{"schema":1,"items":[{"id":"nvd:CVE-2026-12541","kind":"security","severity":"warning","title":"CVE-2026-12541 (CVSS 8.2)","body":"A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.","publishedAt":"2026-10-01T17:17:20.19Z","expiresAt":"2026-10-31T17:17:20.19Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12541"},{"id":"nvd:CVE-2026-12540","kind":"security","severity":"warning","title":"CVE-2026-12540 (CVSS 8.2)","body":"A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, \u0022, or |) to break out of the intended command and execute arbitrary code.","publishedAt":"2026-10-01T17:17:20.053Z","expiresAt":"2026-10-31T17:17:20.053Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12540"},{"id":"nvd:CVE-2026-79898","kind":"security","severity":"critical","title":"CVE-2026-79898 (CVSS 9.1)","body":"Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.","publishedAt":"2026-10-01T15:17:31.623Z","expiresAt":"2026-10-31T15:17:31.623Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79898"},{"id":"nvd:CVE-2026-103262","kind":"security","severity":"warning","title":"CVE-2026-103262 (CVSS 7.5)","body":"Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.","publishedAt":"2026-10-01T11:17:21.05Z","expiresAt":"2026-10-31T11:17:21.05Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103262"},{"id":"nvd:CVE-2026-103251","kind":"security","severity":"warning","title":"CVE-2026-103251 (CVSS 7.1)","body":"n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without authentication.","publishedAt":"2026-10-01T11:17:18.973Z","expiresAt":"2026-10-31T11:17:18.973Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103251"},{"id":"nvd:CVE-2026-103250","kind":"security","severity":"warning","title":"CVE-2026-103250 (CVSS 8.1)","body":"n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that fails to validate the sessionId parameter. Unauthenticated attackers can supply MongoDB query operators in the sessionId field to access conversation histories from other users and perform unauthorized write and delete operations.","publishedAt":"2026-10-01T11:17:18.777Z","expiresAt":"2026-10-31T11:17:18.777Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103250"},{"id":"kev:CVE-2026-104286","kind":"security","severity":"critical","title":"Fortinet FortiMail \u2014 Fortinet FortiMail Path Traversal Vulnerability","body":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.","publishedAt":"2026-10-01T00:00:00Z","expiresAt":"2026-10-31T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104286"},{"id":"nvd:CVE-2026-101884","kind":"security","severity":"warning","title":"CVE-2026-101884 (CVSS 7.5)","body":"OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.","publishedAt":"2026-09-30T20:17:20.663Z","expiresAt":"2026-10-30T20:17:20.663Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101884"},{"id":"nvd:CVE-2026-87004","kind":"security","severity":"warning","title":"CVE-2026-87004 (CVSS 8.1)","body":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider\u0027s token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.","publishedAt":"2026-09-30T18:18:41.47Z","expiresAt":"2026-10-30T18:18:41.47Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87004"},{"id":"nvd:CVE-2026-53605","kind":"security","severity":"warning","title":"CVE-2026-53605 (CVSS 7.8)","body":"Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.","publishedAt":"2026-09-30T18:18:37.213Z","expiresAt":"2026-10-30T18:18:37.213Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53605"},{"id":"nvd:CVE-2026-62308","kind":"security","severity":"critical","title":"CVE-2026-62308 (CVSS 9.1)","body":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.","publishedAt":"2026-09-30T17:16:49.423Z","expiresAt":"2026-10-30T17:16:49.423Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62308"},{"id":"nvd:CVE-2026-55494","kind":"security","severity":"critical","title":"CVE-2026-55494 (CVSS 9.8)","body":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns successfully if Config.AGENT_SECRET is empty. This causes protected Agent APIs to become accessible without authentication. This issue has been patched in version 1.30.4.","publishedAt":"2026-09-30T17:16:47.1Z","expiresAt":"2026-10-30T17:16:47.1Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55494"},{"id":"nvd:CVE-2026-55181","kind":"security","severity":"critical","title":"CVE-2026-55181 (CVSS 9.4)","body":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer\u0027s OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects the user to the configured OIDC authorization endpoint. This bypasses the intended OIDC disable switch. This issue has been patched in version 1.30.3.","publishedAt":"2026-09-30T17:16:46.937Z","expiresAt":"2026-10-30T17:16:46.937Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55181"},{"id":"nvd:CVE-2026-103232","kind":"security","severity":"warning","title":"CVE-2026-103232 (CVSS 7.3)","body":"A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","publishedAt":"2026-09-30T17:16:42Z","expiresAt":"2026-10-30T17:16:42Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103232"},{"id":"nvd:CVE-2026-103231","kind":"security","severity":"warning","title":"CVE-2026-103231 (CVSS 7.3)","body":"A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.","publishedAt":"2026-09-30T16:17:08.657Z","expiresAt":"2026-10-30T16:17:08.657Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103231"},{"id":"nvd:CVE-2026-103230","kind":"security","severity":"warning","title":"CVE-2026-103230 (CVSS 7.3)","body":"A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.","publishedAt":"2026-09-30T16:17:08.463Z","expiresAt":"2026-10-30T16:17:08.463Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103230"},{"id":"nvd:CVE-2026-103229","kind":"security","severity":"warning","title":"CVE-2026-103229 (CVSS 7.3)","body":"A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.","publishedAt":"2026-09-30T16:17:08.243Z","expiresAt":"2026-10-30T16:17:08.243Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103229"},{"id":"nvd:CVE-2026-100254","kind":"security","severity":"warning","title":"CVE-2026-100254 (CVSS 8.8)","body":"In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings","publishedAt":"2026-09-30T16:16:55.947Z","expiresAt":"2026-10-30T16:16:55.947Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100254"},{"id":"nvd:CVE-2026-93994","kind":"security","severity":"warning","title":"CVE-2026-93994 (CVSS 8.1)","body":"Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods \u0022publickey,publickey\u0022. Apache MINA SSHD provides an equivalent configuration mechanism.\n\n\n\n\nIn Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass.\n\n\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.","publishedAt":"2026-09-30T10:17:17.46Z","expiresAt":"2026-10-30T10:17:17.46Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93994"},{"id":"kev:CVE-2026-76504","kind":"security","severity":"critical","title":"Cisco Catalyst SD-WAN Manager \u2014 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability","body":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.","publishedAt":"2026-09-30T00:00:00Z","expiresAt":"2026-10-30T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76504"},{"id":"nvd:CVE-2026-102925","kind":"security","severity":"warning","title":"CVE-2026-102925 (CVSS 7.8)","body":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment\u0027s recorded directory is absent; in the fish script, crafted Tcl or Tk library paths reach __TCL_LIBRARY__ or __TK_LIBRARY__. The surplus quotes can terminate the data-only quoted run and leave shell metacharacters parsed as commands when a user sources the activation script, allowing code execution with that user\u0027s privileges. This issue is fixed in version 21.7.13.","publishedAt":"2026-09-29T21:17:18.57Z","expiresAt":"2026-10-29T21:17:18.57Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102925"},{"id":"nvd:CVE-2026-53988","kind":"security","severity":"critical","title":"CVE-2026-53988 (CVSS 10.0)","body":"Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts.","publishedAt":"2026-09-29T20:17:20.403Z","expiresAt":"2026-10-29T20:17:20.403Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53988"},{"id":"nvd:CVE-2026-102827","kind":"security","severity":"warning","title":"CVE-2026-102827 (CVSS 8.1)","body":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --exec forms can therefore bypass detectVulnerableFlags, reach git push against a local or file remote or an attacker-influenced receive-pack target, and cause Git to invoke an attacker-selected command in consumers that expose those arguments. The clone-side abbreviation handling does not protect the push path. This issue is fixed in 4.0.0.","publishedAt":"2026-09-29T19:17:25.05Z","expiresAt":"2026-10-29T19:17:25.05Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102827"},{"id":"nvd:CVE-2026-102826","kind":"security","severity":"warning","title":"CVE-2026-102826 (CVSS 8.1)","body":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and the initial remediation does not cover includeIf.\u003Ccondition\u003E.path, allowing the same file-loading primitive through a conditional include. A loaded configuration can set an executable Git option such as core.sshCommand, which Git invokes during the clone operation with the privileges of the Node.js process. Exploitation requires the application to pass attacker-influenced custom arguments and requires an attacker-controlled file that the process can read. This issue is fixed in 4.0.0.","publishedAt":"2026-09-29T19:17:24.883Z","expiresAt":"2026-10-29T19:17:24.883Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102826"},{"id":"kev:CVE-2026-86950","kind":"security","severity":"critical","title":"Apple Multiple Products \u2014 Apple Multiple Products Out-of-Bounds Write Vulnerability","body":"Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.","publishedAt":"2026-09-29T00:00:00Z","expiresAt":"2026-10-29T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86950"},{"id":"kev:CVE-2026-88772","kind":"security","severity":"critical","title":"Citrix NetScaler \u2014 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","body":"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service","publishedAt":"2026-09-27T00:00:00Z","expiresAt":"2026-10-27T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88772"},{"id":"kev:CVE-2026-88771","kind":"security","severity":"critical","title":"Citrix NetScaler \u2014 Citrix NetScaler Improper Input Validation Vulnerability","body":"Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.","publishedAt":"2026-09-27T00:00:00Z","expiresAt":"2026-10-27T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88771"},{"id":"kev:CVE-2026-67279","kind":"security","severity":"critical","title":"MikroTik RouterOS \u2014 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","body":"Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.","publishedAt":"2026-09-25T00:00:00Z","expiresAt":"2026-10-25T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67279"},{"id":"kev:CVE-2026-65660","kind":"security","severity":"critical","title":"Microsoft SharePoint \u2014 Microsoft SharePoint Code Injection Vulnerability","body":"Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.","publishedAt":"2026-09-25T00:00:00Z","expiresAt":"2026-10-25T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65660"},{"id":"kev:CVE-2026-87902","kind":"security","severity":"critical","title":"WordPress Core \u2014 WordPress Core Remote File Inclusion Vulnerability","body":"WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local \u0060.php\u0060 file outside the active theme directories, leading to remote code execution.","publishedAt":"2026-09-25T00:00:00Z","expiresAt":"2026-10-25T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87902"},{"id":"kev:CVE-2026-5430","kind":"security","severity":"critical","title":"WSO2 Multiple Products \u2014 WSO2 Multiple Products Path Traversal Vulnerability","body":"WSO2 API Control Plane, API Manager, Traffic Manager \u0026 Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.","publishedAt":"2026-09-24T00:00:00Z","expiresAt":"2026-10-24T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5430"},{"id":"kev:CVE-2026-71362","kind":"security","severity":"critical","title":"Adobe Commerce and Magento \u2014 Adobe Commerce and Magento Incorrect Authorization Vulnerability","body":"Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.","publishedAt":"2026-09-24T00:00:00Z","expiresAt":"2026-10-24T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71362"},{"id":"kev:CVE-2026-93952","kind":"security","severity":"critical","title":"Arista VeloCloud Orchestrator \u2014 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability","body":"Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.","publishedAt":"2026-09-22T00:00:00Z","expiresAt":"2026-10-22T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93952"},{"id":"kev:CVE-2026-94127","kind":"security","severity":"critical","title":"F5 BIG-IP APM \u2014 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability","body":"F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.","publishedAt":"2026-09-22T00:00:00Z","expiresAt":"2026-10-22T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94127"},{"id":"kev:CVE-2026-93616","kind":"security","severity":"critical","title":"Check Point Multiple Products \u2014 Check Point Multiple Products Path Traversal Vulnerability","body":"Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.","publishedAt":"2026-09-22T00:00:00Z","expiresAt":"2026-10-22T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93616"},{"id":"kev:CVE-2026-85102","kind":"security","severity":"critical","title":"Check Point Multiple Products \u2014 Check Point Multiple Products Improper Certificate Validation Vulnerability","body":"Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.","publishedAt":"2026-09-22T00:00:00Z","expiresAt":"2026-10-22T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85102"},{"id":"kev:CVE-2026-7273","kind":"security","severity":"critical","title":"Zyxel GS1900 Series Switches \u2014 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability","body":"Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.","publishedAt":"2026-09-21T00:00:00Z","expiresAt":"2026-10-21T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7273"},{"id":"kev:CVE-2025-39964","kind":"security","severity":"critical","title":"Linux Kernel \u2014 Linux Kernel Race Condition Vulnerability","body":"Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket\u0027s internal state.","publishedAt":"2026-09-18T00:00:00Z","expiresAt":"2026-10-18T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-39964"},{"id":"kev:CVE-2026-53266","kind":"security","severity":"critical","title":"Linux Kernel \u2014 Linux Kernel Out-of-Bounds Write Vulnerability","body":"Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.","publishedAt":"2026-09-18T00:00:00Z","expiresAt":"2026-10-18T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53266"},{"id":"kev:CVE-2025-39682","kind":"security","severity":"critical","title":"Linux Kernel \u2014 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability","body":"Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.","publishedAt":"2026-09-18T00:00:00Z","expiresAt":"2026-10-18T00:00:00Z","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-39682"}]}