CVE Digest

CVE Digest — October 6, 2026

  • Security Bulletin
7 CVE Critical

Digest for October 6, 2026: 0 new entries in the CISA KEV catalog and 7 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

ACN advisories (Italy)

CVEProductCVSSSeveritySummaryReferences
rilevate-vulnerabilita-in-dell-system-update––CriticalDell Technologies released security updates fixing 5 vulnerabilities in Dell System Update, the tool managing driver, BIOS, firmware and application updates: 1 critical and 4 high severity.
risolte-vulnerabilita-in-apache-struts––HighApache Software Foundation released updates fixing several security vulnerabilities, 3 rated high severity, in Apache Struts, the open-source MVC framework for building Java web applications.
rilevate-vulnerabilita-nei-chipset-qualcomm––HighMultiple security vulnerabilities, including 11 rated high severity, were found in Qualcomm chipsets used in mobile devices, embedded systems, network equipment, automotive platforms and other Snapdragon and FastConnect-based systems.
langflow-disponibili-poc-per-lo-sfruttamento-di-4-vulnerabilita––CriticalProof-of-Concept exploits are available for 4 new vulnerabilities in Langflow, a popular open-source platform for building, testing and deploying AI-based applications and agents; 2 are critical and 2 high severity.
risolta-vulnerabilita-in-hpe-integrated-lights-out-ilo-7––CriticalSecurity updates fix a critical vulnerability in HPE Integrated Lights-Out (iLO) 7, the integrated server management platform. If exploited, an attacker could bypass authentication and access the management interface with administrative privileges.
aggiornamenti-di-sicurezza-per-dispositivi-android––CriticalGoogle published the October Android security bulletin, addressing 25 vulnerabilities, including 7 rated critical and 18 high severity.
risolta-vulnerabilita-in-prodotti-atlassian––CriticalSecurity updates fix a critical vulnerability in several Atlassian products. If exploited, an unauthenticated attacker could access specific files in the web application’s root folder, provided they already know the file name and path.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.