CVE Digest

CVE Digest — September 30, 2026

  • Security Bulletin
11 CVE 1 KEV Critical
CVEProductCVSSSeveritySummaryReferences
CVE-2026-76504 KEVCisco Catalyst SD-WAN Manager9.8CriticalCritical actively exploited flaw in Cisco Catalyst SD-WAN Manager: improper URI encoding handling lets an unauthenticated remote attacker bypass API authentication and gain admin privileges (CVSS 9.8). Apply vendor mitigations per CISA BOD 26-04 and triage requirements.
CWE-177
CVE-2026-76504–9.8CriticalACN advisory: Cisco reports active exploitation of critical CVE-2026-76504 in Catalyst SD-WAN Manager, an SD-WAN management solution. Improper URI encoding handling lets unauthenticated remote attackers gain admin privileges. Patch affected systems immediately.
risolta-vulnerabilita-in-ghostscript––HighACN advisory: Artifex Software released updates fixing a high-severity vulnerability in Ghostscript (PostScript and PDF processing) for Windows. Exploitation could allow an attacker to elevate privileges on affected systems. Update to the patched version.
CVE-2026-94545–5.3MediumACN advisory: A public PoC is available for CVE-2026-94545 in Next.js next/og ImageResponse (already patched by vendor). Improper escaping in the Satori library may allow remote arbitrary code execution in certain conditions. Upgrade to fixed versions.
risolte-vulnerabilita-in-openssl-3––HighACN advisory: Security updates fix 14 vulnerabilities in OpenSSL, an open-source cryptographic communications library, 4 rated high severity. Exploitation could compromise service availability or expose sensitive information. Update OpenSSL to patched releases.
vulnerabilita-in-prodotti-teamviewer––HighACN advisory: TeamViewer released updates for Full Client and Host remote access products fixing 5 high-severity vulnerabilities. Exploitation could allow remote code execution, arbitrary file writes, and privilege escalation. Update affected products.
risolte-vulnerabilita-in-google-chrome-76––CriticalACN advisory: Google released a Chrome browser update fixing 32 security vulnerabilities, including 6 critical and 11 high severity. Update Chrome to the latest version to mitigate exposure to these issues.
risolte-vulnerabilita-in-prodotti-watchguard-2––CriticalACN advisory: WatchGuard released updates fixing multiple vulnerabilities in Fireware OS, the operating system for perimeter network security devices, including 1 critical and 13 high severity. Apply updates to protect networks.
sanata-vulnerabilita-in-ibm-i––HighACN advisory: IBM security updates fix a high-severity vulnerability in IBM i, the enterprise operating system for IBM Power Systems. A locally authenticated attacker could perform unauthorized modification of arbitrary files. Apply IBM updates.
risolte-vulnerabilita-in-joomla-––HighACN advisory: Security updates fix multiple vulnerabilities in the Joomla! content management system, including 7 rated high severity. Update Joomla! installations to the latest patched version to mitigate risk.
CVE-2026-89013–7.5HighACN advisory: Active exploitation detected for CVE-2026-89013 in Dolibarr (already patched by vendor). Unauthenticated attackers can read arbitrary files by supplying a crafted hashp parameter that bypasses authorization checks. Apply the vendor patch immediately.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.