CVE Digest — September 24, 2026
7 CVE
2 KEV
Critical
Digest for September 24, 2026: 2 new entries in the CISA KEV catalog and 5 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-5430 KEV | WSO2 Multiple Products | 10 | Critical | WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway contain a path traversal vulnerability enabling unrestricted file upload that can lead to remote code execution. Exploited in the wild; apply vendor mitigations per CISA BOD 26-04 guidance. CWE-347 | |
| CVE-2026-71362 KEV | Adobe Commerce and Magento | 9.1 | Critical | Adobe Commerce and Magento contain an incorrect authorization vulnerability allowing privilege escalation and elevated access to sensitive resources without any user interaction. Exploited in the wild; apply vendor mitigations per CISA BOD 26-04 guidance. CWE-863 | |
| mf | – | – | High | PaperCut NG/MF print management and monitoring software is affected by 3 vulnerabilities, 2 rated high severity. Under certain conditions, exploitation could let a remote attacker execute arbitrary code on affected systems. Apply vendor updates. | |
| rilevate-vulnerabilita-in-apache-tomcat-2 | – | – | Critical | Apache released security updates fixing 15 vulnerabilities (4 critical, 9 high) in Apache Tomcat and Tomcat Native. Exploitation could allow attackers to bypass security mechanisms, tamper with HTTP request content, and compromise service availability. | |
| ee-22 | – | – | Critical | Security updates fix 7 vulnerabilities (1 high, 2 critical) in GitLab Community Edition and Enterprise Edition. Exploitation could allow a malicious user to access confidential information or execute arbitrary code on affected systems. | |
| risolte-vulnerabilita-in-prodotti-manageengine-1 | – | – | Critical | Zoho security updates address 14 vulnerabilities (2 critical, 12 high) across ManageEngine Applications Manager, OpManager, Firewall Analyzer, Network Configuration Manager and related product editions. Apply vendor patches promptly. | |
| rilevata-vulnerabilita-in-watchguard | – | – | High | A high-severity vulnerability affects WatchGuard AuthPoint Authentication Gateway, the on-premise MFA component connecting Active Directory/LDAP and handling RADIUS authentication. Exploitation could let an attacker bypass authentication mechanisms. Apply vendor updates. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.