VulncastBriefing archive

Daily Brief - 2026-09-24

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-6721

critical · CVSS 9.8 · IBM Concert

IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.

  • Remote Code Execution
  • Command Injection
  • application platform

CVE-2026-70125

high · CVSS 8.8 · Microsoft Outlook

Microsoft Outlook Remote Code Execution Vulnerability

  • Remote Code Execution
  • email client

CVE-2026-76183

critical · CVSS 9.8 · Apache Tomcat

Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

  • Authentication Bypass
  • web server
  • websocket

CVE-2026-84719

critical · CVSS 9.9 · Red Hat Ansible Automation Platform

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.

  • Broken Access Control
  • automation controller

CVE-2026-86708

critical · CVSS 10 · Zoho ManageEngine Applications Manager

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.

  • Information Disclosure
  • Impersonation
  • monitoring software