VulncastBriefing archive

Daily Brief - 2026-09-15

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-76461

critical · CVSS 9.8 · Cisco Secure Email Gateway

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

  • Remote Code Execution
  • SQL Injection
  • email security

CVE-2026-85921

high · CVSS 8.2 · Microsoft Windows

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • Double Free
  • Privilege Escalation
  • operating system kernel

CVE-2026-87802

critical · CVSS 9.1 · Apache Syncope

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

  • Improper Authentication
  • Authentication Bypass
  • identity management
  • web application

CVE-2026-90703

critical · CVSS 9.1 · D-Link DWR-M921

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

  • Os Command Injection
  • router firmware

CVE-2026-90942

critical · CVSS 9.6 · Casdoor

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.

  • Information Disclosure
  • Authentication Bypass
  • web application
  • jwt