VulncastBriefing archive

Daily Brief - 2026-09-11

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-0310

Palo Alto Networks PAN-OS

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . Panorama is impacted by this vulnerability.

  • Buffer Overflow
  • Denial of Service
  • Remote Code Execution
  • firewall
  • operating system

CVE-2026-81467

critical · CVSS 9.8 · Dell ThinOS

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

  • OS Command Injection
  • operating system
  • endpoint management

CVE-2026-82098

high · CVSS 8.8 · IBM DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • Remote Code Execution
  • OS Command Injection
  • cloud platform
  • data integration

CVE-2026-88021

high · CVSS 7.1 · HashiCorp Consul

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

  • Authorization Bypass
  • service mesh

CVE-2026-89049

critical · CVSS 9.9 · Amazon AWS Systems Manager Agent

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address. To remediate this issue, users should upgrade to version 3.3.4851.0 or later.

  • Server-Side Request Forgery
  • cloud infrastructure
  • agent software