{"success":true,"data":{"threats":[{"id":"f8025a75-223a-4573-80ca-4aad96131dc2","slug":"cve-2026-88779","externalId":"CVE-2026-88779","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","description":"Vulnerability in NetScaler ADC and NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.","cveId":"CVE-2026-88779","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"citrix","product":"netscaler application delivery controller","affectedVersions":[">= 13.1, < 13.1-37.282",">= 13.1, < 13.1-64.28",">= 14.1, < 14.1-73.41",">= 14.1-66.68, <= 14.1-73.41"],"cwes":["CWE-119"],"tags":["nvd","status:received","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174","https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-88779"],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174","type":"other","title":"CISA catalog note"},{"url":"https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88779","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88779","type":"advisory","title":"US Government Resource"}],"epssScore":0.00592,"epssPercentile":0.46624,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T04:16:43.680Z","addedAt":"2026-10-04T05:50:39.777Z","updatedAt":"2026-10-08T22:07:08.685Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88779","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88779","note":"authoritative record"}]},{"id":"09ef0bc1-5b80-4a97-96e6-1e4fd3ed4819","slug":"cve-2026-104286","externalId":"CVE-2026-104286","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Fortinet FortiMail Path Traversal Vulnerability","description":"An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.","cveId":"CVE-2026-104286","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"fortinet","product":"fortimail","affectedVersions":[">= 7.2.0, <= 7.4.8",">= 7.6.0, <= 7.6.6",">= 8.0.0, <= 8.0.1"],"cwes":["CWE-22","CWE-158"],"tags":["nvd","status:awaiting-analysis","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://fortiguard.fortinet.com/psirt/FG-IR-26-175","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-104286"],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-175","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-104286","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104286","type":"other","title":"CISA catalog note"}],"epssScore":0.02201,"epssPercentile":0.81975,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T20:17:24.010Z","addedAt":"2026-10-01T21:50:40.700Z","updatedAt":"2026-10-08T22:07:08.766Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104286","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104286","note":"authoritative record"}]},{"id":"8a1d1956-4f31-4125-b8d0-5743d7556946","slug":"cve-2026-102490","externalId":"CVE-2026-102490","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Zammad GmbH Zammad Improper Privilege Management Vulnerability","description":"Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service processes began running as root and executed files that were owned and writable by the zammad account before dropping their identity to that account. An attacker holding that foothold could have escalated within seconds, because the affected services were restarted automatically whenever they stopped; no administrator interaction was required. Only installations from the DEB and RPM packages were affected — installations from source or the official container images were not. All released packaged versions were affected.","cveId":"CVE-2026-102490","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X","severity":"critical","vendor":"zammad","product":"zammad","affectedVersions":[">= 1.5.0, < 7.1.0","7.1.0"],"cwes":["CWE-269"],"tags":["nvd","status:received","status:deferred","status:undergoing-analysis","cisa-kev","known-exploited","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://zammad.com/en/product/releases/","https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-102490"],"references":[{"url":"https://csirt.divd.nl/CVE-2026-102490","type":"advisory","title":"Third Party Advisory"},{"url":"https://csirt.divd.nl/DIVD-2026-00015","type":"advisory","title":"Third Party Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102490","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://zammad.com/en/product/releases/","type":"other","title":"CISA catalog note"},{"url":"https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102490","type":"other","title":"CISA catalog note"},{"url":"https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490","type":"vendor","title":"Vendor Advisory"},{"url":"https://github.com/zammad/zammad/security/advisories/GHSA-p97w-927q-8vxq","type":"advisory","title":"csirt@divd.nl"}],"epssScore":0.00579,"epssPercentile":0.45908,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T17:16:40.707Z","addedAt":"2026-09-30T17:50:48.399Z","updatedAt":"2026-10-08T22:07:08.716Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102490","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102490","note":"authoritative record"}]},{"id":"b09325ce-90ce-4185-a0dd-116cadf9f21d","slug":"cve-2026-102489","externalId":"CVE-2026-102489","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Zammad GmbH Zammad Session Fixation Vulnerability","description":"Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.","cveId":"CVE-2026-102489","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X","severity":"critical","vendor":"zammad","product":"zammad","affectedVersions":[">= 6.3.0, < 6.5.4",">= 7.0.0, <= 7.1.3",">= 6.3.0, <= 6.5.4"],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred","status:undergoing-analysis","cisa-kev","known-exploited","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://zammad.com/en/product/releases/","https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-102489"],"references":[{"url":"https://csirt.divd.nl/CVE-2026-102489","type":"advisory","title":"Third Party Advisory"},{"url":"https://csirt.divd.nl/DIVD-2026-00015","type":"advisory","title":"Third Party Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102489","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://zammad.com/en/product/releases/","type":"other","title":"CISA catalog note"},{"url":"https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102489","type":"other","title":"CISA catalog note"},{"url":"https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.01255,"epssPercentile":0.68609,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T17:16:40.550Z","addedAt":"2026-09-30T17:50:48.394Z","updatedAt":"2026-10-08T22:07:08.746Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102489","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102489","note":"authoritative record"}]},{"id":"3987ec04-cc28-4a3e-9e29-2c3513b40af0","slug":"cve-2026-76504","externalId":"CVE-2026-76504","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability","description":"A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.\r\n\r\nThis vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.","cveId":"CVE-2026-76504","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"cisco","product":"catalyst sd-wan manager","affectedVersions":["< 20.9.10.1",">= 20.12, < 20.12.8.2",">= 20.15, < 20.15.6.1",">= 20.18, < 20.18.4.1",">= 26.1, < 26.1.2.1","26.2"],"cwes":["CWE-177"],"tags":["nvd","status:received","status:undergoing-analysis","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-76504"],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76504","type":"other","title":"CISA catalog note"}],"epssScore":0.01819,"epssPercentile":0.78084,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T13:17:20.247Z","addedAt":"2026-09-30T13:50:40.270Z","updatedAt":"2026-10-08T22:07:08.782Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76504","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76504","note":"authoritative record"}]},{"id":"385e7c66-6c26-44d3-a0aa-5eb7ef8a2eb4","slug":"cve-2026-86950","externalId":"CVE-2026-86950","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Apple Multiple Products Out-of-Bounds Write Vulnerability","description":"An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.","cveId":"CVE-2026-86950","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"apple","product":"ipados","affectedVersions":["< 26.7.1","< 15.8.1",">= 26.0, < 26.7.1"],"cwes":["CWE-787"],"tags":["nvd","status:awaiting-analysis","cisa-kev","known-exploited","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://support.apple.com/en-us/149226","https://support.apple.com/en-us/149228","https://support.apple.com/en-us/149229","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-86950"],"references":[{"url":"https://support.apple.com/en-us/149226","type":"other","title":"CISA catalog note"},{"url":"https://support.apple.com/en-us/149228","type":"other","title":"CISA catalog note"},{"url":"https://support.apple.com/en-us/149229","type":"other","title":"CISA catalog note"},{"url":"http://seclists.org/fulldisclosure/2026/Sep/89","type":"advisory","title":"Mailing List"},{"url":"http://seclists.org/fulldisclosure/2026/Sep/90","type":"advisory","title":"Mailing List"},{"url":"http://seclists.org/fulldisclosure/2026/Sep/91","type":"advisory","title":"Mailing List"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86950","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86950","type":"advisory","title":"US Government Resource"}],"epssScore":0.01242,"epssPercentile":0.68289,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T20:17:11.193Z","addedAt":"2026-09-28T21:50:39.544Z","updatedAt":"2026-10-08T22:07:08.800Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86950","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86950","note":"authoritative record"}]},{"id":"aa00f88a-72f0-4993-a42e-61a935262c9b","slug":"cve-2026-88772","externalId":"CVE-2026-88772","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","description":"Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service","cveId":"CVE-2026-88772","cvssScore":9.5,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"citrix","product":"netscaler application delivery controller","affectedVersions":[">= 13.1, < 13.1-64.23",">= 13.1, < 13.1.37.279",">= 14.1, < 14.1-73.37",">= 14.1-66.68, <= 14.1-73.37"],"cwes":["CWE-119"],"tags":["nvd","status:received","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778","https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096","https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-88772"],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778","type":"other","title":"CISA catalog note"},{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096","type":"other","title":"CISA catalog note"},{"url":"https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88772","type":"other","title":"CISA catalog note"}],"epssScore":0.01301,"epssPercentile":0.69594,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T17:16:56.390Z","addedAt":"2026-09-27T17:50:38.073Z","updatedAt":"2026-10-08T22:07:08.816Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88772","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88772","note":"authoritative record"}]},{"id":"929f8378-a81d-48cc-b94c-eadf47f45082","slug":"cve-2026-88771","externalId":"CVE-2026-88771","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Citrix NetScaler Improper Input Validation Vulnerability","description":"Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.","cveId":"CVE-2026-88771","cvssScore":9.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"citrix","product":"netscaler application delivery controller","affectedVersions":[">= 13.1, < 13.1-64.23",">= 13.1, < 13.1.37.279",">= 14.1, < 14.1-73.37",">= 14.1-66.68, <= 14.1-73.37"],"cwes":["CWE-20","CWE-119"],"tags":["nvd","status:received","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778","https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096","https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-88772"],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778","type":"other","title":"CISA catalog note"},{"url":"https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88772","type":"other","title":"CISA catalog note"}],"epssScore":0.01083,"epssPercentile":0.64178,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T17:16:56.260Z","addedAt":"2026-09-27T17:50:38.066Z","updatedAt":"2026-10-08T22:07:08.832Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88771","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88771","note":"authoritative record"}]},{"id":"6ae9cad3-22f8-4466-afb3-62469fb34bfc","slug":"cve-2026-87902","externalId":"CVE-2026-87902","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"WordPress Core Remote File Inclusion Vulnerability","description":"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.","cveId":"CVE-2026-87902","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"wordpress","product":"wordpress","affectedVersions":["< 4.7.37",">= 4.8, < 4.8.32",">= 4.9, < 4.9.33",">= 5.0, < 5.0.29",">= 5.1, < 5.1.26",">= 5.2, < 5.2.28",">= 5.3, < 5.3.25",">= 5.4, < 5.4.23",">= 5.5, < 5.5.22",">= 5.6, < 5.6.21",">= 5.7, < 5.7.19",">= 5.8, < 5.8.17",">= 5.9, < 5.9.18",">= 6.0, < 6.0.16",">= 6.1, < 6.1.14",">= 6.2, < 6.2.13",">= 6.3, < 6.3.12",">= 6.4, < 6.4.12",">= 6.5, < 6.5.12",">= 6.6, < 6.6.9",">= 6.7, < 6.7.9",">= 6.8, < 6.8.10",">= 6.9, < 6.9.9",">= 7.0, < 7.0.6",">= 7.1, < 7.1.2"],"cwes":["CWE-98"],"tags":["nvd","status:received","status:deferred","status:undergoing-analysis","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-87902"],"references":[{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp","type":"other","title":"CISA catalog note"},{"url":"https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/","type":"advisory","title":"Third Party Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87902","type":"other","title":"CISA catalog note"}],"epssScore":0.39979,"epssPercentile":0.98597,"nucleiTemplatePath":"http/cves/2026/CVE-2026-87902.yaml","nucleiSeverity":"critical","enrichment":null,"publishedAt":"2026-09-22T17:17:28.310Z","addedAt":"2026-09-22T17:50:43.535Z","updatedAt":"2026-10-08T22:07:08.881Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":"2026-09-23T19:53:01.362Z","links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87902","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87902","note":"authoritative record"},{"label":"Nuclei template","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-87902.yaml","note":"nuclei rates this critical"}]},{"id":"a073d7bb-c1ba-4825-8ec8-f85b8fac27c0","slug":"cve-2026-94127","externalId":"CVE-2026-94127","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability","description":"When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.\n\nImpact:\nThis vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.","cveId":"CVE-2026-94127","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"f5","product":"big-ip access policy manager","affectedVersions":[">= 17.0.0, <= 17.1.3",">= 17.5.0, <= 17.5.1","21.1.0"],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://my.f5.com/manage/s/article/K000162605","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-94127"],"references":[{"url":"https://my.f5.com/manage/s/article/K000162605","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94127","type":"other","title":"CISA catalog note"}],"epssScore":0.02226,"epssPercentile":0.82185,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T15:17:24.313Z","addedAt":"2026-09-22T15:50:38.441Z","updatedAt":"2026-10-08T22:07:08.985Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94127","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94127","note":"authoritative record"}]},{"id":"1ae93d8e-f7c0-48b3-9c81-76c94334fe03","slug":"cve-2026-93616","externalId":"CVE-2026-93616","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Check Point Multiple Products Path Traversal Vulnerability","description":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.","cveId":"CVE-2026-93616","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"checkpoint","product":"multi-domain security management","affectedVersions":[">= r80, < r81.10","r81.10","r81.20","r82","r82.10","r82.20"],"cwes":["CWE-22"],"tags":["nvd","status:received","status:awaiting-analysis","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://support.checkpoint.com/results/sk/sk1000171/","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-93616","https://support.checkpoint.com/results/sk/sk1000171"],"references":[{"url":"https://support.checkpoint.com/results/sk/sk1000171","type":"patch","title":"Mitigation"},{"url":"https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://support.checkpoint.com/results/sk/sk1000171/","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93616","type":"other","title":"CISA catalog note"}],"epssScore":0.19654,"epssPercentile":0.97333,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T13:17:11.963Z","addedAt":"2026-09-22T13:50:37.433Z","updatedAt":"2026-10-08T22:07:09.004Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93616","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93616","note":"authoritative record"}]},{"id":"d40db75c-413e-45f6-985e-72f3a0b660bd","slug":"cve-2026-93952","externalId":"CVE-2026-93952","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Arista VeloCloud Orchestrator Improper Input Validation Vulnerability","description":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.\n\nHosted, including Dedicated, versions of VCO were impacted and have already been patched.","cveId":"CVE-2026-93952","cvssScore":9.5,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"arista","product":"velocloud orchestrator","affectedVersions":[">= 5.2.0, < 5.2.3.16",">= 6.1.0, <= 6.1.3.7",">= 6.4.0, < 6.4.2.8",">= 7.0.0, <= 7.0.0.2"],"cwes":["CWE-20"],"tags":["nvd","status:received","status:awaiting-analysis","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-93952"],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93952","type":"other","title":"CISA catalog note"}],"epssScore":0.01062,"epssPercentile":0.63559,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T08:16:43.047Z","addedAt":"2026-09-22T09:50:37.295Z","updatedAt":"2026-10-08T22:07:08.972Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93952","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93952","note":"authoritative record"}]},{"id":"1b7618c1-9bef-43e7-92a7-ad57d47f3d45","slug":"cve-2026-87886","externalId":"CVE-2026-87886","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Acronis Backup Incorrect Default Permissions Vulnerability","description":"Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.","cveId":"CVE-2026-87886","cvssScore":7.8,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"acronis","product":"acronis backup","affectedVersions":["< 1.2.3","< 1.8.11","< 1.9.3","1.9.3"],"cwes":["CWE-276"],"tags":["cisa-kev","known-exploited","nvd","status:received","status:modified","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://security-advisory.acronis.com/advisories/SEC-10986","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-87886"],"references":[{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://security-advisory.acronis.com/advisories/SEC-10986","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87886","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/know%20n-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87886","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87886","type":"advisory","title":"US Government Resource"}],"epssScore":0.00233,"epssPercentile":0.13023,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T23:18:53.763Z","addedAt":"2026-09-16T22:51:16.444Z","updatedAt":"2026-10-08T22:07:09.197Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87886","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87886","note":"authoritative record"}]},{"id":"06973418-20f5-4812-b4c5-c2feb5e1aeaf","slug":"cve-2026-76460","externalId":"CVE-2026-76460","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","description":"A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.\r\n\r\nThis vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.","cveId":"CVE-2026-76460","cvssScore":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":"cisco","product":"identity services engine","affectedVersions":["3.1.0","3.2.0","3.3.0","3.4.0","3.5.0"],"cwes":["CWE-648"],"tags":["cisa-kev","known-exploited","nvd","status:received","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-76460"],"references":[{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76460","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460","type":"advisory","title":"US Government Resource"}],"epssScore":0.14026,"epssPercentile":0.96473,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T21:17:21.430Z","addedAt":"2026-09-16T18:51:16.390Z","updatedAt":"2026-10-08T22:07:09.185Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76460","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76460","note":"authoritative record"}]},{"id":"cbc762e6-4196-40ef-baee-d4229a403bb7","slug":"cve-2026-58704","externalId":"CVE-2026-58704","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Google Pixel Improper Authorization Vulnerability","description":"In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-58704","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"android","affectedVersions":[],"cwes":["CWE-285","CWE-693"],"tags":["nvd","status:received","cisa-kev","known-exploited","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-58704"],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58704","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58704","type":"advisory","title":"US Government Resource"}],"epssScore":0.00591,"epssPercentile":0.466,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T19:17:32.297Z","addedAt":"2026-09-15T19:50:37.546Z","updatedAt":"2026-10-08T22:07:09.161Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58704","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58704","note":"authoritative record"}]},{"id":"943d3be1-3b39-435e-b030-94b930521c5d","slug":"cve-2026-76461","externalId":"CVE-2026-76461","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Cisco Secure Email Gateway SQL Injection Vulnerability","description":"A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.\r\n\r\nThis vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.","cveId":"CVE-2026-76461","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"cisco","product":"asyncos","affectedVersions":["< 15.5.5-014",">= 16.0, < 16.0.4-302",">= 16.5, < 16.5.0-780"],"cwes":["CWE-89"],"tags":["nvd","status:received","status:undergoing-analysis","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-76461"],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76461","type":"other","title":"CISA catalog note"}],"epssScore":0.28269,"epssPercentile":0.98077,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T17:17:51.113Z","addedAt":"2026-09-14T17:50:35.968Z","updatedAt":"2026-10-08T22:07:09.208Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76461","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76461","note":"authoritative record"}]},{"id":"4f924f54-6d69-4a52-b9a1-c72532ec4b7f","slug":"cve-2026-85706","externalId":"CVE-2026-85706","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability","description":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.","cveId":"CVE-2026-85706","cvssScore":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","severity":"critical","vendor":"gitlab","product":"gitlab","affectedVersions":[">= 18.7.0, < 19.1.8",">= 19.2.0, < 19.2.6",">= 19.3.0, < 19.3.2",">= 18.7.0, < 18.11.12",">= 19.0.0, < 19.0.9",">= 19.1.0, < 19.1.8"],"cwes":["CWE-35","CWE-22"],"tags":["cisa-kev","known-exploited","nvd","status:received","status:undergoing-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-85706"],"references":[{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85706","type":"other","title":"CISA catalog note"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/627748","type":"advisory","title":"Broken Link"},{"url":"https://hackerone.com/reports/3909881","type":"advisory","title":"Permissions Required"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.92956,"epssPercentile":0.99831,"nucleiTemplatePath":"http/cves/2026/CVE-2026-85706.yaml","nucleiSeverity":"critical","enrichment":null,"publishedAt":"2026-09-12T03:16:30.473Z","addedAt":"2026-09-11T20:51:14.224Z","updatedAt":"2026-10-08T22:07:09.279Z","epssUpdatedAt":"2026-10-06T12:00:23.000Z","nucleiUpdatedAt":"2026-09-13T19:53:01.620Z","links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85706","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85706","note":"authoritative record"},{"label":"Nuclei template","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-85706.yaml"}]},{"id":"fe00a5b2-fae7-4d4d-8331-44768043bd69","slug":"cve-2026-85102","externalId":"CVE-2026-85102","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Check Point Multiple Products Improper Certificate Validation Vulnerability","description":"Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.","cveId":"CVE-2026-85102","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"checkpoint","product":"gaia embedded","affectedVersions":[">= r81.10.00, < r81.10.17",">= r82.00.00, < r82.00.10","r81.10.17","r82.00.10",">= r80, < r81.10","r81.10","r81.20","r82","r82.10"],"cwes":["CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://support.checkpoint.com/results/sk/sk1000117","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-85102"],"references":[{"url":"https://support.checkpoint.com/results/sk/sk1000117","type":"other","title":"CISA catalog note"},{"url":"https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85102","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85102","type":"other","title":"CISA catalog note"}],"epssScore":0.07546,"epssPercentile":0.94364,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T13:20:43.793Z","addedAt":"2026-09-09T13:51:15.726Z","updatedAt":"2026-10-08T22:07:09.035Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85102","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85102","note":"authoritative record"}]},{"id":"854b5a9f-91fe-4384-8ab0-24ff3e505095","slug":"cve-2026-87491","externalId":"CVE-2026-87491","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Google Chromium V8 Out of Bounds Write Vulnerability","description":"Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-87491","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 153.0.8010.36"],"cwes":["CWE-787"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","cisa-kev","known-exploited","status:modified","msrc","vendor-advisory","microsoft","cve"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-87491","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87491"],"references":[{"url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html","type":"other","title":"CISA catalog note"},{"url":"https://issues.chromium.org/issues/543557673","type":"advisory","title":"Permissions Required"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87491","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87491","type":"advisory","title":"US Government Resource"},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87491","type":"vendor","title":"Microsoft MSRC: Chromium CVE-2026-87491: Out of bounds write in V8"}],"epssScore":0.03142,"epssPercentile":0.8753,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T01:17:05.887Z","addedAt":"2026-09-09T01:50:33.896Z","updatedAt":"2026-10-08T22:07:09.388Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87491","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87491","note":"authoritative record"}]},{"id":"22207167-83f6-442a-9f61-23b7908d1e54","slug":"cve-2026-84869","externalId":"CVE-2026-84869","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability","description":"A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.","cveId":"CVE-2026-84869","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":"connectwise","product":"screenconnect","affectedVersions":["< 26.6.5.9742"],"cwes":["CWE-269","CWE-862"],"tags":["nvd","status:received","status:deferred","status:undergoing-analysis","cisa-kev","known-exploited","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-84869"],"references":[{"url":"https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869","type":"advisory","title":"Third Party Advisory"},{"url":"https://www.connectwise.com/company/trust/advisories","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869","type":"advisory","title":"US Government Resource"},{"url":"https://www.huntress.com/blog/rogue-screenconnect-installations","type":"advisory","title":"Third Party Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84869","type":"other","title":"CISA catalog note"}],"epssScore":0.00924,"epssPercentile":0.59222,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T20:18:51.147Z","addedAt":"2026-09-08T21:50:42.324Z","updatedAt":"2026-10-08T22:07:09.226Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84869","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84869","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":1740,"totalPages":87,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T22:31:09.259Z","durationMs":37,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":true,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}