{"success":true,"data":{"threats":[{"id":"bda6fed7-ff4f-4fb9-a3bf-2de0773fd0e8","slug":"cve-2026-84057","externalId":"CVE-2026-84057","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84057 — IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special…","description":"IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.","cveId":"CVE-2026-84057","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288832","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:33.170Z","addedAt":"2026-10-08T23:06:40.540Z","updatedAt":"2026-10-08T23:06:40.540Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84057","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84057","note":"authoritative record"}]},{"id":"b71befbb-3f88-438d-96b9-bf0a4915fbac","slug":"cve-2026-107780","externalId":"CVE-2026-107780","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107780 — Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/…","description":"Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows.","cveId":"CVE-2026-107780","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/dromara/skyeye","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/blob/003549ae5615bd114ba5bb8ddf6a8e8ead97c321/skyeye-promote/skyeye-common/src/main/java/com/skyeye/common/service/impl/TtsServiceImpl.java#L105-L166","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/dromara/skyeye/issues/29","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dromara-skyeye-unauthenticated-os-command-injection-via-texttospeech-format-parameter","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:52.940Z","addedAt":"2026-10-08T23:06:39.499Z","updatedAt":"2026-10-08T23:06:39.499Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107780","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107780","note":"authoritative record"}]},{"id":"612da4f1-0ec2-4ee5-b032-22c565877dfe","slug":"cve-2026-106126","externalId":"CVE-2026-106126","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106126 — A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileg…","description":"A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.","cveId":"CVE-2026-106126","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.tenable.com/security/tns-2026-27","type":"advisory","title":"vulnreport@tenable.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:29.950Z","addedAt":"2026-10-08T21:05:52.804Z","updatedAt":"2026-10-08T23:06:39.279Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106126","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106126","note":"authoritative record"}]},{"id":"0f695391-3ea6-4c0d-94bc-5eb3eec4d372","slug":"cve-2026-84278","externalId":"CVE-2026-84278","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84278 — IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component.","description":"IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, resulting in command execution with root privileges.","cveId":"CVE-2026-84278","cvssScore":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:20:51.387Z","addedAt":"2026-10-08T19:33:17.132Z","updatedAt":"2026-10-08T21:05:52.665Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84278","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84278","note":"authoritative record"}]},{"id":"82e9e161-4c68-4f6d-bbc6-f79001f5c478","slug":"cve-2026-107704","externalId":"CVE-2026-107704","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107704 — The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attac…","description":"The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby process privileges.","cveId":"CVE-2026-107704","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gist.github.com/R3tro16/a99a058d24a06692721a6a3fade9649d","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/jtescher/image_optimizer","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/jtescher/image_optimizer/blob/v1.9.0/lib/image_optimizer.rb#L37-L47","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/jtescher/image_optimizer/blob/v1.9.0/lib/image_optimizer/shell.rb#L30-L32","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/image-optimizer-1.3.0-through-1.9.0-os-command-injection-via-identify-format","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:02.897Z","addedAt":"2026-10-08T19:33:17.072Z","updatedAt":"2026-10-08T23:06:39.172Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107704","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107704","note":"authoritative record"}]},{"id":"0f16d9c5-ceb1-47e2-b229-a8671f0bdcec","slug":"cve-2026-107703","externalId":"CVE-2026-107703","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107703 — @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via…","description":"@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.","cveId":"CVE-2026-107703","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gist.github.com/R3tro16/5a508fcfddfb0dfe66a0a53437ede74c","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/enmaso/node-convert","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/enmaso/node-convert/blob/143e4d76244e2daac57eef59d8ed5983e33ee4fb/convert.js#L4-L15","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/enmaso-node-convert-through-1.0.0-os-command-injection-via-filepath-and-convertto","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:02.720Z","addedAt":"2026-10-08T19:33:17.055Z","updatedAt":"2026-10-08T23:06:39.154Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107703","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107703","note":"authoritative record"}]},{"id":"f03d8af7-122e-4f15-8fb9-3a4f8944ba21","slug":"cve-2026-107699","externalId":"CVE-2026-107699","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107699 — ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsani…","description":"ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.","cveId":"CVE-2026-107699","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gist.github.com/R3tro16/2daadc08b282c48d41203d1125d7632a","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/tzwm/ppt2png","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/tzwm/ppt2png/blob/8c68eba7af943de27422b12c6e224d28587af7ae/ppt2png.js#L5-L35","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ppt2png-through-0.0.6-os-command-injection-via-input-and-output-paths","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:01.853Z","addedAt":"2026-10-08T19:33:17.018Z","updatedAt":"2026-10-08T23:06:39.110Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107699","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107699","note":"authoritative record"}]},{"id":"e8697993-144d-4eee-9fd0-687db190736d","slug":"cve-2026-93858","externalId":"CVE-2026-93858","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93858 — In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() be…","description":"In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted. An authenticated project member can use the standard action-execution API to submit an arbitrary local command as proxy_command; paramiko starts that command as a subprocess on the executor host under the executor's own service account, independent of whether the SSH connection itself ever succeeds. Only Mistral deployments that permit the std.ssh_proxied action, the default configuration, are affected.","cveId":"CVE-2026-93858","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://launchpad.net/bugs/2162100","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.openstack.org/ossa/OSSA-2026-044.html","type":"advisory","title":"cve@mitre.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:18:30.817Z","addedAt":"2026-10-08T18:39:31.961Z","updatedAt":"2026-10-08T23:06:38.987Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93858","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93858","note":"authoritative record"}]},{"id":"597b769d-68bb-4237-98b3-3d7eae7cb5f0","slug":"cve-2026-61443","externalId":"GHSA-c44f-37qr-gw3f","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: SkillTools Executes Scripts Without Path Containment Validation","description":"### Summary\n`SkillTools.run_skill_script()` accepts a `script_path` parameter and executes it via `subprocess.run()` without any path containment validation. While `FileTools` has `_validate_path()` with traversal detection, `SkillTools` performs none. An LLM-directed call can execute arbitrary scripts from any filesystem location. The `@require_approval` decorator can be bypassed via YAML `approve:` for high-risk tools.\n\n### Details\n`src/praisonai-agents/praisonaiagents/tools/skill_tools.py` (lines 69-119):\n\n```python\ndef run_skill_script(self, script_path: str, ...):\n    script_path = os.path.expanduser(script_path)\n    if not os.path.isabs(script_path):\n        script_path = os.path.join(self._working_directory, script_path)\n    script_path = os.path.abspath(script_path)\n\n    if not os.path.exists(script_path):\n        return f\"Error: Script not found at {script_path}\"\n\n    # No path traversal check, no containment validation\n    # Directly executes whatever is at that path:\n    result = subprocess.run(cmd, ...)\n```\n\nBy contrast, `FileTools._validate_path()` (`src/praisonai-agents/praisonaiagents/tools/file_tools.py`, lines 42-78) properly validates that the resolved path stays within the working directory:\n\n```python\ndef _validate_path(self, filepath: str) -> str:\n    # ...\n    cwd = os.path.abspath(os.getcwd())\n    if os.path.commonpath([absolute, cwd]) != cwd:\n        raise ValueError(f\"Path traversal detected: {filepath} escapes workspace {cwd}\")\n```\n\n`SkillTools` has no equivalent check.\n\n### PoC\n\n```python\nimport os, tempfile\nfrom praisonaiagents.tools.skill_tools import SkillTools\n\n# Create a \"safe\" working directory (the jail)\njail = tempfile.mkdtemp(prefix=\"skill_jail_\")\n\n# Create a malicious script OUTSIDE the jail\nattack_script = os.path.join(tempfile.gettempdir(), \"malicious_skill.sh\")\nwith open(attack_script, 'w') as f:\n    f.write(\"#!/bin/bash\\n\")\n    f.write(\"echo \\\"PROOF_OF_EXPLOIT: Script executed outside jail\\\"\\n\")\n    f.write(\"echo \\\"USER: $(whoami)\\\"\\n\")\n    f.write(\"echo \\\"HOSTNAME: $(hostname)\\\"\\n\")\nos.chmod(attack_script, 0o755)\n\n# Bypass approval (simulates Docker env or YAML approve:)\nos.environ[\"PRAISONAI_AUTO_APPROVE\"] = \"true\"\n\nst = SkillTools()\nst._working_directory = jail  # Pretend we're confined\n\n# Run script from OUTSIDE the jail — no path validation!\nresult = st.run_skill_script(attack_script)\nprint(result)\n# Output:\n#   PROOF_OF_EXPLOIT: Script executed outside jail\n#   USER: anushkavirgaonkar\n#   HOSTNAME: Anushkas-MacBook-Pro-2.local\n\n# Cleanup\ndel os.environ[\"PRAISONAI_AUTO_APPROVE\"]\nos.unlink(attack_script)\nos.rmdir(jail)\n```\n\n**Tested result:** The script at `/tmp/malicious_skill.sh` executed successfully despite the working directory being set to a jail directory. The output confirms arbitrary script execution including `whoami` and `hostname`. No path containment check exists — the absolute path is accepted and executed directly.\n\n\n### Impact\n- **Arbitrary script execution**: Run any script on the filesystem from any location\n- **Chaining with file write**: Write a malicious script via `write_file` (YAML-approvable as a high-risk tool), then execute it via `run_skill_script`\n- **Root-level impact in Docker**: All PraisonAI Docker containers run as root (no `USER` directive), so an escaped script runs with full root privileges","cveId":"CVE-2026-61443","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-22","CWE-78"],"tags":["osv","osv:ghsa-c44f-37qr-gw3f","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-c44f-37qr-gw3f","type":"advisory","title":"OSV GHSA-c44f-37qr-gw3f"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-c44f-37qr-gw3f","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61443","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62168","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-skilltools","type":"other","title":"OSV web"}],"epssScore":0.00769,"epssPercentile":0.54219,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:49:23.000Z","addedAt":"2026-10-08T18:42:42.638Z","updatedAt":"2026-10-08T18:42:42.638Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61443","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61443","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-c44f-37qr-gw3f"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-c44f-37qr-gw3f"}]},{"id":"3c3be331-d48d-4c0f-af40-00dd726c1b63","slug":"cve-2026-105110","externalId":"CVE-2026-105110","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105110 — OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitra…","description":"OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.","cveId":"CVE-2026-105110","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78","CWE-306"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/BlackHatExploitation/innbox_root","type":"advisory","title":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epssScore":0.02788,"epssPercentile":0.85991,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T09:16:40.930Z","addedAt":"2026-10-08T10:39:34.906Z","updatedAt":"2026-10-08T23:06:37.240Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105110","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105110","note":"authoritative record"}]},{"id":"672a4036-c6ec-4532-9946-1dd0135b06c5","slug":"cve-2026-107459","externalId":"CVE-2026-107459","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107459 — The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability.","description":"The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.","cveId":"CVE-2026-107459","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.twcert.org.tw/en/cp-139-11255-bce41-2.html","type":"advisory","title":"twcert@cert.org.tw"},{"url":"https://www.twcert.org.tw/tw/cp-132-11254-9c206-1.html","type":"advisory","title":"twcert@cert.org.tw"}],"epssScore":0.01467,"epssPercentile":0.72914,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T06:16:42.000Z","addedAt":"2026-10-08T06:39:29.687Z","updatedAt":"2026-10-08T23:06:37.191Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107459","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107459","note":"authoritative record"}]},{"id":"c6958c66-0a6d-47a3-b879-832e22ce4199","slug":"cve-2026-94586","externalId":"CVE-2026-94586","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94586 — A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Br…","description":"A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can supply malicious parameter strings to execute arbitrary shell commands on the switch with root privileges","cveId":"CVE-2026-94586","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39135","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.01248,"epssPercentile":0.68425,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:06.660Z","addedAt":"2026-10-08T06:39:29.583Z","updatedAt":"2026-10-08T21:05:46.628Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94586","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94586","note":"authoritative record"}]},{"id":"cefcb6c9-8ec0-41e5-99be-ca8a6b8006b7","slug":"cve-2026-94581","externalId":"CVE-2026-94581","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94581 — An OS command injection vulnerability exists in the REST API management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10…","description":"An OS command injection vulnerability exists in the REST API management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 allows an authenticated, high-privileged remote attacker to execute arbitrary system commands with root permissions. An attacker with administrative privileges to configure SSH known host settings can supply specially crafted parameter values containing shell metacharacters to trigger command execution on the host system.","cveId":"CVE-2026-94581","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39137","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.01297,"epssPercentile":0.69518,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:06.393Z","addedAt":"2026-10-08T06:39:29.568Z","updatedAt":"2026-10-08T21:05:46.547Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94581","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94581","note":"authoritative record"}]},{"id":"50747662-3693-4ff2-a0d0-f868e96acaa9","slug":"cve-2026-94579","externalId":"CVE-2026-94579","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94579 — An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination o…","description":"An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user authenticating via an external directory or AAA service whose username or profile identifier contains shell metacharacters can trigger arbitrary command execution with root privileges when their remote SSH session closes.","cveId":"CVE-2026-94579","cvssScore":5.4,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39147","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.0265,"epssPercentile":0.85186,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:06.247Z","addedAt":"2026-10-08T06:39:29.559Z","updatedAt":"2026-10-08T21:05:46.518Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94579","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94579","note":"authoritative record"}]},{"id":"bf0fc5ea-f476-4bd8-8172-fc2792ec3643","slug":"cve-2026-87677","externalId":"CVE-2026-87677","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87677 — An OS command injection vulnerability exists in the account management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.…","description":"An OS command injection vulnerability exists in the account management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When an administrator initiates an account deletion, the system invokes an internal maintenance routine to clean up cryptographic keys associated with the target account. Malformed account names previously accepted by Fabric OS can cause the execution of embedded shell metacharacters, triggering command injection.","cveId":"CVE-2026-87677","cvssScore":5.4,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39131","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00617,"epssPercentile":0.47967,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:05.833Z","addedAt":"2026-10-08T06:39:29.533Z","updatedAt":"2026-10-08T21:05:46.435Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87677","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87677","note":"authoritative record"}]},{"id":"9fc52de4-48c5-4a1e-9486-2e75c783dc5c","slug":"cve-2026-87662","externalId":"CVE-2026-87662","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87662 — Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of specific download protocols utilizes unsanitized parameter strings.","description":"Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of specific download protocols utilizes unsanitized parameter strings. When processing upgrade requests, parameters are converted into system command strings and executed through a system shell interface. Because control characters and shell metacharacters in fields like the host or file path are not stripped or sanitized, an attacker can execute arbitrary shell commands with the firmware management daemon's elevated privileges.","cveId":"CVE-2026-87662","cvssScore":7,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39162","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00238,"epssPercentile":0.13617,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:05.433Z","addedAt":"2026-10-08T06:39:29.510Z","updatedAt":"2026-10-08T21:05:46.334Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87662","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87662","note":"authoritative record"}]},{"id":"c773ca56-f3a6-4b0a-ad7f-2757aed7ceb8","slug":"cve-2026-87675","externalId":"CVE-2026-87675","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87675 — An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 throu…","description":"An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When performing a configuration download operation, the management daemon will relay configuration parameters, user-supplied relay host strings, and filenames directly to an internal utility script without sufficient character set validation. Because the local utility fails to sanitize shell metacharacters before processing them in a system shell command, a malicious or compromised configuration file can cause arbitrary operating system commands to be executed on a remote local switch when an administrator initiates a configuration download.","cveId":"CVE-2026-87675","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39146","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00733,"epssPercentile":0.52939,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T04:17:55.843Z","addedAt":"2026-10-08T04:39:33.070Z","updatedAt":"2026-10-08T21:05:46.030Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87675","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87675","note":"authoritative record"}]},{"id":"0ebe7274-e5d7-4ddb-91d2-3f77e64e6c9f","slug":"cve-2026-87674","externalId":"CVE-2026-87674","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87674 — A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.…","description":"A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Insufficient access controls on internal inter-process communication (IPC) channels allow an unprivileged local user to submit malformed logging configurations. Due to improper input sanitization during configuration file generation, an attacker can inject arbitrary directives that execute with elevated privileges when the logging service reloads, leading to local privilege escalation.","cveId":"CVE-2026-87674","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39145","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00108,"epssPercentile":0.01114,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T04:17:53.370Z","addedAt":"2026-10-08T04:39:33.062Z","updatedAt":"2026-10-08T21:05:46.015Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87674","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87674","note":"authoritative record"}]},{"id":"342192bc-6966-498d-acf5-2aa8fb098488","slug":"cve-2026-87673","externalId":"CVE-2026-87673","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87673 — An OS command injection vulnerability exists in maintenance command-line diagnostic utilities on Brocade Fabric OS versions before 9.2.2d and 10.0.…","description":"An OS command injection vulnerability exists in maintenance command-line diagnostic utilities on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. The binary fails to sanitize user-supplied input options when invoking underlying system commands through a shell interpreter. A privileged user with maintenance account access can exploit this issue by supplying crafted parameters, which results in arbitrary OS command execution with root privileges.","cveId":"CVE-2026-87673","cvssScore":7,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39144","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00899,"epssPercentile":0.58405,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T04:17:53.117Z","addedAt":"2026-10-08T04:39:33.055Z","updatedAt":"2026-10-08T21:05:45.966Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87673","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87673","note":"authoritative record"}]},{"id":"44e3d376-065e-4e15-974b-133d18fe9e5e","slug":"cve-2026-87666","externalId":"CVE-2026-87666","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87666 — An OS command injection vulnerability exists in the time and zone management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 throu…","description":"An OS command injection vulnerability exists in the time and zone management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When updating system timezone settings via the REST API or configuration download routines, the system fails to sanitize input values before processing them in underlying shell execution routines. An authenticated user with low-privilege administrative access can exploit this vulnerability by submitting a crafted timezone string containing shell metacharacters. Successful exploitation allows the attacker to escape the restricted management environment and execute arbitrary shell commands with elevated privileges.","cveId":"CVE-2026-87666","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39149","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.01847,"epssPercentile":0.78427,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T04:17:52.553Z","addedAt":"2026-10-08T04:39:33.041Z","updatedAt":"2026-10-08T21:05:45.923Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87666","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87666","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":1357,"totalPages":68,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:47:04.079Z","durationMs":30,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-78"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}