CVE Digest

CVE Digest — September 14, 2026

  • Security Bulletin
7 CVE 1 KEV
CVEProductCVSSSeveritySummaryReferences
CVE-2026-76461 KEVCisco Secure Email GatewayUnknownCisco Secure Email Gateway (AsyncOS) has a SQL injection flaw letting an unauthenticated remote attacker execute arbitrary commands as root. Listed in CISA KEV; apply vendor mitigations per BOD 26-04.
CVE-2026-76461UnknownCisco released security updates fixing 6 vulnerabilities (5 critical, 1 high) in Secure Email Gateway and Secure Email and Web Manager. Active exploitation of CVE-2026-76461 is reported; patch promptly.
risolta-vulnerabilita-in-parallels-desktop-for-macUnknownParallels released security updates fixing a high-severity vulnerability in Parallels Desktop for Mac, software for running virtual machines on macOS. Users should update to the latest version.
risolta-vulnerabilita-in-misp-1UnknownA high-severity vulnerability in MISP, the open-source platform for sharing and analyzing cyber threat intelligence, has been fixed. Users should apply the available updates.
risolta-vulnerabilita-in-mongodb-serverUnknownSecurity updates fix a high-severity flaw in MongoDB Server. An authenticated attacker with read/write database privileges could compromise service availability and manipulate data on affected systems.
CVE-2026-42016UnknownActive exploitation of two high-severity, already-patched vulnerabilities (CVE-2026-42016, CVE-2026-42018) in JFrog Artifactory, a software artifact management and distribution platform, has been detected.
CVE-2026-84869UnknownActive exploitation of the critical, already-patched vulnerability CVE-2026-84869 in ConnectWise ScreenConnect has been detected. Users should update immediately.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.