{"success":true,"data":{"threats":[{"id":"3a3a4010-9e07-4645-abba-e86a8d95f10f","slug":"cve-2026-9209","externalId":"CVE-2026-9209","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-9209 — mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQuery…","description":"mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request.","cveId":"CVE-2026-9209","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250","CWE-306"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://mjobtime.com/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.sprocketsecurity.com/blog/cve-2026-9209-pre-authentication-sql-injection-to-remote-code-execution-in-mjobtime","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/mjobtime-unauthenticated-sql-execution-rce-via-login-aspx","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:57.677Z","addedAt":"2026-10-08T16:39:35.993Z","updatedAt":"2026-10-08T23:06:38.355Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9209","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-9209","note":"authoritative record"}]},{"id":"3f824e0f-add5-4487-9ac6-ecb7711f151b","slug":"cve-2026-107176","externalId":"CVE-2026-107176","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107176 — A flaw was found in the cluster-samples-operator.","description":"A flaw was found in the cluster-samples-operator. The RBAC Role coreos-pull-secret-reader in namespace openshift-config grants get, list, and watch permissions on all Secret resources without resourceNames scoping. The operator only requires access to the pull-secret Secret. If the samples-operator pod or its service account token is compromised through a separate vulnerability, an attacker could read all secrets in openshift-config, potentially including OAuth identity provider credentials, cloud provider credentials, and other sensitive cluster configuration.","cveId":"CVE-2026-107176","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107176","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2523035","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00164,"epssPercentile":0.05131,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T20:17:11.153Z","addedAt":"2026-10-07T20:39:40.469Z","updatedAt":"2026-10-08T21:05:43.898Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107176","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107176","note":"authoritative record"}]},{"id":"d6551d67-b2a6-4114-aaee-4b64cd719972","slug":"cve-2026-106378","externalId":"CVE-2026-106378","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106378 — Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process…","description":"Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106378","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-250"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/507596239","type":"advisory","title":"Permissions Required"}],"epssScore":0.00323,"epssPercentile":0.23316,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:06.960Z","addedAt":"2026-10-06T20:39:32.036Z","updatedAt":"2026-10-07T14:39:33.422Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106378","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106378","note":"authoritative record"}]},{"id":"0f685d8e-8c00-4e90-83a3-a9868e34c251","slug":"cve-2026-66246","externalId":"CVE-2026-66246","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-66246 — iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure d…","description":"iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.","cveId":"CVE-2026-66246","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133940","type":"advisory","title":"psirt@hcl.com"}],"epssScore":0.00304,"epssPercentile":0.21236,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T14:17:29.770Z","addedAt":"2026-10-01T15:50:41.745Z","updatedAt":"2026-10-01T15:50:41.745Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66246","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-66246","note":"authoritative record"}]},{"id":"59efed6c-bae8-429d-8313-1f00a2d1b88e","slug":"cve-2026-102118","externalId":"CVE-2026-102118","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102118 — A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service accoun…","description":"A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.","cveId":"CVE-2026-102118","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"accellion","product":"kiteworks","affectedVersions":["< 9.5.0"],"cwes":["CWE-59","CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-8pmh-222g-6j48","type":"vendor","title":"Vendor Advisory"},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","type":"advisory","title":"Broken Link"}],"epssScore":0.00397,"epssPercentile":0.31771,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T21:16:59.707Z","addedAt":"2026-09-30T21:50:45.143Z","updatedAt":"2026-10-07T14:39:32.377Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102118","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102118","note":"authoritative record"}]},{"id":"61b8f01e-008a-4c3b-b22e-d9978b7263b0","slug":"cve-2026-55094","externalId":"CVE-2026-55094","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55094 — Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes.","description":"Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.","cveId":"CVE-2026-55094","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-20","CWE-94","CWE-95","CWE-250","CWE-306"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2045091","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/commit/a1b0154b8235937657c2ded127f193b564e2334b","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/issues/8716","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/pull/8718","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/releases/tag/v100.3.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/taskcluster/taskcluster/security/advisories/GHSA-ccv5-c45x-2q38","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00423,"epssPercentile":0.34605,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T18:18:37.387Z","addedAt":"2026-09-30T19:50:43.929Z","updatedAt":"2026-09-30T21:50:44.639Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55094","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55094","note":"authoritative record"}]},{"id":"2ad31c37-e52c-44d5-8fa3-83c294e6f983","slug":"cve-2026-53605","externalId":"CVE-2026-53605","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-53605 — Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen.","description":"Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.","cveId":"CVE-2026-53605","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250","CWE-269"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pollen-robotics/reachy-mini-os/commit/cee4076f36bd95a2a6b894a56a48c7e971e75445","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pollen-robotics/reachy-mini-os/releases/tag/v0.2.4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pollen-robotics/reachy-mini-os/security/advisories/GHSA-7rhg-9v48-x3h2","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00126,"epssPercentile":0.01981,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T18:18:37.213Z","addedAt":"2026-09-30T19:50:43.923Z","updatedAt":"2026-10-02T17:50:40.061Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53605","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-53605","note":"authoritative record"}]},{"id":"1f7f73f6-6de8-4e5d-8cb7-5c5903fa7e17","slug":"cve-2026-102247","externalId":"CVE-2026-102247","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102247 — A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602.","description":"A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may be used.","cveId":"CVE-2026-102247","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/baguette168/CVE/issues/2","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-102247","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/933377","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/411145","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/411145/cti","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00393,"epssPercentile":0.31339,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T04:17:54.110Z","addedAt":"2026-09-29T05:50:38.648Z","updatedAt":"2026-09-29T19:50:41.118Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102247","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102247","note":"authoritative record"}]},{"id":"476bf4c0-7dac-4628-aeb3-bd50e0a44bb0","slug":"cve-2026-88808","externalId":"CVE-2026-88808","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88808 — A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin…","description":"A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files.\n\nThis issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.","cveId":"CVE-2026-88808","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"suse","product":"rancher fleet","affectedVersions":[">= 0.14.0, < 0.14.11",">= 0.15.0, < 0.15.7",">= 0.16.0, < 0.16.2"],"cwes":["CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rancher/fleet/security/advisories/GHSA-q9v4-358v-r8q5","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00278,"epssPercentile":0.1857,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T16:17:16.150Z","addedAt":"2026-09-28T17:50:41.345Z","updatedAt":"2026-10-07T18:39:30.243Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88808","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88808","note":"authoritative record"}]},{"id":"dc309800-706b-450f-bc26-b9b70cfda798","slug":"cve-2026-87899","externalId":"CVE-2026-87899","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87899 — Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.","description":"Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.","cveId":"CVE-2026-87899","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.cpanel.net/hc/en-us/articles/43591715125271","type":"advisory","title":"support@hackerone.com"}],"epssScore":0.00576,"epssPercentile":0.45737,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T20:17:20.480Z","addedAt":"2026-09-23T21:50:38.721Z","updatedAt":"2026-09-24T21:50:44.029Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87899","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87899","note":"authoritative record"}]},{"id":"91cf6053-c132-41c1-aa03-e9ea6a363ae6","slug":"cve-2026-19087","externalId":"CVE-2026-19087","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19087 — IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due …","description":"IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.","cveId":"CVE-2026-19087","cvssScore":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":"ibm","product":"financial transaction manager","affectedVersions":[">= 4.0.7.0, < 4.0.11.0","4.0.6.0"],"cwes":["CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288641","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00093,"epssPercentile":0.00508,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T16:16:41.980Z","addedAt":"2026-09-23T17:50:39.819Z","updatedAt":"2026-10-07T14:39:32.163Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19087","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19087","note":"authoritative record"}]},{"id":"6ebd8a55-6fce-4951-a012-27e352129de9","slug":"cve-2026-84787","externalId":"CVE-2026-84787","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84787 — ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allo…","description":"ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.","cveId":"CVE-2026-84787","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.manageengine.com/itom/advisory/cve-2026-84787.html","type":"advisory","title":"0fc0942c-577d-436f-ae8e-945763c79b02"}],"epssScore":0.00846,"epssPercentile":0.56756,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T12:17:07.857Z","addedAt":"2026-09-23T13:50:38.721Z","updatedAt":"2026-09-24T05:50:38.875Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84787","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84787","note":"authoritative record"}]},{"id":"cae8d05f-e62d-4a84-8906-1e8f2bc9fe5f","slug":"cve-2026-77521","externalId":"CVE-2026-77521","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-77521 — MaxKB is an open-source AI assistant for enterprise.","description":"MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_SANDBOX disabled run commands directly as the application user, while the official root container's string-based gosu wrapper allowed shell metacharacters to execute outside the intended sandbox. This issue is fixed in version 2.10.5-lts.","cveId":"CVE-2026-77521","cvssScore":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78","CWE-250","CWE-749"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/1Panel-dev/MaxKB/commit/594f50f2ea80a502d1c955371ba0438b277c30ea","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.5-lts","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.01049,"epssPercentile":0.63196,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T21:17:10.943Z","addedAt":"2026-09-21T21:50:38.426Z","updatedAt":"2026-09-22T15:50:37.988Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77521","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-77521","note":"authoritative record"}]},{"id":"5024012e-e524-45f4-b0dc-4afbc57c1bf7","slug":"cve-2026-92574","externalId":"CVE-2026-92574","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92574 — A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Ku…","description":"A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary.\nAffected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released.\nExploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.","cveId":"CVE-2026-92574","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-92574","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2535436","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00654,"epssPercentile":0.49766,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T10:17:17.360Z","addedAt":"2026-09-21T11:50:37.883Z","updatedAt":"2026-10-01T13:50:40.515Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92574","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92574","note":"authoritative record"}]},{"id":"caa910b3-df0b-4cdc-8a33-064a9cf8a199","slug":"cve-2026-54501","externalId":"CVE-2026-54501","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-54501 — Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted insta…","description":"Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. A user with crawler or administrator permission on the specific instance can supply a crafted Git URL that executes arbitrary operating-system commands in the backend pod. Open registration or hosted free-trial access can make the required role broadly obtainable. Successful exploitation can expose, modify, or delete application database records, archived items, browser profiles, storage data, proxy credentials, and other configured service data. This issue is fixed in version 1.22.8.","cveId":"CVE-2026-54501","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-20","CWE-77","CWE-78","CWE-88","CWE-250"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/webrecorder/browsertrix/commit/a306afc3893a74ed0ec2407bdf0515ed52da8e46","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/webrecorder/browsertrix/releases/tag/v1.22.8","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/webrecorder/browsertrix/security/advisories/GHSA-47vv-v544-r985","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.01217,"epssPercentile":0.67701,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T21:17:15.707Z","addedAt":"2026-09-17T21:50:37.953Z","updatedAt":"2026-09-24T21:50:42.649Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54501","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-54501","note":"authoritative record"}]},{"id":"f8f1cc08-ef45-4d5d-818e-73c56a2c29f5","slug":"cve-2026-55225","externalId":"CVE-2026-55225","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55225 — Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations.","description":"Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role with full Secret CRUD permissions there and bind it to the Entity Operator ServiceAccount in the attacker's namespace. The attacker can mint a token for that ServiceAccount and read or write Secrets in any target namespace where the Cluster Operator has been granted permissions, regardless of STRIMZI_NAMESPACE. This issue is fixed in versions 1.0.1 and 1.1.0.","cveId":"CVE-2026-55225","cvssScore":8,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269","CWE-441","CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/strimzi/strimzi-kafka-operator/commit/b3bfeffcc30754c3e62e6f4afd8a76942cac440d","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/commit/f6c5207ba7ec89b46ce6720b8638d647e556a261","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/pull/12844","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/releases/tag/1.0.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/releases/tag/1.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/security/advisories/GHSA-mw9r-p8xp-wx96","type":"advisory","title":"security-advisories@github.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:54435","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-55225","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490275","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55225.json","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epssScore":0.00295,"epssPercentile":0.20283,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T18:17:23.667Z","addedAt":"2026-09-15T19:50:36.983Z","updatedAt":"2026-09-30T17:50:44.381Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55225","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55225","note":"authoritative record"}]},{"id":"770feade-3100-4f59-892b-708592a1bd00","slug":"cve-2026-75092","externalId":"CVE-2026-75092","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-75092 — A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository).","description":"A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs:\nmysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql.\n\nA process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQL’s runtime-user check and before plugin-symbol validation.\n\nWhen an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint — OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp.","cveId":"CVE-2026-75092","cvssScore":7.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-75092","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517499","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/oamg/leapp-repository","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/oamg/leapp-repository/commit/3e4cafffc8de1600a66519b326a407f37b665356","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/oamg/leapp-repository/pull/1343","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:67608","type":"advisory","title":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:67609","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00129,"epssPercentile":0.02156,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T09:16:43.727Z","addedAt":"2026-09-15T09:50:35.042Z","updatedAt":"2026-09-16T19:50:39.669Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75092","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-75092","note":"authoritative record"}]},{"id":"76f79104-ab92-4eec-bb94-23f302f413a2","slug":"cve-2026-89259","externalId":"CVE-2026-89259","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-89259 — Hugo is a static site generator.","description":"Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked during a build to read and write files outside the project's working directory. Affected versions are those after v0.43; the issue was fixed in v0.165.0 by removing tailwindcss from the default security.exec.allow list. Users who do not use TailwindCSS, or who only build trusted sites, are not affected. As a workaround, users can define a restrictive security.exec.allow list in hugo.toml.","cveId":"CVE-2026-89259","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-250"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-vrm6-x8vp-mv2r","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hugo-before-0.165.0-insufficient-permission-restriction-via-tailwindcss","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00587,"epssPercentile":0.46395,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-11T12:16:56.480Z","addedAt":"2026-09-11T13:50:40.164Z","updatedAt":"2026-09-24T21:50:41.709Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89259","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-89259","note":"authoritative record"}]},{"id":"71ac85ad-c23f-474c-889a-eb958dbbe489","slug":"cve-2026-79942","externalId":"CVE-2026-79942","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79942 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessa…","description":"Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.","cveId":"CVE-2026-79942","cvssScore":3.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","severity":"low","vendor":"dell","product":"secure connect gateway","affectedVersions":["< 5.36.00.00","< 5.36.00.16"],"cwes":["CWE-250"],"tags":["nvd","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00154,"epssPercentile":0.03956,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T16:17:08.270Z","addedAt":"2026-09-09T17:50:39.343Z","updatedAt":"2026-09-09T21:50:42.800Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79942","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79942","note":"authoritative record"}]},{"id":"18ad3136-172d-4b86-b31e-63af3249f6b0","slug":"cve-2026-87506","externalId":"CVE-2026-87506","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87506 — Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentia…","description":"Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-87506","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 153.0.8010.36"],"cwes":["CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","msrc","vendor-advisory","microsoft","cve"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87506"],"references":[{"url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/497551905","type":"advisory","title":"Permissions Required"},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87506","type":"vendor","title":"Microsoft MSRC: Chromium CVE-2026-87506: Privilege elevation in WebUI"}],"epssScore":0.00404,"epssPercentile":0.32586,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T01:17:07.593Z","addedAt":"2026-09-09T01:50:33.972Z","updatedAt":"2026-09-15T01:52:56.365Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87506","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87506","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":84,"totalPages":5,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:44:34.963Z","durationMs":42,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-250"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}