CVE Digest — September 29, 2026
9 CVE
1 KEV
Critical
Digest for September 29, 2026: 1 new entry in the CISA KEV catalog and 8 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
- Risolte vulnerabilità in prodotti Mozilla
- Disponibili PoC per lo sfruttamento di 7 vulnerabilità in prodotti axios
- Risolte vulnerabilità in prodotti HPE
- JFrog: rilevato sfruttamento in rete della CVE-2026-82329 relativa ad Artifactory
- Rilevate vulnerabilità in FreePBX
- Progress Software: sanate vulnerabilità in Progress Telerik Fiddler Everywhere
- Aggiornamenti disponibili per WatchGuard AP
- Apple: rilevato sfruttamento in rete della CVE-2026-86950
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-86950 KEV | Apple Multiple Products | 8.8 | High | Apple iOS, iPadOS and macOS contain an out-of-bounds write (CWE-787) in CoreGraphics. Processing a maliciously crafted file may allow arbitrary code execution. Fixed in iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Exploited in an extremely sophisticated targeted … CWE-787 | |
| risolte-vulnerabilita-in-prodotti-mozilla-11 | – | – | Critical | ACN reports security updates addressing multiple vulnerabilities, one rated critical and 39 rated high, in Mozilla Firefox and Firefox ESR. Apply the latest updates promptly to mitigate potential exploitation. | |
| disponibili-poc-per-lo-sfruttamento-di-7-vulnerabilita-in-prodotti-axios | – | – | High | Proofs of concept (PoC) are publicly available for the exploitation of 7 high-severity vulnerabilities in the axios product. Review exposure and update axios to patched versions as soon as possible. | |
| risolte-vulnerabilita-in-prodotti-hpe | – | – | High | ACN reports security updates resolving 3 vulnerabilities, including 2 rated high, in HPE OneView and HPE Synergy Composer. Upgrade affected products to the fixed releases. | |
| CVE-2026-82329 | – | 9.8 | Critical | Active exploitation of CVE-2026-82329 in JFrog Artifactory (critical, CVSS 9.8, CWE-287). An unauthenticated remote attacker may bypass access controls and gain administrative privileges under default configuration. Apply vendor fixes immediately. | |
| rilevate-vulnerabilita-in-freepbx-1 | – | – | High | ACN reports 6 high-severity vulnerabilities in multiple FreePBX modules. FreePBX is an open-source platform for graphically configuring and managing Asterisk-based phone systems. Apply available updates to affected modules. | |
| progress-software-sanate-vulnerabilita-in-progress-telerik-fiddler-everywhere | – | – | High | ACN reports security updates fixing 2 vulnerabilities, one rated high, in Progress Telerik Fiddler Everywhere. Update to the latest version to address the issues. | |
| aggiornamenti-disponibili-per-watchguard-ap | – | – | Critical | WatchGuard security updates fix 3 vulnerabilities, 2 critical and 1 high, in WatchGuard AP wireless access points. Exploitation could let an attacker bypass authentication and execute arbitrary code. Apply updates promptly. | |
| CVE-2026-86950 | – | 8.8 | High | Active exploitation detected for CVE-2026-86950 (already patched by Apple) affecting iOS, iPadOS, macOS Tahoe and macOS Sequoia. Exploitation may allow arbitrary code execution. Apply vendor updates if not already deployed. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.