CVE Digest

CVE Digest — September 24, 2026

  • Security Bulletin
7 CVE 2 KEV Critical

Digest for September 24, 2026: 2 new entries in the CISA KEV catalog and 5 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

ACN advisories (Italy)

CVEProductCVSSSeveritySummaryReferences
CVE-2026-5430 KEVWSO2 Multiple Products10CriticalWSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway contain a path traversal vulnerability enabling unrestricted file upload that can lead to remote code execution. Exploited in the wild; apply vendor mitigations per CISA BOD 26-04 guidance.
CWE-347
CVE-2026-71362 KEVAdobe Commerce and Magento9.1CriticalAdobe Commerce and Magento contain an incorrect authorization vulnerability allowing privilege escalation and elevated access to sensitive resources without any user interaction. Exploited in the wild; apply vendor mitigations per CISA BOD 26-04 guidance.
CWE-863
mf––HighPaperCut NG/MF print management and monitoring software is affected by 3 vulnerabilities, 2 rated high severity. Under certain conditions, exploitation could let a remote attacker execute arbitrary code on affected systems. Apply vendor updates.
rilevate-vulnerabilita-in-apache-tomcat-2––CriticalApache released security updates fixing 15 vulnerabilities (4 critical, 9 high) in Apache Tomcat and Tomcat Native. Exploitation could allow attackers to bypass security mechanisms, tamper with HTTP request content, and compromise service availability.
ee-22––CriticalSecurity updates fix 7 vulnerabilities (1 high, 2 critical) in GitLab Community Edition and Enterprise Edition. Exploitation could allow a malicious user to access confidential information or execute arbitrary code on affected systems.
risolte-vulnerabilita-in-prodotti-manageengine-1––CriticalZoho security updates address 14 vulnerabilities (2 critical, 12 high) across ManageEngine Applications Manager, OpManager, Firewall Analyzer, Network Configuration Manager and related product editions. Apply vendor patches promptly.
rilevata-vulnerabilita-in-watchguard––HighA high-severity vulnerability affects WatchGuard AuthPoint Authentication Gateway, the on-premise MFA component connecting Active Directory/LDAP and handling RADIUS authentication. Exploitation could let an attacker bypass authentication mechanisms. Apply vendor updates.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.