CVE Digest — September 17, 2026
11 CVE
Digest for September 17, 2026: 0 new entries in the CISA KEV catalog and 11 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
- Joomla JCE: rilevato sfruttamento CVE-2026-48907 al fine di distribuire webshell utilizzate per defacement
- LiteLLM: rilevato sfruttamento in rete della CVE-2026-59822
- Rilevate vulnerabilità in prodotti Dell
- Risolte vulnerabilità in Apache NiFi
- Risolte vulnerabilità in prodotti HP
- Risolte vulnerabilità in Docker
- Risolta vulnerabilità in prodotti Check Point
- Risolte vulnerabilità in prodotti Cisco
- Risolte vulnerabilità in Craft CMS
- Aggiornamenti per prodotti Siemens
- Risolte vulnerabilità in ISC BIND 9
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-48907 | – | – | Unknown | Italian CSIRT reports a significant rise in active exploitation of CVE-2026-48907 against exposed web servers. The flaw affects the Joomla Content Editor (JCE) plugin for Joomla! and is used to deploy webshells for website defacement. Already fixed by the vendor and covered by a… | |
| CVE-2026-59822 | – | – | Unknown | Active exploitation detected in the wild for CVE-2026-59822, a vulnerability in LiteLLM by BerriAI, a proxy server used as a gateway to large language models (LLMs). An unauthenticated remote attacker can bypass authentication mechanisms and access MCP tools without valid creden… | |
| rilevate-vulnerabilita-in-prodotti-dell-1 | – | – | Unknown | Dell Technologies security updates fix multiple vulnerabilities across various products: one rated critical and eleven rated high severity. Administrators should review the Dell security advisory for affected products and apply the updates as soon as possible. | |
| risolte-vulnerabilita-in-apache-nifi | – | – | Unknown | Apache Software Foundation released security updates for Apache NiFi and NiFi Registry, open-source platforms for managing, processing and versioning data flows. The fixes address several vulnerabilities, including two rated high severity, that could allow file operations outsid… | |
| risolte-vulnerabilita-in-prodotti-hp | – | – | Unknown | HP released security updates fixing multiple vulnerabilities, four rated critical and five rated high severity, affecting HP AC Print & Scan, HP Output Central and HP Linux Imaging and Printing Software (HPLIP), software solutions for managing printing and scanning functionality… | |
| risolte-vulnerabilita-in-docker-1 | – | – | Unknown | Docker security updates fix two vulnerabilities in Docker Sandboxes: one rated critical and one rated high severity. Organizations using Docker Sandboxes should upgrade to the patched versions to mitigate potential exploitation. | |
| risolta-vulnerabilita-in-prodotti-check-point | – | – | Unknown | Check Point security updates fix a critical-severity vulnerability in the login process of Security Management Server and Log Server. If exploited, a remote attacker could execute arbitrary code on affected systems. Apply the updates immediately. | |
| CVE-2026-76460 | – | – | Unknown | Cisco released security updates addressing multiple new vulnerabilities across various Cisco products: 24 rated critical and 25 rated high severity. Notably, CVE-2026-76460 is being actively exploited in the wild. Prioritize patching affected Cisco devices. | |
| risolte-vulnerabilita-in-craft-cms | – | – | Unknown | Security updates released for Craft CMS, a content management system for building and managing websites and web applications, fixing several vulnerabilities including four rated high severity. Exploitation could allow access to sensitive information, bypass security restrictions… | |
| aggiornamenti-per-prodotti-siemens-27 | – | – | Unknown | Siemens released security updates to fix a vulnerability affecting certain WTV series remote-reading and energy metering devices. Organizations using these devices should review the Siemens advisory and apply the available updates. | |
| risolte-vulnerabilita-in-isc-bind-9 | – | – | Unknown | ISC released security updates for BIND 9 and BIND Supported Preview Edition, DNS request resolution software, fixing several vulnerabilities, seven rated high severity. The flaws can cause abnormal process termination or excessive resource consumption, potentially compromising s… |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.