VulncastBriefing archive

Weekly Brief - 2026-09-07

· 2291 vulnerabilities · 11 min listen

▶ Listen to this briefing

CVE-2026-58574

critical · CVSS 9.8 · Dell PowerStore

Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.

  • Broken Authentication
  • storage appliance

CVE-2026-82854

critical · CVSS 9.8 · Nodemailer

Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without sanitization, allowing injection of arbitrary SMTP commands such as RCPT TO to silently add attacker-controlled recipients. Exploitation requires the application to expose the envelope size to attacker-controlled input, as Nodemailer does not include size in the default auto-constructed envelope.

  • Command Injection
  • node.js
  • email
  • smtp

CVE-2026-76658

critical · CVSS 10 · HPE Networking Fabric Composer

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

  • Remote Code Execution
  • network management

CVE-2026-84121

critical · CVSS 9.6 · Mozilla Firefox

Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • Use-After-Free
  • Sandbox Escape
  • web browser
  • email client

CVE-2026-20212

critical · CVSS 9.8 · Cisco Nexus 9000 Series Switches

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

  • Remote Code Execution
  • network switch

CVE-2026-84354

critical · CVSS 9.6 · Google Chrome

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • Remote Code Execution
  • web browser

CVE-2026-84795

critical · CVSS 9.8 · Craft CMS

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

  • Privilege Escalation
  • php
  • web application

CVE-2026-70352

critical · CVSS 10 · Microsoft Azure AI Language

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

  • Privilege Escalation
  • cloud platform
  • artificial intelligence

CVE-2026-85050

critical · CVSS 9.6 · Google Chrome

Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • Out Of Bounds Write
  • Remote Code Execution
  • web browser
  • mobile application

CVE-2026-78327

critical · CVSS 9.1 · SonicWall Network Security Manager

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.

  • OS Command Injection
  • Remote Code Execution
  • network management
  • firewall management