical-vulnerabilities/","reason":"Atlassian","category":"News","sources":["Cyber Security News","The Hacker News","The Register Security"],"coverage":3,"cve_ids":["CVE-2026-21589"],"summary":"Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589, the flaw has a CVSS score of 9.3. It lets\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Critical-Atlassian-Flaw-CVE-2026-21589-Exposes-Files-in-Jira-Confluence-Bitbucket-and-Five-More-Products-1.webp","description":"Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589, the flaw has a CVSS score of 9.3. It lets unauthenticated attackers access specific files in an affected application\u2019s web root directory. The advisory, published on October 5, 2026, covers Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges customers running affected installations to patch\u2026","related":[{"title":"Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products","link":"https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html","source":"The Hacker News","date_rel":"5h ago"},{"title":"Atlassian warns of critical file access flaw in its datacenter products","link":"https://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284","source":"The Register Security","date_rel":"8h ago"}]},{"title":"Need for Speed: AI-Driven Attacks Are Changing Security Strategies","link":"https://www.darkreading.com/cyber-risk/ai-attacks-security-strategies","reason":"Teams","category":"News","sources":["Dark Reading","The Hacker News","Wiz Research"],"coverage":3,"cve_ids":[],"summary":"AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.","source":"Dark Reading","date_rel":"23h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt805a291660c85e6c/6abfd753b06065c7488d51a1/fighterjet-Asanka_Ratnayake-GettyImages-2207309883.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"What\u2019s New in Wiz Service Catalog: Smarter Discovery, Governance, and Service-Level Context","link":"https://www.wiz.io/blog/wiz-service-catalog-updates","source":"Wiz Research","date_rel":"20h ago"},{"title":"The Credential Layer Is Expanding Faster Than Security Teams Can See It","link":"https://thehackernews.com/2026/10/the-credential-layer-is-expanding.html","source":"The Hacker News","date_rel":"5 Oct"}]},{"title":"Cybersecurity M&A Roundup: 39 Deals Announced in September 2026","link":"https://www.securityweek.com/cybersecurity-ma-roundup-39-deals-announced-in-september-2026/","reason":"Ibm","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind.","source":"SecurityWeek","date_rel":"1h ago","thumbnail":"","description":"","related":[{"title":"IBM security advisory (AV26-997)","link":"https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-997","source":"CCCS Alerts & Advisories","date_rel":"23h ago"}]},{"title":"Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE","link":"https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html","reason":"CVE-2026-61500","category":"News","sources":["Bleeping Computer","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-61500"],"summary":"A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session\u2026","source":"The Hacker News","date_rel":"5 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTCvFj7lVSH1eLS0oYdxqBa4wQkNQvuemuCAL5XqwKueywAUl8Fg6zY-5UT9cdx3fZZ81DHX_emE9JXthW_OfH-axyWn3bE5CpCp4CDs4HREWjv_1uBtt5iJE947S-Bkn-4Mn1Shwt1kV9FF4RO9Wa7_4jmUtvbWrx2zs4-cdSg-FkUtxW-erVx2CXKhU3/s1600/hfs-rce-main.jpg","description":"A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and","related":[{"title":"Rejetto HFS servers now actively scanned for critical RCE flaw","link":"https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/","source":"Bleeping Computer","date_rel":"16h ago"},{"title":"Exploitation Hits Rejetto HFS Vulnerability Discovered by AI","link":"https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/","source":"SecurityWeek","date_rel":"5 Oct"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-105284","vendor":"Totolink","product":"A3002MU","severity":"CRITICAL","score":10.0,"description":"A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization\u2026","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0078,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://gist.github.com/H3rmesk1t/ac6e91a8fba51002be085755c8bf7d43","https://vuldb.com/cve/CVE-2026-105284","https://vuldb.com/submit/977217"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105284"},{"id":"CVE-2026-105285","vendor":"Totolink","product":"A3002MU","severity":"CRITICAL","score":10.0,"description":"A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_nam\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.011,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://gist.github.com/H3rmesk1t/b68352b011bc2825adc85cf336c25dfb","https://vuldb.com/cve/CVE-2026-105285","https://vuldb.com/submit/977224"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105285"},{"id":"CVE-2026-105484","vendor":"TOTOLINK","product":"X6000R","severity":"CRITICAL","score":10.0,"description":"A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the \u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://vuldb.com/cve/CVE-2026-105484","https://vuldb.com/submit/984434","https://vuldb.com/vuln/413619"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105484"},{"id":"CVE-2026-105636","vendor":"makeplane","product":"plane","severity":"CRITICAL","score":9.9,"description":"Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() \u2026","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615","https://github.com/makeplane/plane/pull/9163","https://github.com/makeplane/plane/releases/tag/v1.4.0"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105636"},{"id":"CVE-2026-105691","vendor":"penpot","product":"penpot","severity":"CRITICAL","score":9.9,"description":"Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec.\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/penpot/penpot/commit/aa3bc1ae984577f0354d4270d2546e15985f4bcf","https://github.com/penpot/penpot/pull/11272","https://github.com/penpot/penpot/releases/tag/2.18.0"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105691"},{"id":"CVE-2026-105697","vendor":"langflow-ai","product":"langflow","severity":"CRITICAL","score":9.9,"description":"Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3)\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/langflow-ai/langflow/commit/eba285edf1dd4a33bf23a9cb8113c991fcdf3d1d","https://github.com/langflow-ai/langflow/commit/efbc4a16e639409d938a4883463d27ef0bc637a0","https://github.com/langflow-ai/langflow/pull/12290"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105697"},{"id":"CVE-2026-105740","vendor":"langflow-ai","product":"langflow","severity":"CRITICAL","score":9.9,"description":"Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the \"Stdio\" transport. The use\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/langflow-ai/langflow/commit/efbc4a16e639409d938a4883463d27ef0bc637a0","https://github.com/langflow-ai/langflow/pull/12290","https://github.com/langflow-ai/langflow/security/advisories/GHSA-7w94-79vh-5mr2"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105740"},{"id":"CVE-2026-105778","vendor":"Tenda","product":"AC5","severity":"CRITICAL","score":9.9,"description":"A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based b\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/raisecnull/Tenda-AC5v3-BOF/blob/main/blog.md","https://vuldb.com/cve/CVE-2026-105778","https://vuldb.com/submit/992587"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105778"},{"id":"CVE-2026-88395","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/fangtang7/CVE/blob/main/GouGuOA/sql.md","https://github.com/fangtang7/CVE/blob/main/GouGuOA/sql.md"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-88395"},{"id":"CVE-2026-105639","vendor":"makeplane","product":"plane","severity":"CRITICAL","score":9.8,"description":"Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can ca\u2026","cwe":"CWE-200","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/makeplane/plane/commit/6220ba990b2276a1a1979d1d5df68f650b8b47ad","https://github.com/makeplane/plane/pull/9297","https://github.com/makeplane/plane/releases/tag/v1.4.0"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105639"}],"vendor_spikes":[{"vendor":"makeplane","count":35,"critical_count":4},{"vendor":"Google","count":27,"critical_count":0},{"vendor":"Red Hat","count":26,"critical_count":0},{"vendor":"Unknown","count":25,"critical_count":1},{"vendor":"TryGhost","count":19,"critical_count":0},{"vendor":"WordPress","count":17,"critical_count":0},{"vendor":"Qualcomm","count":15,"critical_count":0},{"vendor":"Microsoft","count":12,"critical_count":2},{"vendor":"penpot","count":12,"critical_count":1},{"vendor":"moby","count":10,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":11,"new_cve_count":408,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-88771":{"anchor":"#dev-4","rank":4,"coverage":5},"CVE-2026-88772":{"anchor":"#dev-4","rank":4,"coverage":5},"CVE-2026-88779":{"anchor":"#dev-6","rank":6,"coverage":4},"CVE-2026-21589":{"anchor":"#dev-7","rank":7,"coverage":3},"CVE-2026-61500":{"anchor":"#dev-10","rank":10,"coverage":3}}}