VulncastBriefing archive

Daily Brief - 2026-10-01

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-100255

high · CVSS 8.1 · JetBrains TeamCity

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset

  • Account Takeover
  • ci/cd pipeline

CVE-2026-102115

critical · CVSS 9.8 · Kiteworks Core

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

  • Authentication Bypass
  • authentication
  • workflow engine

CVE-2026-47505

high · CVSS 7.8 · NVIDIA GPU Display Driver

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, or escalation of privileges, information disclosure, and data tampering.

  • Use-After-Free
  • Remote Code Execution
  • Denial Of Service
  • Privilege Escalation
  • Information Disclosure
  • kernel driver
  • graphics driver

CVE-2026-76504

critical · CVSS 9.8 · Cisco Catalyst SD-WAN Manager

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

  • Authentication Bypass
  • network management software

CVE-2026-94052

critical · CVSS 9.1 · Apache Software Foundation MINA SSHD

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator. Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.

  • Authentication Bypass
  • java
  • ssh server