CVE Digest — September 23, 2026
10 CVE
Critical
Digest for September 23, 2026: 0 new entries in the CISA KEV catalog and 10 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
- Notepad++: disponibili PoC per 6 vulnerabilità
- D-Link: PoC pubblico per lo sfruttamento della CVE-2026-95675
- Vulnerabilità in Moodle
- Risolte vulnerabilità in Google Chrome
- Risolte vulnerabilità su GitHub Enterprise Server
- Adobe: aggiornamenti di sicurezza
- Rilevate vulnerabilità in Erlang/OTP
- Risolte vulnerabilità in prodotti ManageEngine
- Vulnerabilità in prodotti SolarWinds
- WordPress: PoC pubbliche per lo sfruttamento di nuove vulnerabilità
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| notepad-disponibili-poc-per-6-vulnerabilita | – | – | High | Public Proofs of Concept are available for 6 Notepad++ vulnerabilities, 4 rated high severity. Exploitation could allow arbitrary code execution, bypass component integrity verification, and compromise the affected systems. | |
| CVE-2026-95675 | – | 9.8 | Critical | A public PoC is available for CVE-2026-95675, an unauthenticated remote code execution flaw (CVSS 9.8) in D-Link DAP-1360 firmware 6.14 and earlier, an end-of-life device. Crafted requests to the web interface let remote attackers run arbitrary commands as root and fully comprom… | |
| vulnerabilita-in-moodle-6 | – | – | Unknown | Two new vulnerabilities were reported in Moodle, the open-source e-learning platform. If exploited, they could allow a malicious user to access sensitive information and bypass security features on the affected systems. | |
| risolte-vulnerabilita-in-google-chrome-75 | – | – | Critical | Google released a Chrome update fixing 108 security vulnerabilities, including 11 rated critical and 25 rated high. Users should apply the update to the latest browser version as soon as possible. | |
| risolte-vulnerabilita-su-github-enterprise-server-2 | – | – | Critical | GitHub released security updates fixing 3 GitHub Enterprise Server vulnerabilities, including 1 critical and 1 high severity. Exploitation could allow arbitrary code execution, security mechanism bypass, and access to sensitive information. | |
| adobe-aggiornamenti-di-sicurezza-24 | – | – | Critical | Adobe released security updates fixing multiple vulnerabilities, including 9 critical and 17 high severity, across InDesign, Content Credentials Rust SDK, C2PA Tool, Bridge, Connect, Experience Manager Forms, Substance 3D Modeler, Premiere, and Premiere Pro. | |
| otp-4 | – | – | Critical | Three new vulnerabilities were reported in Erlang/OTP, the open-source platform for building highly available distributed systems: 1 critical and 2 high severity. Exploitation could allow authentication bypass, access to sensitive information, and availability compromise. | |
| risolte-vulnerabilita-in-prodotti-manageengine | – | – | Unknown | Zoho security updates fix 2 vulnerabilities in ManageEngine ADSelfService Plus, the account management solution for Active Directory environments. They could allow a remote attacker to execute arbitrary code or bypass REST API authentication mechanisms. | |
| vulnerabilita-in-prodotti-solarwinds | – | – | Critical | SolarWinds updates fix 2 vulnerabilities in Observability Self-Hosted, the infrastructure and application monitoring platform: 1 critical and 1 high severity. Under certain configurations, an unauthenticated remote attacker could execute arbitrary code and compromise the affecte… | |
| wordpress-poc-pubbliche-per-lo-sfruttamento-di-nuove-vulnerabilita | – | – | Unknown | Public Proofs of Concept are available for 3 WordPress Core vulnerabilities that the vendor has already patched. Organizations should verify they are running a fixed version to prevent exploitation. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.