{"success":true,"data":{"threats":[{"id":"8c5bd16c-33d4-4039-a4b3-9523bc309a80","slug":"cve-2026-106326","externalId":"CVE-2026-106326","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106326 — Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions into a pr…","description":"Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)","cveId":"CVE-2026-106326","cvssScore":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/511745101","type":"advisory","title":"Permissions Required"}],"epssScore":0.00082,"epssPercentile":0.00191,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:00.900Z","addedAt":"2026-10-06T20:39:31.631Z","updatedAt":"2026-10-08T16:39:34.796Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106326","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106326","note":"authoritative record"}]},{"id":"f0a0dd3a-f79d-453b-a980-fad277260873","slug":"cve-2026-106324","externalId":"CVE-2026-106324","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106324 — Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access r…","description":"Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106324","cvssScore":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-863"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/501171258","type":"advisory","title":"Permissions Required"}],"epssScore":0.0018,"epssPercentile":0.06958,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:00.677Z","addedAt":"2026-10-06T20:39:31.611Z","updatedAt":"2026-10-08T16:39:34.783Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106324","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106324","note":"authoritative record"}]},{"id":"f56ded8f-bff7-4e9b-a107-ec7456d0eaf4","slug":"cve-2026-106250","externalId":"CVE-2026-106250","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106250 — Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system acc…","description":"Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)","cveId":"CVE-2026-106250","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-862"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/502497790","type":"advisory","title":"Permissions Required"}],"epssScore":0.0017,"epssPercentile":0.0583,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:52.053Z","addedAt":"2026-10-06T20:39:31.025Z","updatedAt":"2026-10-07T22:39:36.100Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106250","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106250","note":"authoritative record"}]},{"id":"c8d37fde-c6d9-4c11-96b1-1cf0f1609475","slug":"cve-2026-106244","externalId":"CVE-2026-106244","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106244 — Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via c…","description":"Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)","cveId":"CVE-2026-106244","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-863"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/502475175","type":"advisory","title":"Permissions Required"}],"epssScore":0.00182,"epssPercentile":0.07078,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:51.367Z","addedAt":"2026-10-06T20:39:30.979Z","updatedAt":"2026-10-08T12:39:41.047Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106244","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106244","note":"authoritative record"}]},{"id":"0a7a1b0c-8813-40a4-870e-be476487b598","slug":"cve-2026-106242","externalId":"CVE-2026-106242","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106242 — Information leak in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak s…","description":"Information leak in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)","cveId":"CVE-2026-106242","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-200"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/501647772","type":"advisory","title":"Permissions Required"}],"epssScore":0.00228,"epssPercentile":0.12538,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:51.143Z","addedAt":"2026-10-06T20:39:30.959Z","updatedAt":"2026-10-08T12:39:41.034Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106242","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106242","note":"authoritative record"}]},{"id":"20e1c2b5-0556-4175-a68a-65c9158f3c1f","slug":"cve-2026-106198","externalId":"CVE-2026-106198","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106198 — Missing authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to b…","description":"Missing authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106198","cvssScore":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-862"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/510773353","type":"advisory","title":"Permissions Required"}],"epssScore":0.00224,"epssPercentile":0.11989,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:46.020Z","addedAt":"2026-10-06T20:39:30.617Z","updatedAt":"2026-10-08T16:39:34.754Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106198","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106198","note":"authoritative record"}]},{"id":"fb5d81f8-6f30-4046-98e3-e5fba6353034","slug":"cve-2026-106196","externalId":"CVE-2026-106196","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106196 — Missing authorization in Navigation in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy into a …","description":"Missing authorization in Navigation in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106196","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-862"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/504215649","type":"advisory","title":"Permissions Required"}],"epssScore":0.00224,"epssPercentile":0.11989,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:45.787Z","addedAt":"2026-10-06T20:39:30.601Z","updatedAt":"2026-10-08T18:39:30.171Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106196","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106196","note":"authoritative record"}]},{"id":"c8809af4-517a-4399-80fb-0f8ba874268b","slug":"cve-2026-106188","externalId":"CVE-2026-106188","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106188 — Confused deputy in SignIn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into…","description":"Confused deputy in SignIn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106188","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/515477538","type":"advisory","title":"Permissions Required"}],"epssScore":0.00222,"epssPercentile":0.11685,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:44.860Z","addedAt":"2026-10-06T20:39:30.526Z","updatedAt":"2026-10-08T16:39:34.740Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106188","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106188","note":"authoritative record"}]},{"id":"51ea1034-8e1f-45ab-bc96-df54ccc47b83","slug":"cve-2026-105749","externalId":"CVE-2026-105749","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105749 — Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem.","description":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/backend/html_backend.py, docling/backend/jats_backend.py, and docling/backend/boxnote_backend.py, accept the rowspan and colspan attribute values without an upper bound and execute loops or allocate a table grid proportional to the declared span. A very small document can therefore cause sustained CPU use or multi-gigabyte memory allocation, and the document_timeout setting does not interrupt the single backend conversion call. Export through the TableData.grid property can further materialize the oversized grid. This issue is fixed in 2.131.0.","cveId":"CVE-2026-105749","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"docling","product":"docling","affectedVersions":[">= 2.0.0, < 2.131.0","pkg:pypi/docling >= 2.0.0, < 2.131.0","pkg:pypi/docling-slim >= 2.92.0, < 2.131.0"],"cwes":["CWE-400","CWE-789"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","osv","osv:ghsa-cgc7-9qp3-86m3","ecosystem:pypi","status:modified","osv:pysec-2026-4195"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/docling-project/docling/commit/c5b4429cc6500a344c13edeb22e67610c2159b09","https://github.com/docling-project/docling/pull/4414","https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3"],"references":[{"url":"https://github.com/docling-project/docling/commit/c5b4429cc6500a344c13edeb22e67610c2159b09","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/pull/4414","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/releases/tag/v2.131.0","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3","type":"patch","title":"OSV fix"},{"url":"https://osv.dev/vulnerability/GHSA-cgc7-9qp3-86m3","type":"advisory","title":"OSV GHSA-cgc7-9qp3-86m3"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105749","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4195","type":"advisory","title":"OSV PYSEC-2026-4195"}],"epssScore":0.00266,"epssPercentile":0.16968,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T22:16:57.943Z","addedAt":"2026-10-05T23:50:40.412Z","updatedAt":"2026-10-08T12:42:40.313Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105749","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105749","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-CGC7-9QP3-86M3"}]},{"id":"8a1d1956-4f31-4125-b8d0-5743d7556946","slug":"cve-2026-102490","externalId":"CVE-2026-102490","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Zammad GmbH Zammad Improper Privilege Management Vulnerability","description":"Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service processes began running as root and executed files that were owned and writable by the zammad account before dropping their identity to that account. An attacker holding that foothold could have escalated within seconds, because the affected services were restarted automatically whenever they stopped; no administrator interaction was required. Only installations from the DEB and RPM packages were affected — installations from source or the official container images were not. All released packaged versions were affected.","cveId":"CVE-2026-102490","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X","severity":"critical","vendor":"zammad","product":"zammad","affectedVersions":[">= 1.5.0, < 7.1.0","7.1.0"],"cwes":["CWE-269"],"tags":["nvd","status:received","status:deferred","status:undergoing-analysis","cisa-kev","known-exploited","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://zammad.com/en/product/releases/","https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-102490"],"references":[{"url":"https://csirt.divd.nl/CVE-2026-102490","type":"advisory","title":"Third Party Advisory"},{"url":"https://csirt.divd.nl/DIVD-2026-00015","type":"advisory","title":"Third Party Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102490","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://zammad.com/en/product/releases/","type":"other","title":"CISA catalog note"},{"url":"https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102490","type":"other","title":"CISA catalog note"},{"url":"https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490","type":"vendor","title":"Vendor Advisory"},{"url":"https://github.com/zammad/zammad/security/advisories/GHSA-p97w-927q-8vxq","type":"advisory","title":"csirt@divd.nl"}],"epssScore":0.00579,"epssPercentile":0.45908,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T17:16:40.707Z","addedAt":"2026-09-30T17:50:48.399Z","updatedAt":"2026-10-08T23:07:08.030Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102490","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102490","note":"authoritative record"}]},{"id":"b09325ce-90ce-4185-a0dd-116cadf9f21d","slug":"cve-2026-102489","externalId":"CVE-2026-102489","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Zammad GmbH Zammad Session Fixation Vulnerability","description":"Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.","cveId":"CVE-2026-102489","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X","severity":"critical","vendor":"zammad","product":"zammad","affectedVersions":[">= 6.3.0, < 6.5.4",">= 7.0.0, <= 7.1.3",">= 6.3.0, <= 6.5.4"],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred","status:undergoing-analysis","cisa-kev","known-exploited","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://zammad.com/en/product/releases/","https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-102489"],"references":[{"url":"https://csirt.divd.nl/CVE-2026-102489","type":"advisory","title":"Third Party Advisory"},{"url":"https://csirt.divd.nl/DIVD-2026-00015","type":"advisory","title":"Third Party Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102489","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://zammad.com/en/product/releases/","type":"other","title":"CISA catalog note"},{"url":"https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102489","type":"other","title":"CISA catalog note"},{"url":"https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.01255,"epssPercentile":0.68609,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T17:16:40.550Z","addedAt":"2026-09-30T17:50:48.394Z","updatedAt":"2026-10-08T23:07:08.042Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102489","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102489","note":"authoritative record"}]},{"id":"60050da0-17c0-41d9-ab01-75862af83d00","slug":"cve-2026-98164","externalId":"CVE-2026-98164","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-98164 — In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: Check write tracking in all address spaces\n\nkvm_gfn_is_write_tra…","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: Check write tracking in all address spaces\n\nkvm_gfn_is_write_tracked() checks only the supplied memslot, but page\ntracking is per-address-space and shadow pages are shared across all\naddress spaces.  With SMM, a GFN can therefore be write-tracked in one\naddress space and appear untracked through the other.\n\nCheck the supplied slot first, then the slot for the other address space.\nThis ensures all callers honor write tracking regardless of the active\naddress space.  In particular, it prevents mmu_try_to_unsync_pages() from\nmarking an upper-level shadow page unsync and eventually triggering the\nBUG in pte_list_remove().\n\n[invert direction of the conditional. - Paolo]","cveId":"CVE-2026-98164","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"linux","product":"linux kernel","affectedVersions":[">= 4.2, < 6.1.187",">= 6.2, < 6.6.156",">= 6.7, < 6.12.108",">= 6.13, < 6.18.49",">= 6.19, < 7.1.13","7.2"],"cwes":["CWE-670"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://git.kernel.org/stable/c/09aa68552d2542cc6c23edd1568ac265dc5d886f","https://git.kernel.org/stable/c/0f38453cdb2e17566ccb7c0f3dabd5bd21caca26","https://git.kernel.org/stable/c/429b6f43b4d8c98988fdca99e02dc156134e3d77","https://git.kernel.org/stable/c/c0a9bd5fca0b5f2dea32b0fc31350e71e8648112","https://git.kernel.org/stable/c/d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212a","https://git.kernel.org/stable/c/ec8fcaf354c1cbb36755d48e9f5a00c9591349e5"],"references":[{"url":"https://git.kernel.org/stable/c/09aa68552d2542cc6c23edd1568ac265dc5d886f","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/0f38453cdb2e17566ccb7c0f3dabd5bd21caca26","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/429b6f43b4d8c98988fdca99e02dc156134e3d77","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/c0a9bd5fca0b5f2dea32b0fc31350e71e8648112","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212a","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/ec8fcaf354c1cbb36755d48e9f5a00c9591349e5","type":"patch","title":"Patch"}],"epssScore":0.00149,"epssPercentile":0.03537,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T13:17:53.710Z","addedAt":"2026-09-29T13:50:39.799Z","updatedAt":"2026-10-07T08:39:32.554Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98164","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-98164","note":"authoritative record"}]},{"id":"1a02a360-f916-43e0-a155-9ced67d8424f","slug":"cve-2026-88777","externalId":"CVE-2026-88777","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88777 — Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.","description":"Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service","cveId":"CVE-2026-88777","cvssScore":8.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"citrix","product":"netscaler application delivery controller","affectedVersions":[">= 13.1, < 13.1-64.23",">= 13.1, < 13.1.37.279",">= 14.1, < 14.1-73.37",">= 14.1-66.68, <= 14.1-73.37"],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00384,"epssPercentile":0.30331,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T17:16:56.990Z","addedAt":"2026-09-27T17:50:38.109Z","updatedAt":"2026-09-29T23:50:39.044Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88777","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88777","note":"authoritative record"}]},{"id":"9a5df1f3-3825-40ad-a9ba-176fb2edb87d","slug":"cve-2026-88776","externalId":"CVE-2026-88776","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88776 — Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.","description":"Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service","cveId":"CVE-2026-88776","cvssScore":8.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"citrix","product":"netscaler application delivery controller","affectedVersions":[">= 13.1, < 13.1-64.23",">= 13.1, < 13.1.37.279",">= 14.1, < 14.1-73.37",">= 14.1-66.68, <= 14.1-73.37"],"cwes":["CWE-119"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00384,"epssPercentile":0.30331,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T17:16:56.870Z","addedAt":"2026-09-27T17:50:38.102Z","updatedAt":"2026-09-29T17:50:39.905Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88776","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88776","note":"authoritative record"}]},{"id":"81dd6df4-46c4-4799-9012-deba1623f3cb","slug":"cve-2026-88775","externalId":"CVE-2026-88775","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88775 — Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.","description":"Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service","cveId":"CVE-2026-88775","cvssScore":8.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"citrix","product":"netscaler application delivery controller","affectedVersions":[">= 13.1, < 13.1-64.23",">= 13.1, < 13.1.37.279",">= 14.1, < 14.1-73.37",">= 14.1-66.68, <= 14.1-73.37"],"cwes":["CWE-120"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00384,"epssPercentile":0.30331,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T17:16:56.750Z","addedAt":"2026-09-27T17:50:38.095Z","updatedAt":"2026-09-29T17:50:39.894Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88775","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88775","note":"authoritative record"}]},{"id":"67cc4da6-6f32-4776-a3e0-5401c17eb4e7","slug":"cve-2026-88774","externalId":"CVE-2026-88774","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88774 — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.","description":"Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.","cveId":"CVE-2026-88774","cvssScore":7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"citrix","product":"netscaler application delivery controller","affectedVersions":[">= 13.1, < 13.1-64.23",">= 13.1, < 13.1.37.279",">= 14.1, < 14.1-73.37",">= 14.1-66.68, <= 14.1-73.37"],"cwes":["CWE-20"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00241,"epssPercentile":0.13956,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T17:16:56.633Z","addedAt":"2026-09-27T17:50:38.089Z","updatedAt":"2026-09-29T17:50:39.886Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88774","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88774","note":"authoritative record"}]},{"id":"0842ef45-0c01-42ab-8a96-f8456da83d3d","slug":"cve-2026-100843","externalId":"CVE-2026-100843","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100843 — MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deseriali…","description":"MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.","cveId":"CVE-2026-100843","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"project-monai","product":"monai","affectedVersions":["pkg:pypi/monai < 1.6.0","< 1.6.0"],"cwes":["CWE-502"],"tags":["nvd","status:received","osv","osv:ghsa-qxq5-qhx6-94qw","ecosystem:pypi","status:awaiting-analysis","status:analyzed","status:modified","osv:pysec-2026-4018"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Project-MONAI/MONAI/security/advisories/GHSA-qxq5-qhx6-94qw","type":"exploit","title":"OSV evidence"},{"url":"https://www.vulncheck.com/advisories/monai-before-1.6.0-remote-code-execution-via-algo-from-pickle","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/GHSA-qxq5-qhx6-94qw","type":"advisory","title":"OSV GHSA-qxq5-qhx6-94qw"},{"url":"https://github.com/Project-MONAI/MONAI","type":"vendor","title":"OSV package"},{"url":"https://github.com/Project-MONAI/MONAI/releases/tag/1.6.0","type":"other","title":"OSV web"},{"url":"https://github.com/advisories/GHSA-89gg-p5r5-q6r4","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4018","type":"advisory","title":"OSV PYSEC-2026-4018"}],"epssScore":0.00196,"epssPercentile":0.08543,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T02:17:22.853Z","addedAt":"2026-09-27T03:50:37.881Z","updatedAt":"2026-10-01T13:54:24.381Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100843","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100843","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-QXQ5-QHX6-94QW"}]},{"id":"5300c9e4-acb8-48ba-b1d5-072ff3ade240","slug":"cve-2026-98163","externalId":"CVE-2026-98163","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-98163 — In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: Avoid iteration of dying tasks with zero refcount\n\nThe commit 260fbcb9…","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: Avoid iteration of dying tasks with zero refcount\n\nThe commit 260fbcb92bbea (\"cgroup: Move dying_tasks cleanup from\ncgroup_task_release() to cgroup_task_free()\") extended the lifetime of\ntasks on the dying_tasks list.\nThe iterators have provision to go through dying_tasks because of\ndying threadgroup leaders or explicit CSS_TASK_ITER_WITH_DEAD, however,\nit was expected that such tasks can obtain a new reference (that is\npossible before cgroup_task_release()/put_task_struct_rcu_user()).\nThe tasks after cgroup_task_release() and before cgroup_task_free()\nare subject to race when they may or may not have ->usage count > 0.\n\nThe race window is between css_task_iter_next() invocations\nwhen css_set_lock is released and we may arrive at a new ->task_pos.\nThe iterator should not attempt to resurrect tasks whose ->usage count\ndropped to zero. (When that happens, __put_task_struct_rcu_cb() is\nalready imminent and the returned task_struct would could be used\nafter free.)\n\nAs for the fix, we cannot simply check the signal->live count of a task\non the dying list because that won't distinguish regular zombies waiting\nto be reaped from RCU remnant tasks that are going to be free'd.\nTherefore add an extra check to rule out ->usage==0 tasks from any\niteration.\n\nThe repeat: loop in css_task_iter_advance() doesn't consider ->usage\ncount, so add a new loop to css_task_iter_next() to skip de-used tasks\non the dying_list.\n\nRough illustration of the possible race\n\n  R (reader of cgroup.procs)         T (thread)                       L (group leader)\n  ---------------------------------  -------------------------------- --------------------------------\n                                                                      L exits, signal->live > 0\n                                                                      cgroup_task_dead(L)\n                                                                        css_set_skip_task_iters() // skips only cset->tasks\n                                                                        list_add_tail(&L->cg_list, &cset->dying_tasks)\n  css_task_iter_next()\n    take css_set_lock\n    css_task_iter_advance()\n      leader && signal->live != 0\n      => it->task_pos = &L->cg_list\n    release css_set_lock\n                                     T exits\n                                     --signal->live == 0\n\t\t\t\t     cgroup_task_dead(T) // css_set_lock\n                                     release_task(T)\n                                       cgroup_task_release(T)\n                                       release_task(L) // zap_leader\n                                         cgroup_task_release(L)\n                                         put_task_struct_rcu_user(L)\n                                         ...RCU...\n                                         put_task_struct(L)\n                                           L->usage = 0\n                                           /* L still on dying_tasks */\n                                           ...RCU...\n                                           __put_task_struct(L)\n  css_task_iter_next() // another iteration\n    take css_set_lock\n    it->task_pos = &L->cg_list\n    get_task_struct(L)\n      => addition on 0\n    drop css_set_lock\n                                           cgroup_task_free(L)\n                                             css_set_skip_task_iters() // dying skip comes too late\n                                           free_task(L)\n  cgroup_procs_show()\n    task_pid_vnr(L)","cveId":"CVE-2026-98163","cvssScore":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"linux","product":"linux kernel","affectedVersions":[">= 6.19, < 7.2.8","7.3"],"cwes":["CWE-362","CWE-416"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://git.kernel.org/stable/c/057dac23d329d5c5ed62352f2659a39fd46c6d4a","https://git.kernel.org/stable/c/828938118d6c2bb711301748c3e39e4bed6a62f5"],"references":[{"url":"https://git.kernel.org/stable/c/057dac23d329d5c5ed62352f2659a39fd46c6d4a","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/828938118d6c2bb711301748c3e39e4bed6a62f5","type":"patch","title":"Patch"}],"epssScore":0.00105,"epssPercentile":0.01013,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-26T09:16:38.303Z","addedAt":"2026-09-26T09:50:37.559Z","updatedAt":"2026-10-07T08:39:32.539Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98163","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-98163","note":"authoritative record"}]},{"id":"90bb061f-cfc1-466e-bd19-faba2477e0cd","slug":"cve-2026-98161","externalId":"CVE-2026-98161","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-98161 — In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm: pmem: keep PREFLUSH before data writes\n\npmem_submit_bio() records a RE…","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm: pmem: keep PREFLUSH before data writes\n\npmem_submit_bio() records a REQ_PREFLUSH error, but continues to copy the\nbio data and can later overwrite the error with a successful REQ_FUA flush.\nThat lets data writes run after a failed preflush and can complete the bio\nsuccessfully despite the failed ordering barrier.\n\nRun the REQ_PREFLUSH flush synchronously before touching the bio data and\ncomplete the bio with the flush error if it fails. Keep asynchronous flush\nchaining for REQ_FUA. At that point, data copy has completed and the parent\nbio can wait for the chained flush bio.","cveId":"CVE-2026-98161","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"linux","product":"linux kernel","affectedVersions":[">= 5.3, < 6.18.52",">= 6.19, < 7.2.6"],"cwes":["CWE-754"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://git.kernel.org/stable/c/72561ca1ab96f0f0f32737a6171641e05a318538","https://git.kernel.org/stable/c/770a90c2127220f0fc194ce909ad4f0842e141cb","https://git.kernel.org/stable/c/c644a2f8fef5618fcf453c591177700fd07dd024"],"references":[{"url":"https://git.kernel.org/stable/c/72561ca1ab96f0f0f32737a6171641e05a318538","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/770a90c2127220f0fc194ce909ad4f0842e141cb","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/c644a2f8fef5618fcf453c591177700fd07dd024","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/d34c30bc994328d9cf6749b2e9a32aabd08fd076","type":"advisory","title":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"epssScore":0.00114,"epssPercentile":0.01352,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-25T14:17:27.770Z","addedAt":"2026-09-25T15:50:39.435Z","updatedAt":"2026-10-03T11:50:42.660Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98161","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-98161","note":"authoritative record"}]},{"id":"3e4ad353-0ef8-46aa-b1d1-f759db51f96b","slug":"cve-2026-95844","externalId":"CVE-2026-95844","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95844 — Moquette is a lightweight Java MQTT broker.","description":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations. A remote client can publish or subscribe with a deeply nested topic, causing a StackOverflowError that disrupts session processing and can deny service to broker clients. This issue is fixed in version 0.18.1.","cveId":"CVE-2026-95844","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"moquette","product":"moquette","affectedVersions":["< 0.18.1"],"cwes":["CWE-674"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049"],"references":[{"url":"https://github.com/moquette-io/moquette/commit/ca17e0be19e86d5e291f4532dfdc94616c8e0049","type":"patch","title":"Patch"},{"url":"https://github.com/moquette-io/moquette/releases/tag/v0.18.1","type":"advisory","title":"Release Notes"},{"url":"https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq","type":"vendor","title":"Exploit"}],"epssScore":0.00358,"epssPercentile":0.27502,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T17:17:21.280Z","addedAt":"2026-09-23T17:50:39.978Z","updatedAt":"2026-09-29T03:50:38.286Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95844","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95844","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":7521,"totalPages":377,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:43:42.073Z","durationMs":54,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["status:modified"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}