VulncastBriefing archive

Daily Brief - 2026-10-03

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-102795

critical · CVSS 9.3 · Apache Traffic Server

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected.

  • Improper Access Control
  • web server

CVE-2026-103628

critical · CVSS 9.6 · Google Chrome

Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • Out Of Bounds Write
  • Remote Code Execution
  • web browser
  • webgl

CVE-2026-84411

critical · CVSS 9.8 · MikroTik RouterOS

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

  • Integer Underflow
  • Remote Code Execution
  • Denial of Service
  • router firmware
  • network appliance

CVE-2026-90970

critical · CVSS 9.9 · GitLab AI Gateway

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

  • Remote Code Execution
  • Sandbox Escape
  • ai software
  • web application

CVE-2026-96940

high · CVSS 8.8 · Microsoft Exchange Server

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

  • Privilege Escalation
  • email server