CVE Digest

CVE Digest — September 25, 2026

  • Security Bulletin
8 CVE 3 KEV Critical

Digest for September 25, 2026: 3 new entries in the CISA KEV catalog and 5 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

ACN advisories (Italy)

CVEProductCVSSSeveritySummaryReferences
CVE-2026-67279 KEVMikroTik RouterOS6.5MediumUnauthenticated clients can complete an SSH rekey and open a session channel without prior authentication, sending an exec request that creates and overwrites RouterOS files. Chainable with CVE-2026-86060. Fixed in 6.49.21, 7.23.4, 7.24.2.
CWE-841
CVE-2026-65660 KEVMicrosoft SharePoint8.8HighCode injection (CWE-94) in Microsoft Office SharePoint lets an authorized attacker execute code over the network. High severity (CVSS 8.8), added to CISA KEV. Apply vendor updates per BOD 26-04, prioritizing exposed SharePoint servers.
CWE-94
CVE-2026-87902 KEVWordPress Core8.1HighUnauthenticated remote file inclusion in WordPress Core lets page-template resolution include an arbitrary readable local .php file outside the active theme, leading to RCE if pre-conditions are met. High severity (CVSS 8.1), in CISA KEV. Patch immediately.
CWE-98
risolte-vulnerabilita-in-prodotti-elastic-2––HighElastic released fixes for vulnerabilities in its products, including one rated high severity in Kibana that could allow a malicious user to elevate privileges on affected systems. Review the advisory and apply vendor updates.
CVE-2026-71540–7.5HighA public PoC exists for CVE-2026-71540 in Wazuh, an unauthenticated cluster protocol flaw (CWE-770, CVSS 7.5) forcing buffer allocations up to 256 MiB per peer that can exhaust memory and terminate cluster processes. Fixed in 4.14.7; update promptly.
risolte-vulnerabilita-in-prodotti-dell––HighDell updates fix multiple vulnerabilities, including 5 rated high severity in BOSS, Rugged Control Center, Trusted Device Client and ThinOS 10. Exploitation may bypass authentication, escalate privileges and allow unauthorized modification of data or code.
risolte-vulnerabilita-in-servicenow––CriticalServiceNow released security updates fixing 5 vulnerabilities, 2 rated critical and 3 high, in ServiceNow AI Platform. Exploitation could affect confidentiality, integrity or availability. Apply vendor patches and review the advisory.
rilevate-vulnerabilita-in-prodotti-mongodb-6––HighMongoDB fixed 5 high-severity vulnerabilities in PyMongo, C Driver, Compass and Laravel MongoDB. Exploitation could allow arbitrary code execution, access to sensitive information, data alteration and denial of service. Apply vendor updates.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.