CVE Digest — October 7, 2026
16 CVE
Critical
Digest for October 7, 2026: 0 new entries in the CISA KEV catalog and 16 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
- Aggiornamenti di sicurezza per prodotti Cisco
- Telegram Desktop: PoC pubblica per lo sfruttamento della CVE-2026-107181
- Rilevate vulnerabilità in Craft CMS
- Rilevata vulnerabilità in llama.cpp
- Aggiornamenti di sicurezza per dispositivi Google Pixel
- Veeam: risolte vulnerabilità in Backup & Replication
- Rilevata vulnerabilità in Asustor ADM
- Risolte vulnerabilità in prodotti SonicWall
- Risolte vulnerabilità in prodotti HPE Networking
- Rilevate nuove vulnerabilità in Langflow
- Aggiornamenti di sicurezza per Gitea
- Vulnerabilità in prodotti ASUS
- Risolte vulnerabilità in GitHub Enterprise Server
- Risolte vulnerabilità in prodotti Elastic
- Vulnerabilità in prodotti JetBrains
- Risolte vulnerabilità in Google Chrome
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| aggiornamenti-di-sicurezza-per-prodotti-cisco | – | – | Critical | Cisco released security updates fixing 35 vulnerabilities across its products, 15 rated critical and 13 high. Admins should review the advisory and update affected systems promptly. | |
| CVE-2026-107181 | – | 8.1 | High | A public PoC exploits CVE-2026-107181 (CVSS 8.1) in Telegram Desktop; a patch exists. An IPC record-separator injection in Core::Sandbox lets crafted tg:// links inject OPEN: records, exfiltrating tdata session keys and enabling account takeover. Update to 7.2.9+. | |
| rilevate-vulnerabilita-in-craft-cms-3 | – | – | High | Eleven vulnerabilities, four high severity, were found in Craft CMS, a web/e-commerce content management tool. If exploited, an authenticated attacker could make unauthorized changes to application data and execute arbitrary remote code. Apply the updates. | |
| rilevata-vulnerabilita-in-llama.cpp | – | – | High | A high-severity vulnerability was found in llama.cpp, the open-source inference engine for running LLMs locally. If exploited, a remote attacker could compromise service availability and potentially execute arbitrary code. Apply the available update. | |
| aggiornamenti-di-sicurezza-per-dispositivi-google-pixel-8 | – | – | Critical | Google published October security updates for Pixel devices fixing 6 vulnerabilities, 3 critical and 3 high. If exploited, an attacker could access sensitive information and escalate privileges. Install the updates. | |
| veeam-risolte-vulnerabilita-in-backup-replication-3 | – | – | High | Veeam fixed 4 vulnerabilities, 2 high, in Backup & Replication. An authenticated remote attacker with the Backup Viewer role could run arbitrary code on the Backup Server; with valid Cloud Connect tenant credentials, could read arbitrary files on the provider host. | |
| rilevata-vulnerabilita-in-asustor-adm | – | – | Critical | A critical vulnerability affects the ADM software on ASUSTOR network storage (NAS) products. If exploited, attackers could read arbitrary files on affected systems. Apply the vendor update. | |
| risolte-vulnerabilita-in-prodotti-sonicwall-2 | – | – | Critical | SonicWall released updates fixing 4 vulnerabilities, 1 critical and 2 high, in SMA1000 series models 6210, 7210 and 8200v. If exploited, an attacker could bypass security mechanisms and execute arbitrary code. Apply the updates. | |
| risolte-vulnerabilita-in-prodotti-hpe-networking-1 | – | – | Critical | HPE released updates fixing 37 vulnerabilities, 16 critical and 12 high, affecting HPE Networking AOS-Switch (AOS-S) and ClearPass Policy Manager (CPPM). Admins should apply the updates. | |
| rilevate-nuove-vulnerabilita-in-langflow-1 | – | – | Critical | Twenty-four new vulnerabilities, 2 critical and 18 high, were found in Langflow, the open-source platform for building, testing and deploying AI applications and agents. Apply the available updates. | |
| aggiornamenti-di-sicurezza-per-gitea | – | – | High | Security updates fix 9 vulnerabilities, 3 high, in Gitea, the open-source collaborative platform for source code management and software development. Apply the updates. | |
| vulnerabilita-in-prodotti-asus-2 | – | – | Critical | ASUS released updates fixing 4 vulnerabilities, 2 critical and 2 high, affecting several router models. Apply the vendor updates. | |
| risolte-vulnerabilita-in-github-enterprise-server | – | – | High | Updates fix two vulnerabilities, one high, in GitHub Enterprise Server. An authenticated user allowed to push content to a repository could force the system to send crafted requests to attacker-controlled internal hosts, potentially executing arbitrary code. | |
| risolte-vulnerabilita-in-prodotti-elastic-3 | – | – | High | Elastic released security updates fixing multiple vulnerabilities, 3 high, affecting Kibana and Elasticsearch. Apply the updates. | |
| vulnerabilita-in-prodotti-jetbrains-1 | – | – | High | JetBrains released updates fixing two vulnerabilities, one high, in TeamCity. If exploited, a remote attacker could execute arbitrary code on affected systems. Apply the updates. | |
| risolte-vulnerabilita-in-google-chrome-78 | – | – | Critical | Google released a Chrome update fixing 247 new security vulnerabilities, 12 critical and 42 high. Users should update Chrome to the latest version. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.