CVE Digest

CVE Digest — September 23, 2026

  • Security Bulletin
10 CVE Critical
CVEProductCVSSSeveritySummaryReferences
notepad-disponibili-poc-per-6-vulnerabilita––HighPublic Proofs of Concept are available for 6 Notepad++ vulnerabilities, 4 rated high severity. Exploitation could allow arbitrary code execution, bypass component integrity verification, and compromise the affected systems.
CVE-2026-95675–9.8CriticalA public PoC is available for CVE-2026-95675, an unauthenticated remote code execution flaw (CVSS 9.8) in D-Link DAP-1360 firmware 6.14 and earlier, an end-of-life device. Crafted requests to the web interface let remote attackers run arbitrary commands as root and fully comprom…
vulnerabilita-in-moodle-6––UnknownTwo new vulnerabilities were reported in Moodle, the open-source e-learning platform. If exploited, they could allow a malicious user to access sensitive information and bypass security features on the affected systems.
risolte-vulnerabilita-in-google-chrome-75––CriticalGoogle released a Chrome update fixing 108 security vulnerabilities, including 11 rated critical and 25 rated high. Users should apply the update to the latest browser version as soon as possible.
risolte-vulnerabilita-su-github-enterprise-server-2––CriticalGitHub released security updates fixing 3 GitHub Enterprise Server vulnerabilities, including 1 critical and 1 high severity. Exploitation could allow arbitrary code execution, security mechanism bypass, and access to sensitive information.
adobe-aggiornamenti-di-sicurezza-24––CriticalAdobe released security updates fixing multiple vulnerabilities, including 9 critical and 17 high severity, across InDesign, Content Credentials Rust SDK, C2PA Tool, Bridge, Connect, Experience Manager Forms, Substance 3D Modeler, Premiere, and Premiere Pro.
otp-4––CriticalThree new vulnerabilities were reported in Erlang/OTP, the open-source platform for building highly available distributed systems: 1 critical and 2 high severity. Exploitation could allow authentication bypass, access to sensitive information, and availability compromise.
risolte-vulnerabilita-in-prodotti-manageengine––UnknownZoho security updates fix 2 vulnerabilities in ManageEngine ADSelfService Plus, the account management solution for Active Directory environments. They could allow a remote attacker to execute arbitrary code or bypass REST API authentication mechanisms.
vulnerabilita-in-prodotti-solarwinds––CriticalSolarWinds updates fix 2 vulnerabilities in Observability Self-Hosted, the infrastructure and application monitoring platform: 1 critical and 1 high severity. Under certain configurations, an unauthenticated remote attacker could execute arbitrary code and compromise the affecte…
wordpress-poc-pubbliche-per-lo-sfruttamento-di-nuove-vulnerabilita––UnknownPublic Proofs of Concept are available for 3 WordPress Core vulnerabilities that the vendor has already patched. Organizations should verify they are running a fixed version to prevent exploitation.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.