CVE Digest

CVE Digest — October 7, 2026

  • Security Bulletin
16 CVE Critical
CVEProductCVSSSeveritySummaryReferences
aggiornamenti-di-sicurezza-per-prodotti-cisco––CriticalCisco released security updates fixing 35 vulnerabilities across its products, 15 rated critical and 13 high. Admins should review the advisory and update affected systems promptly.
CVE-2026-107181–8.1HighA public PoC exploits CVE-2026-107181 (CVSS 8.1) in Telegram Desktop; a patch exists. An IPC record-separator injection in Core::Sandbox lets crafted tg:// links inject OPEN: records, exfiltrating tdata session keys and enabling account takeover. Update to 7.2.9+.
rilevate-vulnerabilita-in-craft-cms-3––HighEleven vulnerabilities, four high severity, were found in Craft CMS, a web/e-commerce content management tool. If exploited, an authenticated attacker could make unauthorized changes to application data and execute arbitrary remote code. Apply the updates.
rilevata-vulnerabilita-in-llama.cpp––HighA high-severity vulnerability was found in llama.cpp, the open-source inference engine for running LLMs locally. If exploited, a remote attacker could compromise service availability and potentially execute arbitrary code. Apply the available update.
aggiornamenti-di-sicurezza-per-dispositivi-google-pixel-8––CriticalGoogle published October security updates for Pixel devices fixing 6 vulnerabilities, 3 critical and 3 high. If exploited, an attacker could access sensitive information and escalate privileges. Install the updates.
veeam-risolte-vulnerabilita-in-backup-replication-3––HighVeeam fixed 4 vulnerabilities, 2 high, in Backup & Replication. An authenticated remote attacker with the Backup Viewer role could run arbitrary code on the Backup Server; with valid Cloud Connect tenant credentials, could read arbitrary files on the provider host.
rilevata-vulnerabilita-in-asustor-adm––CriticalA critical vulnerability affects the ADM software on ASUSTOR network storage (NAS) products. If exploited, attackers could read arbitrary files on affected systems. Apply the vendor update.
risolte-vulnerabilita-in-prodotti-sonicwall-2––CriticalSonicWall released updates fixing 4 vulnerabilities, 1 critical and 2 high, in SMA1000 series models 6210, 7210 and 8200v. If exploited, an attacker could bypass security mechanisms and execute arbitrary code. Apply the updates.
risolte-vulnerabilita-in-prodotti-hpe-networking-1––CriticalHPE released updates fixing 37 vulnerabilities, 16 critical and 12 high, affecting HPE Networking AOS-Switch (AOS-S) and ClearPass Policy Manager (CPPM). Admins should apply the updates.
rilevate-nuove-vulnerabilita-in-langflow-1––CriticalTwenty-four new vulnerabilities, 2 critical and 18 high, were found in Langflow, the open-source platform for building, testing and deploying AI applications and agents. Apply the available updates.
aggiornamenti-di-sicurezza-per-gitea––HighSecurity updates fix 9 vulnerabilities, 3 high, in Gitea, the open-source collaborative platform for source code management and software development. Apply the updates.
vulnerabilita-in-prodotti-asus-2––CriticalASUS released updates fixing 4 vulnerabilities, 2 critical and 2 high, affecting several router models. Apply the vendor updates.
risolte-vulnerabilita-in-github-enterprise-server––HighUpdates fix two vulnerabilities, one high, in GitHub Enterprise Server. An authenticated user allowed to push content to a repository could force the system to send crafted requests to attacker-controlled internal hosts, potentially executing arbitrary code.
risolte-vulnerabilita-in-prodotti-elastic-3––HighElastic released security updates fixing multiple vulnerabilities, 3 high, affecting Kibana and Elasticsearch. Apply the updates.
vulnerabilita-in-prodotti-jetbrains-1––HighJetBrains released updates fixing two vulnerabilities, one high, in TeamCity. If exploited, a remote attacker could execute arbitrary code on affected systems. Apply the updates.
risolte-vulnerabilita-in-google-chrome-78––CriticalGoogle released a Chrome update fixing 247 new security vulnerabilities, 12 critical and 42 high. Users should update Chrome to the latest version.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.