CVE Digest — September 25, 2026
8 CVE
3 KEV
Critical
Digest for September 25, 2026: 3 new entries in the CISA KEV catalog and 5 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-67279 KEV | MikroTik RouterOS | 6.5 | Medium | Unauthenticated clients can complete an SSH rekey and open a session channel without prior authentication, sending an exec request that creates and overwrites RouterOS files. Chainable with CVE-2026-86060. Fixed in 6.49.21, 7.23.4, 7.24.2. CWE-841 | |
| CVE-2026-65660 KEV | Microsoft SharePoint | 8.8 | High | Code injection (CWE-94) in Microsoft Office SharePoint lets an authorized attacker execute code over the network. High severity (CVSS 8.8), added to CISA KEV. Apply vendor updates per BOD 26-04, prioritizing exposed SharePoint servers. CWE-94 | |
| CVE-2026-87902 KEV | WordPress Core | 8.1 | High | Unauthenticated remote file inclusion in WordPress Core lets page-template resolution include an arbitrary readable local .php file outside the active theme, leading to RCE if pre-conditions are met. High severity (CVSS 8.1), in CISA KEV. Patch immediately. CWE-98 | |
| risolte-vulnerabilita-in-prodotti-elastic-2 | – | – | High | Elastic released fixes for vulnerabilities in its products, including one rated high severity in Kibana that could allow a malicious user to elevate privileges on affected systems. Review the advisory and apply vendor updates. | |
| CVE-2026-71540 | – | 7.5 | High | A public PoC exists for CVE-2026-71540 in Wazuh, an unauthenticated cluster protocol flaw (CWE-770, CVSS 7.5) forcing buffer allocations up to 256 MiB per peer that can exhaust memory and terminate cluster processes. Fixed in 4.14.7; update promptly. | |
| risolte-vulnerabilita-in-prodotti-dell | – | – | High | Dell updates fix multiple vulnerabilities, including 5 rated high severity in BOSS, Rugged Control Center, Trusted Device Client and ThinOS 10. Exploitation may bypass authentication, escalate privileges and allow unauthorized modification of data or code. | |
| risolte-vulnerabilita-in-servicenow | – | – | Critical | ServiceNow released security updates fixing 5 vulnerabilities, 2 rated critical and 3 high, in ServiceNow AI Platform. Exploitation could affect confidentiality, integrity or availability. Apply vendor patches and review the advisory. | |
| rilevate-vulnerabilita-in-prodotti-mongodb-6 | – | – | High | MongoDB fixed 5 high-severity vulnerabilities in PyMongo, C Driver, Compass and Laravel MongoDB. Exploitation could allow arbitrary code execution, access to sensitive information, data alteration and denial of service. Apply vendor updates. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.