CVE Digest

CVE Digest — September 21, 2026

  • Security Bulletin
6 CVE 1 KEV Critical

Digest for September 21, 2026: 1 new entry in the CISA KEV catalog and 5 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

ACN advisories (Italy)

CVEProductCVSSSeveritySummaryReferences
CVE-2026-7273 KEVZyxel GS1900 Series Switches8.8HighZyxel GS1900 series switches have a stack-based buffer overflow in the CGI program (CWE-121). A LAN-based unauthenticated attacker can execute OS commands via a crafted HTTP request. Affects GS1900-48HPv2 firmware up to 2.90(ABTQ.1)C0. CVSS 8.8. Added to CISA KEV 2026-09-21; app…
CWE-121
risolte-vulnerabilita-in-prodotti-zohocorp-manageengine-1––HighZohocorp released updates fixing two high-severity vulnerabilities in ManageEngine DataSecurity Plus. If exploited, they could allow an attacker to bypass authentication controls and compromise data integrity on affected systems. Upgrade to patched versions.
risolte-vulnerabilita-in-synology-diskstation-manager-dsm-––CriticalMultiple security vulnerabilities were found in Synology DiskStation Manager (DSM): two rated high and two critical. Exploitation could let an attacker read or write arbitrary files on the filesystem and compromise availability of affected systems. Apply Synology updates.
CVE-2026-55556–8.2HighPublic PoCs are available for CVE-2026-55556 and CVE-2026-61548 in rsyslog, already patched by the vendor. The imhttp Basic Authentication path has a heap overflow (CWE-122) letting an unauthenticated remote attacker overwrite adjacent heap memory and crash the process, interrup…
rilevate-vulnerabilita-in-exim-2––HighTwo high-severity vulnerabilities were found in the Exim mail server. If exploited, they could allow an attacker to access sensitive information, modify data or code without authorization, and compromise availability on affected systems. Apply vendor updates.
rilevate-vulnerabilita-in-prodotti-mongodb-5––CriticalSecurity updates fix new vulnerabilities in MongoDB C Driver and Mongoid, three rated critical and six high. Exploitation could allow bypassing security mechanisms, accessing sensitive information, altering or deleting data, and compromising service availability. Update affected…

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.