CVE Digest — October 5, 2026
7 CVE
Critical
Digest for October 5, 2026: 0 new entries in the CISA KEV catalog and 7 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
- Progress Software: aggiornamenti di sicurezza
- Risolte vulnerabilità nei chipset MediaTek
- Zimbra ZCS: rilevato sfruttamento di vulnerabilità in versioni non aggiornate
- Aggiornamenti di sicurezza per LibreOffice
- Risolte vulnerabilità in Google Chrome
- Risolta vulnerabilità su GitLab AI Gateway
- Rilevate vulnerabilità in cPanel/WHM
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| progress-software-aggiornamenti-di-sicurezza-10 | – | – | Unknown | Progress Software released security updates fixing new vulnerabilities in Sitefinity Next.js Renderer and Telerik Fiddler Classic. If exploited, they could let an attacker elevate privileges or bypass security mechanisms on affected systems. | |
| risolte-vulnerabilita-nei-chipset-mediatek-1 | – | – | Critical | Security updates fix 31 vulnerabilities, 2 rated critical and 9 high, in MediaTek chipsets, hardware components used in many mobile devices and embedded systems. Users should apply the vendor updates promptly. | |
| CVE-2026-73570 | – | 8.9 | High | Italy’s CSIRT reports multiple compromises of internet-exposed Zimbra Collaboration Suite, mainly via CVE-2026-73570 (CVSS 8.9, RCE) and other flaws on outdated instances. Attackers run code as the app user and persist via webshells and scheduled tasks. | |
| aggiornamenti-di-sicurezza-per-libreoffice-3 | – | – | High | LibreOffice security updates fix 6 vulnerabilities, including 1 high-severity issue in LibreOffice Calc, the open-source spreadsheet application. If exploited, it could allow an attacker to execute arbitrary code on affected systems. | |
| risolte-vulnerabilita-in-google-chrome-77 | – | – | Unknown | Google released a Chrome update fixing 11 new security vulnerabilities. If exploited, they could let an attacker bypass security mechanisms, execute arbitrary code and compromise service availability on affected systems. | |
| risolta-vulnerabilita-su-gitlab-ai-gateway-1 | – | – | Critical | Security updates fix a critical vulnerability in GitLab AI Gateway. If exploited, it could allow a malicious authenticated user to execute arbitrary code on affected systems. Apply the GitLab updates. | |
| whm | – | – | Critical | Security updates fix 3 critical vulnerabilities in cPanel/WHM (Web Host Manager). If exploited, they could allow an attacker to execute arbitrary code with administrative privileges on affected systems. Apply the updates. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.