VulncastBriefing archive

Daily Brief - 2026-09-02

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-76658

critical · CVSS 10 · HPE Networking Fabric Composer

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

  • Remote Code Execution
  • network management

CVE-2026-78592

high · CVSS 7.3 · Elastic Kibana

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent administrative action in the tag management interface to act on an unintended target, resulting in the deletion of privileged resources including administrative accounts and other organizational assets. Exploitation requires an administrator to interact with the affected interface.

  • Path Traversal
  • web application
  • data visualization

CVE-2026-79682

high · CVSS 8.8 · Dell PowerStore

Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

  • Command Injection
  • Privilege Escalation
  • storage appliance

CVE-2026-84121

critical · CVSS 9.6 · Mozilla Firefox

Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • Use-After-Free
  • Sandbox Escape
  • web browser
  • email client

CVE-2026-9637

Rockwell Automation Logix

A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover

  • Denial Of Service
  • industrial automation
  • plc