CVE Digest

CVE Digest — September 28, 2026

  • Security Bulletin
5 CVE Critical

Digest for September 28, 2026: 0 new entries in the CISA KEV catalog and 5 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

ACN advisories (Italy)

CVEProductCVSSSeveritySummaryReferences
operational-summary-agosto-2026––UnknownCSIRT Italia published its monthly operational summary for August 2026, covering analysis and trends of the cyber threat and listing the most severe vulnerabilities identified during the period.
CVE-2026-85542–8.8HighActive exploitation reported for CVE-2026-85542, a command injection (CWE-78, CVSS 8.8) in IBM Guardium Data Protection 12.2. An authenticated attacker can supply a crafted GIM bundle to execute arbitrary commands with elevated privileges on the Central Manager. Vendor patch ava…
flowiseai-poc-pubbliche-per-lo-sfruttamento-di-6-vulnerabilita––CriticalPublic proof-of-concept exploits are available for 6 new vulnerabilities in Flowise, an AI application and workflow platform: 2 rated critical and 4 rated high severity. Update to the patched version promptly to mitigate exposure.
risolte-vulnerabilita-in-zammad-1––CriticalSecurity updates released for Zammad, an open-source help desk and customer support platform, fixing 30 vulnerabilities: 1 critical and 10 high severity. Upgrade to the latest version to prevent exploitation.
risolte-vulnerabilita-in-zimbra-collaboration-suite––CriticalSecurity updates released for Zimbra Collaboration Suite (ZCS), Synacor’s email collaboration platform, fixing multiple vulnerabilities including 4 rated critical. Apply the patches immediately to protect affected deployments.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.