CVE Digest — September 10, 2026
8 CVE
2 KEV
Digest for September 10, 2026: 2 new entries in the CISA KEV catalog and 6 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-86060 KEV | MikroTik RouterOS | – | Unknown | MikroTik RouterOS improperly neutralizes command argument delimiters, letting an attacker change the trusted RouterOS policy mask and escalate privileges. Added to CISA KEV on 2026-09-10; apply vendor mitigations per BOD 26-04 guidance. | |
| CVE-2026-67277 KEV | MikroTik RouterOS | – | Unknown | MikroTik RouterOS lacks authentication for a critical function in the btest service, enabling kernel memory disclosure and denial of service. Added to CISA KEV on 2026-09-10; apply vendor mitigations per BOD 26-04 guidance. | |
| risolte-vulnerabilita-in-palo-alto-networks-pan-os | – | – | Unknown | Palo Alto Networks released PAN-OS security updates fixing several vulnerabilities in next-generation firewalls and centralized security management products, including one rated high severity. Update PAN-OS promptly. | |
| rapid7-risolte-vulnerabilita-in-velociraptor | – | – | Unknown | Rapid7 released security updates for Velociraptor, the open-source digital forensics and incident response platform, fixing several vulnerabilities, including one rated critical and one high severity. | |
| risolta-vulnerabilita-in-prodotti-eset | – | – | Unknown | A high-severity vulnerability was fixed across several ESET products; if exploited it could allow an attacker to escalate privileges on affected systems. Apply the latest ESET updates. | |
| risolta-vulnerabilita-in-fortra-goanywhere-mft | – | – | Unknown | Fortra security updates fix a high-severity vulnerability in GoAnywhere MFT, the secure file transfer and centralized management platform. Apply the updates promptly. | |
| risolte-vulnerabilita-in-prodotti-check-point | – | – | Unknown | Check Point released updates fixing two critical vulnerabilities in Security Gateway, Security Management and Spark Firewall, which could let an unauthenticated remote attacker execute arbitrary code on compromised systems. | |
| campagna-di-phishing-a-tema-registro-imprese- | – | – | Unknown | CSIRT reported an email phishing campaign tricking victims into entering business data on a portal that misuses the Registro Imprese and Chamber of Commerce names and logos to steal their information. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.