VulncastBriefing archive

Daily Brief - 2026-09-08

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-18922

critical · CVSS 9.8 · Red Hat 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.

  • Authentication Bypass
  • directory server

CVE-2026-61410

critical · CVSS 9.4 · Dell Secure Connect Gateway

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system by sending a specially crafted request to the application, bypassing intended restrictions on code execution.Dell recommends customers to upgrade at the earliest opportunity.

  • Remote Code Execution
  • appliance
  • gateway

CVE-2026-75650

critical · CVSS 10 · Adobe Commerce

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

  • Remote Code Execution
  • template engine

CVE-2026-85640

medium · CVSS 6.3 · Zohocorp ManageEngine Endpoint Central

Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component

  • Privilege Escalation
  • endpoint management

CVE-2026-86480

critical · CVSS 9.8 · JetBrains Hub

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

  • Privilege Escalation
  • web application