VulncastBriefing archive

Daily Brief - 2026-10-09

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-107406

Citrix NetScaler ADC

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive   For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37  * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS  * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

  • Memory Overflow
  • Remote Code Execution
  • Denial of Service
  • load balancer
  • network appliance

CVE-2026-16340

critical · CVSS 9.8 · IBM DataPower Gateway

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.

  • Remote Code Execution
  • Buffer Overflow
  • api gateway
  • web service security

CVE-2026-89091

high · CVSS 8.8 · ansible-core

A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the privileges of the user running ansible-galaxy, leading to code execution on the control node. This is a bypass of the fix for CVE-2020-10691.

  • Path Traversal
  • Arbitrary Code Execution
  • automation tool

CVE-2026-93858

OpenStack Mistral

In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted. An authenticated project member can use the standard action-execution API to submit an arbitrary local command as proxy_command; paramiko starts that command as a subprocess on the executor host under the executor's own service account, independent of whether the SSH connection itself ever succeeds. Only Mistral deployments that permit the std.ssh_proxied action, the default configuration, are affected.

  • Remote Code Execution
  • cloud orchestration

CVE-2026-96207

critical · CVSS 10 · Microsoft Partner Center

Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

  • Privilege Escalation
  • web application