{"date_iso":"2026-10-09","date_human":"Friday, October 9, 2026","generated_utc":"2026-10-09 12:57 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own","link":"https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html","reason":"Google","category":"News","sources":["Ars Technica Security","CCCS Alerts & Advisories","Cisco Talos","Dark Reading","ESET WeLiveSecurity","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Hacker News","The Record","The Register Security"],"coverage":11,"cve_ids":[],"summary":"Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqGob0G-EHmqSYe9ZFWu_Pqg2ZivxomC2c4TSsW_k2yx0eZClRf8rgYVhDJTUrrhyzKr8yQr00rjzvVCRc7EsZjELELmKTWVxzLLsvx0DV5Q0rLWGd1eczFcVKTIBweBiuxIpfnB9HnT-1_DPUpxqagt4sXvjLvPiY1bZOz36oJnXV84KoOHVW8ZYY8es/s1600/pwn2own.jpg","description":"Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero","related":[{"title":"Google Domains Impacted by Recent ccTLD Hijacks","link":"https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own","link":"https://www.securityweek.com/google-pixel-10-exploits-earned-hackers-560000-at-pwn2own/","source":"SecurityWeek","date_rel":"6h ago"},{"title":"Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal","link":"https://therecord.media/lawmakers-warn-of-google-spirit-ai-training-deal","source":"The Record","date_rel":"16h ago"},{"title":"Attackers hijack country-code domains to impersonate Google and other services","link":"https://www.malwarebytes.com/blog/news/2026/10/attackers-hijack-country-code-domains-to-impersonate-google-and-other-services","source":"Malwarebytes Labs","date_rel":"21h ago"},{"title":"Attackers Hijack Three ccTLDs to Obtain Google Certificates","link":"https://www.infosecurity-magazine.com/news/attackers-hijack-cctlds-obtain/","source":"Infosecurity Magazine","date_rel":"22h ago"},{"title":"UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing","link":"https://blog.talosintelligence.com/uat-11985/","source":"Cisco Talos","date_rel":"8 Oct"}]},{"title":"Microsoft Says PKI, HSMs and Security Appliances Must Prepare for Post-Quantum Authentication","link":"https://cybersecuritynews.com/post-quantum-authentication/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cisco Talos","Cyber Security News","Dark Reading","Graham Cluley","Huntress","The Hacker News","The Register Security"],"coverage":8,"cve_ids":[],"summary":"Microsoft is urging organizations to prepare their certificate systems for post-quantum authentication, warning that public key infrastructure (PKI), hardware security modules (HSMs), and security appliances need\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Microsoft-Says-PKI-HSMs-and-Security-Appliances-Must-Prepare-for-Post-Quantum-Authentication.webp","description":"Microsoft is urging organizations to prepare their certificate systems for post-quantum authentication, warning that public key infrastructure (PKI), hardware security modules (HSMs), and security appliances need testing before deployment. Its October 8 guidance says the shift will affect applications, devices, certificate chains, and the processes that keep digital trust working. The message goes beyond protecting encrypted traffic. While many quantum security plans focus on attackers collecting data now to decrypt later, authentication depends on certificates and private keys being issued\u2026","related":[{"title":"Microsoft: Outdated Windows devices will stop receiving security updates","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-outdated-windows-devices-will-lose-security-protection-next-year/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"Microsoft Teams to get support for third-party deepfake detection tools","link":"https://www.bleepingcomputer.com/news/security/microsoft-teams-to-add-third-party-deepfake-detection-impersonation-protection/","source":"Bleeping Computer","date_rel":"8 Oct"},{"title":"U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks","link":"https://thehackernews.com/2026/10/us-offers-up-to-10-million-for-tips-on.html","source":"The Hacker News","date_rel":"8 Oct"},{"title":"Smashing Security podcast #487: Clippy\u2019s crypto comeback","link":"https://grahamcluley.com/smashing-security-podcast-487/","source":"Graham Cluley","date_rel":"7 Oct"},{"title":"Microsoft, Adobe, Apple, and Foxit vulnerabilities","link":"https://blog.talosintelligence.com/microsoft-adobe-apple-and-foxit-vulnerabilities/","source":"Cisco Talos","date_rel":"7 Oct"},{"title":"Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs","link":"https://www.huntress.com/blog/screenconnect-power-bi","source":"Huntress","date_rel":"7 Oct"}]},{"title":"VirusTotal Adds Scanning for Public IPv4 Space to Expose C2 Servers and Malware Infrastructure","link":"https://cybersecuritynews.com/virustotal-adds-daily-internet-scanning/","reason":"Teams","category":"News","sources":["Cisco Security Advisories","Cyber Security News","Dark Reading","Elastic Security Labs","Rapid7 Blog","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"VirusTotal has added daily scanning of the public IPv4 space, giving security teams a new way to find command-and-control (C2) servers and track malware infrastructure. Announced on October 8, 2026, the update records\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/VirusTotal-Adds-Daily-Internet-Scanning-to-Expose-C2-Servers-and-Malware-Infrastructure.webp","description":"VirusTotal has added daily scanning of the public IPv4 space, giving security teams a new way to find command-and-control (C2) servers and track malware infrastructure. Announced on October 8, 2026, the update records exposed services, port activity, banners, and server fingerprints alongside existing threat intelligence. The change helps researchers look beyond an IP address\u2019s detection score. Earlier reports showed hosting details, passive DNS records, and files that contacted an address. The new data shows what a server exposes now, helping analysts find related hosts that have no malware\u2026","related":[{"title":"Cisco Meraki Security Hardening Release: October 2026","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Meraki%20Security%20Hardening%20Release:%20October%202026%26vs_k=1","source":"Cisco Security Advisories","date_rel":"8 Oct"},{"title":"Introducing AlertZero: Inbox zero for your alert queue","link":"https://www.elastic.co/security-labs/blog/ai-soc-automation-alertzero","source":"Elastic Security Labs","date_rel":"8 Oct"},{"title":"Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws","link":"https://thehackernews.com/2026/10/anthropic-expands-claude-access-for.html","source":"The Hacker News","date_rel":"7 Oct"},{"title":"IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams","link":"https://www.darkreading.com/cybersecurity-operations/ai-reshaping-ciso-budgets-security-teams","source":"Dark Reading","date_rel":"6 Oct"},{"title":"Securing Agent-to-Agent Communication: The Next Identity Frontier","link":"https://www.rapid7.com/blog/post/ai-securing-agent-to-agent-communication-next-identity-frontier","source":"Rapid7 Blog","date_rel":"6 Oct"}]},{"title":"Low-cost Android phones ship with residential proxy malware","link":"https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/","reason":"Android","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Malwarebytes Labs","SecurityWeek"],"coverage":4,"cve_ids":[],"summary":"A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad\u2026","source":"Bleeping Computer","date_rel":"17h ago","thumbnail":"","description":"A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.","related":[{"title":"Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries","link":"https://www.securityweek.com/pre-baked-firmware-malware-hits-budget-android-devices-in-150-countries/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"Google issues Android security updates: who can get them and how","link":"https://www.malwarebytes.com/blog/bugs/2026/10/google-issues-android-security-updates-who-can-get-them-and-how","source":"Malwarebytes Labs","date_rel":"7 Oct"},{"title":"Android security advisory \u2013 October 2026 monthly rollup (AV26-1003)","link":"https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-october-2026-monthly-rollup-av26-1003","source":"CCCS Alerts & Advisories","date_rel":"6 Oct"}]},{"title":"Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets","link":"https://www.theregister.com/ai-and-ml/2026/10/06/zombie-instructions-on-carefully-constructed-web-pages-could-trick-github-copilot-cli-into-sharing-secrets/5301206","reason":"Github","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Register Security"],"coverage":3,"cve_ids":[],"summary":"GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to\u2026","source":"The Register Security","date_rel":"6 Oct","thumbnail":"https://image.theregister.com/?imageId=5243747&width=800","description":"GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection\u2026","related":[{"title":"FakeGit malware campaign returns with 17,610 malicious GitHub repos","link":"https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/","source":"Bleeping Computer","date_rel":"19h ago"},{"title":"GitHub security advisory (AV26-1007)","link":"https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-1007","source":"CCCS Alerts & Advisories","date_rel":"7 Oct"}]},{"title":"Cisco warns of critical flaws allowing Nexus switch takeover","link":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/","reason":"Cisco","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","SecurityWeek"],"coverage":3,"cve_ids":[],"summary":"Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.","source":"Bleeping Computer","date_rel":"21h ago","thumbnail":"","description":"","related":[{"title":"Cisco Patches a Dozen Critical Vulnerabilities","link":"https://www.securityweek.com/cisco-patches-a-dozen-critical-vulnerabilities/","source":"SecurityWeek","date_rel":"21h ago"},{"title":"Cisco security advisory (AV26-1020)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-1020","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]},{"title":"Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer","link":"https://www.huntress.com/blog/ahsaycbs-flaws-exploit","reason":"CVE-2026-105133","category":"Threat Intel","sources":["Huntress","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-105133","CVE-2026-105134"],"summary":"Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.","source":"Huntress","date_rel":"16h ago","thumbnail":"https://cdn.builder.io/api/v1/image/assets%2F3eb6f92aedf74f109c7b4b0897ec39a8%2F266936e4b61b4dd6821599adf741b9db","description":"","related":[{"title":"Unpatched AhsayCBS Vulnerabilities Exploited in the Wild","link":"https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/","source":"SecurityWeek","date_rel":"2h ago"}]},{"title":"Let\u2019s Encrypt Cuts TLS Certificate Lifetimes From 90 to 64 Days Starting February 2027","link":"https://cybersecuritynews.com/lets-encrypt-tls-certificate-lifetime-64-days/","reason":"Certificate Lifetimes Starting","category":"News","sources":["Ars Technica Security","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"Let\u2019s Encrypt will cut its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, giving website operators less time between renewals. The change applies to certificates issued or renewed from\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Lets-Encrypt-certificate-lifetime.webp","description":"Let\u2019s Encrypt will cut its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, giving website operators less time between renewals. The change applies to certificates issued or renewed from that date, while subscribers can still choose shorter certificate profiles offering 45 days or roughly six days. Let\u2019s Encrypt Certificate Lifetime According to the October 7 announcement published by Let\u2019s Encrypt , the nonprofit certificate authority confirmed the schedule. Existing certificates will remain valid until their normal expiry dates, and Let\u2019s Encrypt will not\u2026","related":[{"title":"Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027","link":"https://arstechnica.com/gadgets/2026/10/lets-encrypt-cuts-certificate-lifetimes-to-64-days-starting-february-2027/","source":"Ars Technica Security","date_rel":"16h ago"}]},{"title":"Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details","link":"https://thehackernews.com/2026/10/atlassian-data-center-flaw-draws.html","reason":"Atlassian","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw\u2026","source":"The Hacker News","date_rel":"7 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEityRbZfy1N9Y0SuqWl7yeWTYMjeirrTbDx719fM65Be6yXOt2Zl0YweAi0hAfswNzV_LrHa4eFCpcCemC3FNwxZve4bPkSelQiRnCdXpZofAnI7Si96nULBV6i25jgFaZkEY1T3LuPRhj6QzTSsWHZtLuoH1zXlLKZN3WwSiKS7QoY_Zug0CtaaCGozT6N/s1600/jira-attack.jpg","description":"Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software","related":[{"title":"Critical Flaw in Multiple Atlassian Products Exploited in the Wild","link":"https://www.infosecurity-magazine.com/news/critical-vulnerability-atlassian/","source":"Infosecurity Magazine","date_rel":"8 Oct"},{"title":"Atlassian security advisory (AV26-1002) - Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/atlassian-security-advisory-av26-1002","source":"CCCS Alerts & Advisories","date_rel":"7 Oct"}]},{"title":"Citrix gives NetScaler admins another critical reason to patch","link":"https://www.theregister.com/security/2026/10/09/citrix-gives-netscaler-admins-another-critical-reason-to-patch/5302212","reason":"CVE-2026-107406","category":"News","sources":["SecurityWeek","The Register Security"],"coverage":2,"cve_ids":["CVE-2026-107406"],"summary":"Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to\u2026","source":"The Register Security","date_rel":"1h ago","thumbnail":"https://image.theregister.com/?imageId=5302230&width=800","description":"Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration\u2026","related":[{"title":"Citrix Urges Immediate Patching of Critical NetScaler Vulnerability","link":"https://www.securityweek.com/citrix-urges-immediate-patching-of-critical-netscaler-vulnerability/","source":"SecurityWeek","date_rel":"6h ago"}]}],"worth_reading":[{"title":"Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents","link":"https://www.tenable.com/blog/tenable-openai-security-vetting-open-source-ai-agents-exchange-inspector","reason":"Exchange","category":"Research","sources":["Bleeping Computer","Tenable Blog"],"coverage":2,"cve_ids":[],"summary":"Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here\u2019s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already\u2026","source":"Tenable Blog","date_rel":"8 Oct","thumbnail":"","description":"Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here\u2019s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed. Key takeaways Every Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code and threat model. Tenable security researchers then verify runtime behavior in a clean\u2026","related":[{"title":"Uranium crypto exchange hacker convicted for stealing $53 million","link":"https://www.bleepingcomputer.com/news/security/uranium-crypto-exchange-hacker-found-guilty-of-53-million-theft/","source":"Bleeping Computer","date_rel":"23h ago"}]},{"title":"CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products","link":"https://www.rapid7.com/blog/post/etr-cve-2026-21589-critical-unauthenticated-arbitrary-file-access-in-atlassian-products","reason":"CVE-2026-21589","category":"Research","sources":["Rapid7 Blog","SANS Internet Storm Center","watchTowr Labs"],"coverage":3,"cve_ids":["CVE-2026-21589"],"summary":"Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira\u2026","source":"Rapid7 Blog","date_rel":"7 Oct","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration\u2026","related":[{"title":"Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)","link":"https://isc.sans.edu/diary/rss/33406","source":"SANS Internet Storm Center","date_rel":"7 Oct"},{"title":"You Won\u2019t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)","link":"https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/","source":"watchTowr Labs","date_rel":"6 Oct"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-96207","vendor":"Microsoft","product":"Microsoft Partner Center","severity":"CRITICAL","score":10.0,"description":"Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-295","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","fix":false,"fix_url":"","refs":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96207"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-96207"},{"id":"CVE-2026-106126","vendor":"Microsoft","product":"Tenable Identity Exposure (SaaS)","severity":"CRITICAL","score":9.9,"description":"A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.tenable.com/security/tns-2026-27"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-106126"},{"id":"CVE-2026-94510","vendor":"Microsoft","product":"Microsoft Bookings","severity":"CRITICAL","score":9.9,"description":"Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L","fix":false,"fix_url":"","refs":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-94510"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-94510"},{"id":"CVE-2026-105110","vendor":"Iskratel","product":"Innbox","severity":"CRITICAL","score":9.8,"description":"OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0279,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/BlackHatExploitation/innbox_root"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105110"},{"id":"CVE-2026-92555","vendor":"AKIN Software Computer Import-Export Industry and Trade Co. Ltd.","product":"AKINSOFT WOLVOX Control Panel","severity":"CRITICAL","score":9.8,"description":"Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources.\n\nThis issue affects AKINSOFT WOLVOX Co\u2026","cwe":"CWE-201","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1273"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-92555"},{"id":"CVE-2026-16340","vendor":"IBM","product":"DataPower Gateway 10.6CD","severity":"CRITICAL","score":9.8,"description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-\u2026","cwe":"CWE-787","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.ibm.com/support/pages/node/7289775"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-16340"},{"id":"CVE-2026-14991","vendor":"IBM","product":"DataPower Gateway 10.6CD","severity":"CRITICAL","score":9.8,"description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffe\u2026","cwe":"CWE-787","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.ibm.com/support/pages/node/7289775"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-14991"},{"id":"CVE-2026-15762","vendor":"IBM","product":"DataPower Gateway 10.6CD","severity":"CRITICAL","score":9.8,"description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.","cwe":"CWE-787","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.ibm.com/support/pages/node/7289775"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-15762"},{"id":"CVE-2026-14269","vendor":"IBM","product":"DataPower Gateway 10.6CD","severity":"CRITICAL","score":9.8,"description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote \u2026","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.ibm.com/support/pages/node/7289775"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-14269"},{"id":"CVE-2026-14502","vendor":"IBM","product":"DataPower Gateway 10.6CD","severity":"CRITICAL","score":9.8,"description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.ibm.com/support/pages/node/7289775"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-14502"}],"vendor_spikes":[{"vendor":"IBM","count":93,"critical_count":17},{"vendor":"Microsoft","count":39,"critical_count":7},{"vendor":"Progressive Robot Ltd","count":17,"critical_count":0},{"vendor":"Unknown","count":16,"critical_count":1},{"vendor":"MongoDB","count":15,"critical_count":0},{"vendor":"WordPress","count":13,"critical_count":0},{"vendor":"ImageMagick","count":13,"critical_count":0},{"vendor":"banq","count":13,"critical_count":0},{"vendor":"Go standard library","count":12,"critical_count":0},{"vendor":"pydantic","count":10,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":19,"new_cve_count":444,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-105133":{"anchor":"#dev-7","rank":7,"coverage":2},"CVE-2026-105134":{"anchor":"#dev-7","rank":7,"coverage":2},"CVE-2026-107406":{"anchor":"#dev-10","rank":10,"coverage":2}}}