VulncastBriefing archive

Daily Brief - 2026-09-30

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-100819

critical · CVSS 9.6 · Mozilla Firefox

Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

  • Sandbox Escape
  • web browser
  • operating system interaction

CVE-2026-84436

critical · CVSS 9.1 · IBM Guardium Data Protection

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.

  • Command Injection
  • database management

CVE-2026-84739

high · CVSS 8.7 · GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary JavaScript in the context of another user's browser session due to improper sanitization of path components in the merge request diff viewer.

  • Cross-Site Scripting
  • devops platform

CVE-2026-91048

Apache Karaf

The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a fully attacker-controlled JDBC URL into a pax-jdbc-config factory Configuration with no validation. pax-jdbc-config reactively turns that into a live DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2 INIT=RUNSCRIPT), so a viewer-level shell user could reach arbitrary code execution, bypassing the admin-role gate that already protects shell:exec. This is a privilege-escalation-to-RCE chain, not merely an "admin misconfiguration". The same applies to jms:* shell commands.

  • Broken Access Control
  • Remote Code Execution
  • Privilege Escalation
  • java
  • application server

CVE-2026-95357

critical · CVSS 9.6 · Google Chrome

Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • Out of Bounds Write
  • web browser