CVE Digest

CVE Digest — September 10, 2026

  • Security Bulletin
8 CVE 2 KEV

Digest for September 10, 2026: 2 new entries in the CISA KEV catalog and 6 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

ACN advisories (Italy)

CVEProductCVSSSeveritySummaryReferences
CVE-2026-86060 KEVMikroTik RouterOSUnknownMikroTik RouterOS improperly neutralizes command argument delimiters, letting an attacker change the trusted RouterOS policy mask and escalate privileges. Added to CISA KEV on 2026-09-10; apply vendor mitigations per BOD 26-04 guidance.
CVE-2026-67277 KEVMikroTik RouterOSUnknownMikroTik RouterOS lacks authentication for a critical function in the btest service, enabling kernel memory disclosure and denial of service. Added to CISA KEV on 2026-09-10; apply vendor mitigations per BOD 26-04 guidance.
risolte-vulnerabilita-in-palo-alto-networks-pan-osUnknownPalo Alto Networks released PAN-OS security updates fixing several vulnerabilities in next-generation firewalls and centralized security management products, including one rated high severity. Update PAN-OS promptly.
rapid7-risolte-vulnerabilita-in-velociraptorUnknownRapid7 released security updates for Velociraptor, the open-source digital forensics and incident response platform, fixing several vulnerabilities, including one rated critical and one high severity.
risolta-vulnerabilita-in-prodotti-esetUnknownA high-severity vulnerability was fixed across several ESET products; if exploited it could allow an attacker to escalate privileges on affected systems. Apply the latest ESET updates.
risolta-vulnerabilita-in-fortra-goanywhere-mftUnknownFortra security updates fix a high-severity vulnerability in GoAnywhere MFT, the secure file transfer and centralized management platform. Apply the updates promptly.
risolte-vulnerabilita-in-prodotti-check-pointUnknownCheck Point released updates fixing two critical vulnerabilities in Security Gateway, Security Management and Spark Firewall, which could let an unauthenticated remote attacker execute arbitrary code on compromised systems.
campagna-di-phishing-a-tema-registro-imprese-UnknownCSIRT reported an email phishing campaign tricking victims into entering business data on a portal that misuses the Registro Imprese and Chamber of Commerce names and logos to steal their information.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.