{"date_iso":"2026-10-07","date_human":"Wednesday, October 7, 2026","generated_utc":"2026-10-07 12:57 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Hackers obtain counterfeit TLS certificates for Google and other large services","link":"https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services/","reason":"Google","category":"Media","sources":["Ars Technica Security","Bleeping Computer","Dark Reading","Infosecurity Magazine","Malwarebytes Labs","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the\u2026","source":"Ars Technica Security","date_rel":"17h ago","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2026/10/broken-https-tls-500x500.jpg","description":"Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for \u201cseveral Google domains\u201d and \u201cseveral leading global brands and widely used online\u2026","related":[{"title":"Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes","link":"https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html","source":"The Hacker News","date_rel":"18h ago"},{"title":"Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps","link":"https://www.darkreading.com/application-security/google-pagebreak-ai-agent-500-flaws-web-apps","source":"Dark Reading","date_rel":"19h ago"},{"title":"Nikkei discloses breaches of employees\u2019 Microsoft, Google email accounts","link":"https://www.bleepingcomputer.com/news/security/nikkei-discloses-breaches-of-employees-microsoft-google-email-accounts/","source":"Bleeping Computer","date_rel":"6 Oct"},{"title":"Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports","link":"https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html","source":"The Hacker News","date_rel":"6 Oct"},{"title":"Google pauses open source bug bounty program after rise in AI submissions","link":"https://www.malwarebytes.com/blog/news/2026/10/google-pauses-open-source-bug-bounty-program-after-rise-in-ai-submissions","source":"Malwarebytes Labs","date_rel":"5 Oct"},{"title":"Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports","link":"https://www.infosecurity-magazine.com/news/google-suspends-opensource-bug/","source":"Infosecurity Magazine","date_rel":"5 Oct"}]},{"title":"Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details","link":"https://thehackernews.com/2026/10/atlassian-data-center-flaw-draws.html","reason":"Atlassian","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEityRbZfy1N9Y0SuqWl7yeWTYMjeirrTbDx719fM65Be6yXOt2Zl0YweAi0hAfswNzV_LrHa4eFCpcCemC3FNwxZve4bPkSelQiRnCdXpZofAnI7Si96nULBV6i25jgFaZkEY1T3LuPRhj6QzTSsWHZtLuoH1zXlLKZN3WwSiKS7QoY_Zug0CtaaCGozT6N/s1600/jira-attack.jpg","description":"Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software","related":[{"title":"Atlassian Patches Critical Vulnerability Affecting 8 Products","link":"https://www.securityweek.com/atlassian-patches-critical-vulnerability-affecting-8-products/","source":"SecurityWeek","date_rel":"6h ago"},{"title":"Atlassian security advisory (AV26-1002)","link":"https://cyber.gc.ca/en/alerts-advisories/atlassian-security-advisory-av26-1002","source":"CCCS Alerts & Advisories","date_rel":"23h ago"},{"title":"Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products","link":"https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html","source":"The Hacker News","date_rel":"6 Oct"},{"title":"Atlassian warns of critical file access flaw in its datacenter products","link":"https://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284","source":"The Register Security","date_rel":"6 Oct"}]},{"title":"'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates","link":"https://www.darkreading.com/application-security/bigdiskbuster-microsoft-defender-running-blocking-updates","reason":"Microsoft","category":"News","sources":["CCCS Alerts & Advisories","CrowdStrike Blog","Dark Reading","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.","source":"Dark Reading","date_rel":"19h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt3886ee964b5d16f1/6ac4000875ac86196ed5f175/broken_hard_drive-Bryngelzon-GettyImages-115958814.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Microsoft extends the Outlook naughty step with two more file types","link":"https://www.theregister.com/software/2026/10/06/microsoft-extends-the-outlook-naughty-step-with-two-more-file-types/5301350","source":"The Register Security","date_rel":"21h ago"},{"title":"Microsoft security advisory (AV26-1001)","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-av26-1001","source":"CCCS Alerts & Advisories","date_rel":"5 Oct"},{"title":"Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes","link":"https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html","source":"The Hacker News","date_rel":"5 Oct"},{"title":"Falcon Data Security for SaaS Secures Sensitive Data in Microsoft 365","link":"https://www.crowdstrike.com/en-us/blog/falcon-data-security-for-saas-secures-sensitive-data/","source":"CrowdStrike Blog","date_rel":"5 Oct"}]},{"title":"Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws","link":"https://thehackernews.com/2026/10/anthropic-expands-claude-access-for.html","reason":"Teams","category":"News","sources":["Dark Reading","Rapid7 Blog","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimg1tAvNh5aMWuNTZXjb4kKfxIQ0iWkuo2bCznozA8oz2Fm36WzbPnBI1bBDX5Mc3hpyOMIcjS_fcdYzzpQnrtUkex17u0_fn7r3bgcRYEN4o2hoGf4vlw5hQKEgcDd2VoVT2P9unKzsVOlly1QFlu6WfySqGPZ4Pf7xrZXaL4pEy1vrhWQBHR7SiqHHvf/s1600/claude-flaws.jpg","description":"Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional","related":[{"title":"IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams","link":"https://www.darkreading.com/cybersecurity-operations/ai-reshaping-ciso-budgets-security-teams","source":"Dark Reading","date_rel":"19h ago"},{"title":"Securing Agent-to-Agent Communication: The Next Identity Frontier","link":"https://www.rapid7.com/blog/post/ai-securing-agent-to-agent-communication-next-identity-frontier","source":"Rapid7 Blog","date_rel":"22h ago"},{"title":"What\u2019s New in Wiz Service Catalog: Smarter Discovery, Governance, and Service-Level Context","link":"https://www.wiz.io/blog/wiz-service-catalog-updates","source":"Wiz Research","date_rel":"5 Oct"},{"title":"Need for Speed: AI-Driven Attacks Are Changing Security Strategies","link":"https://www.darkreading.com/cyber-risk/ai-attacks-security-strategies","source":"Dark Reading","date_rel":"5 Oct"},{"title":"The Credential Layer Is Expanding Faster Than Security Teams Can See It","link":"https://thehackernews.com/2026/10/the-credential-layer-is-expanding.html","source":"The Hacker News","date_rel":"5 Oct"}]},{"title":"CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products","link":"https://www.rapid7.com/blog/post/etr-cve-2026-21589-critical-unauthenticated-arbitrary-file-access-in-atlassian-products","reason":"CVE-2026-21589","category":"Research","sources":["Bleeping Computer","Rapid7 Blog","watchTowr Labs"],"coverage":3,"cve_ids":["CVE-2026-21589"],"summary":"Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira\u2026","source":"Rapid7 Blog","date_rel":"45m ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration\u2026","related":[{"title":"Hackers exploit critical Atlassian flaw after public PoC release","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atlassian-flaw-after-public-poc-release/","source":"Bleeping Computer","date_rel":"8m ago"},{"title":"Atlassian warns of critical file-access flaw in Jira, Confluence","link":"https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-file-access-flaw-in-jira-confluence/","source":"Bleeping Computer","date_rel":"19h ago"},{"title":"You Won\u2019t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)","link":"https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/","source":"watchTowr Labs","date_rel":"19h ago"}]},{"title":"Google Chrome Update Fixes Massive 247 Vulnerabilities, Including 4 Code Execution Flaws","link":"https://cybersecuritynews.com/chrome-fixes-massive-247-vulnerabilities/","reason":"Chrome","category":"News","sources":["Cyber Security News","Malwarebytes Labs","SecurityWeek"],"coverage":3,"cve_ids":[],"summary":"Google released a major Chrome security update on October 6, 2026, fixing 247 vulnerabilities, including four critical memory-safety flaws , across Windows, Mac, and Linux. The patched versions are 155.0.8059.39/.40 for\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Google-Chrome-Update-Fixes-Massive-247-Vulnerabilities-Including-4-Code-Execution-Flaws-1.webp","description":"Google released a major Chrome security update on October 6, 2026, fixing 247 vulnerabilities, including four critical memory-safety flaws , across Windows, Mac, and Linux. The patched versions are 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 for Linux. Although the critical bugs raise concerns about possible code execution, Google\u2019s announcement identifies them as use-after-free vulnerabilities. It does not describe specific exploitation methods or confirm arbitrary code execution. The first critical vulnerability, CVE-2026-106382, affects Chromecast. Google reported the\u2026","related":[{"title":"Chrome 155 Update Patches 247 Vulnerabilities","link":"https://www.securityweek.com/chrome-155-update-patches-247-vulnerabilities/","source":"SecurityWeek","date_rel":"2h ago"},{"title":"Update Chrome and ChromeOS to fix critical security issues","link":"https://www.malwarebytes.com/blog/bugs/2026/10/update-chrome-and-chromeos-to-fix-critical-security-issues","source":"Malwarebytes Labs","date_rel":"2h ago"}]},{"title":"Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access","link":"https://thehackernews.com/2026/10/apple-plans-tighter-macos-full-disk.html","reason":"Apple","category":"News","sources":["Bleeping Computer","Schneier on Security","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. \"Some developers are using Full\u2026","source":"The Hacker News","date_rel":"5 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDBg5lUcW7uXfKt2vo4Pq5MQUxOty2Xq3pApCIyhUAuSpTzu1jR_CGkNNS2UkAKxYvqk4KCyP1Ehr0PYcW6xVolcSuSdfRPx4rSDDnkuAKaCkgBii_l7kH-s9u7oEhyK2FpvAnaTRWDV48t9XBXEv-MpUIWhBaZYIBx3CFY_zSUXxdw-3C5rB_30Y0VEtf/s1600/macos-ai.jpg","description":"Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. \"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems\u2014including files, mail, messages, and even browsing history \u2013 without users' full knowledge","related":[{"title":"Musician sent to prison for $10 million streaming fraud using AI bots","link":"https://www.bleepingcomputer.com/news/security/musician-gets-18-months-in-prison-for-10-million-streaming-fraud-using-ai-bots/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"Possible Vulnerability in Apple\u2019s Automatic Reboot","link":"https://www.schneier.com/blog/archives/2026/10/possible-vulnerability-in-apples-automatic-reboot.html","source":"Schneier on Security","date_rel":"6 Oct"}]},{"title":"FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials","link":"https://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.html","reason":"Fortinet","category":"News","sources":["CyberScoop","The Hacker News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQZeKQIcHTVLgqnHpZYN73YclFawl51QxpykrKEb97sAJjA8qtN7FaUJaS0jLMeSS29cTB0nR_yFzsITX_e5SI8Xa8BfM1LDOGsEEEpDmVC8YNqOcEYEuep1UbHovyLlxrwRmYZ3FrbaaKq9eKwICiUTkkPleIibOHdWnbV5cpwYPCrHQasrTxVFA9seQ-/s1600/forti-admin.jpg","description":"The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. \"The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat","related":[{"title":"FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks","link":"https://www.theregister.com/security/2026/10/07/fortibleed-still-a-bleeding-nuisance-as-fbi-confirms-ongoing-attacks/5301585","source":"The Register Security","date_rel":"2h ago"},{"title":"Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks","link":"https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/","source":"CyberScoop","date_rel":"15h ago"}]},{"title":"Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan","link":"https://thehackernews.com/2026/10/linux-backdoors-impersonate-email.html","reason":"Linux","category":"News","sources":["Dark Reading","Infosecurity Magazine","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors\u2026","source":"The Hacker News","date_rel":"18h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj42ncE2ZMHIbAm_fj5U9fqCYUvPwhyUiNbARM3CC5IxhnMXjIZ2ENa99UDGeaZqGPlqn53A7y7Nkz1ZxzzyykKxEb4GT0jxWhrar9Q5yPmBN1NL6599HRdbzbLSYf3WPuU7tkkY5eOsvhAT9dw-24DXuusztPyRr2H66840cWZx17MZ0B-rB877W19bgX1/s1600/linux-spam.jpg","description":"Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may","related":[{"title":"Security researcher claims they found KVM guest-host escape flaw","link":"https://www.theregister.com/offbeat/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw/5301267","source":"The Register Security","date_rel":"6 Oct"},{"title":"ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes","link":"https://www.darkreading.com/iot/clingstun-vulnerable-iot-devices-proxy-nodes","source":"Dark Reading","date_rel":"5 Oct"},{"title":"Debian's latest kernel security update has 1,313 reasons to patch","link":"https://www.theregister.com/os-platforms/2026/10/05/debians-latest-kernel-security-update-has-1313-reasons-to-patch/5301124","source":"The Register Security","date_rel":"5 Oct"},{"title":"New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic","link":"https://www.infosecurity-magazine.com/news/smtp-linux-backdoors-network-edge/","source":"Infosecurity Magazine","date_rel":"5 Oct"}]},{"title":"Citrix NetScaler security snafus get even worse amid more 0-day reports","link":"https://www.theregister.com/security/2026/10/05/citrix-netscaler-security-snafus-get-even-worse-amid-more-0-day-reports/5301232","reason":"Citrix","category":"News","sources":["CCCS Alerts & Advisories","CyberScoop","Infosecurity Magazine","The Register Security"],"coverage":4,"cve_ids":[],"summary":"The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch\u2026","source":"The Register Security","date_rel":"5 Oct","thumbnail":"https://image.theregister.com/?imageId=259122&width=800","description":"The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was\u2026","related":[{"title":"Citrix discloses third actively exploited NetScaler zero-day in less than a week","link":"https://cyberscoop.com/citrix-netscaler-third-exploited-zero-day-vulnerability/","source":"CyberScoop","date_rel":"5 Oct"},{"title":"Citrix NetScaler Targeted Via New Zero Day","link":"https://www.infosecurity-magazine.com/news/citrix-netscaler-zero-day/","source":"Infosecurity Magazine","date_rel":"5 Oct"},{"title":"Citrix security advisory (AV26-996)","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-996","source":"CCCS Alerts & Advisories","date_rel":"5 Oct"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-32579","vendor":"WordPress","product":"Kognetiks Chatbot for WordPress","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0049,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/chatbot-chatgpt/vulnerability/wordpress-kognetiks-chatbot-for-wordpress-plugin-2-4-8-arbitrary-file-upload-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-32579"},{"id":"CVE-2026-39770","vendor":"AmentoTech","product":"Doctreat","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0042,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/theme/doctreat/vulnerability/wordpress-doctreat-theme-1-7-0-arbitrary-file-upload-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-39770"},{"id":"CVE-2026-39773","vendor":"AmentoTech","product":"Doctreat Core","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0029,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/doctreat_core/vulnerability/wordpress-doctreat-core-plugin-1-7-0-privilege-escalation-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-39773"},{"id":"CVE-2026-63688","vendor":"Dell","product":"Dell Container Storage Modules (CSM)","severity":"CRITICAL","score":10.0,"description":"Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploi\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-63688"},{"id":"CVE-2026-63692","vendor":"Dell","product":"Container Storage Modules","severity":"CRITICAL","score":10.0,"description":"Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Eleva\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-63692"},{"id":"CVE-2026-105857","vendor":"payloadcms","product":"payload","severity":"CRITICAL","score":10.0,"description":"Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely \u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/payloadcms/payload/commit/333b82b9f3e685fed6826c2e3270da79df8336c6","https://github.com/payloadcms/payload/releases/tag/v3.90.0","https://github.com/payloadcms/payload/security/advisories/GHSA-r488-j9vj-wx3q"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105857"},{"id":"CVE-2026-106102","vendor":"quasarframework","product":"quasar","severity":"CRITICAL","score":10.0,"description":"Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into tit\u2026","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","fix":false,"fix_url":"","refs":["https://github.com/quasarframework/quasar/commit/11505afe5b5218f2c468f130181815b898fd1e40","https://github.com/quasarframework/quasar/releases/tag/quasar-v2.22.0","https://github.com/quasarframework/quasar/security/advisories/GHSA-pq96-jpmf-w254"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-106102"},{"id":"CVE-2026-32568","vendor":"WordPress","product":"WooCommerce Designer Pro","severity":"CRITICAL","score":9.9,"description":"Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0074,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/wc-designer-pro/vulnerability/wordpress-woocommerce-designer-pro-plugin-1-9-33-remote-code-execution-rce-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-32568"},{"id":"CVE-2026-39755","vendor":"revmakx","product":"WP Duplicate","severity":"CRITICAL","score":9.9,"description":"Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0045,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/local-sync/vulnerability/wordpress-wp-duplicate-plugin-1-1-11-arbitrary-file-upload-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-39755"},{"id":"CVE-2026-39757","vendor":"AmentoTech","product":"Taskbot","severity":"CRITICAL","score":9.9,"description":"Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0048,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/taskbot/vulnerability/wordpress-taskbot-plugin-6-6-arbitrary-file-upload-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-39757"}],"vendor_spikes":[{"vendor":"Google","count":253,"critical_count":20},{"vendor":"Linux","count":194,"critical_count":2},{"vendor":"WordPress","count":44,"critical_count":4},{"vendor":"HP","count":37,"critical_count":16},{"vendor":"Gitea","count":30,"critical_count":0},{"vendor":"payloadcms","count":29,"critical_count":3},{"vendor":"Microsoft","count":26,"critical_count":2},{"vendor":"Arista Networks","count":24,"critical_count":2},{"vendor":"IBM","count":24,"critical_count":2},{"vendor":"Dell","count":22,"critical_count":7}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":1006,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-21589":{"anchor":"#dev-5","rank":5,"coverage":3}}}