VulncastBriefing archive

Daily Brief - 2026-09-03

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-20212

critical · CVSS 9.8 · Cisco Nexus 9000 Series Switches

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

  • Remote Code Execution
  • network switch

CVE-2026-66842

high · CVSS 8.8 · F5 BIG-IP

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • Privilege Escalation
  • network appliance
  • load balancer

CVE-2026-78604

high · CVSS 7.8 · Elastic Agent

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.

  • Incorrect Permission Assignment
  • Local Privilege Escalation
  • Replace Binaries
  • operating system services

CVE-2026-84354

critical · CVSS 9.6 · Google Chrome

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • Remote Code Execution
  • web browser

CVE-2026-84795

critical · CVSS 9.8 · Craft CMS

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

  • Privilege Escalation
  • php
  • web application