VulncastBriefing archive

Weekly Brief - 2026-09-14

· 3775 vulnerabilities · 11 min listen

▶ Listen to this briefing

CVE-2026-18922

critical · CVSS 9.8 · Red Hat 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.

  • Authentication Bypass
  • directory server

CVE-2026-75650

critical · CVSS 10 · Adobe Commerce

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

  • Remote Code Execution
  • template engine

CVE-2026-85982

critical · CVSS 9 · Auth0 AD/LDAP Connector

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could then execute in an administrator's browser when they view the affected search results or update logs.

  • Cross-Site Scripting
  • directory service
  • web application
  • ldap

CVE-2026-80172

critical · CVSS 9.8 · Dell Secure Connect Gateway

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens. Since there is no nonce validation or time limit on requests, the attack can be performed indefinitely. Dell recommends customers to upgrade at the earliest opportunity

  • Broken Authentication
  • Unauthorized Access
  • appliance

CVE-2026-85103

critical · CVSS 9.8 · Check Point Quantum Security Gateway

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

  • Buffer Overflow
  • Remote Code Execution
  • network appliance

CVE-2026-87654

critical · CVSS 9.6 · Google Chrome

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • Buffer Overflow
  • web browser

CVE-2026-87911

critical · CVSS 9.6 · Amazon postgres-mcp-server

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode. To remediate this issue, users should upgrade to version 1.1.7 or later.

  • Command Injection
  • database
  • server software

CVE-2026-81467

critical · CVSS 9.8 · Dell ThinOS

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

  • OS Command Injection
  • operating system
  • endpoint management

CVE-2026-89049

critical · CVSS 9.9 · Amazon AWS Systems Manager Agent

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address. To remediate this issue, users should upgrade to version 3.3.4851.0 or later.

  • Server-Side Request Forgery
  • cloud infrastructure
  • agent software

CVE-2026-85706

critical · CVSS 10 · GitLab CE/EE

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

  • Path Traversal
  • Broken Access Control
  • software development platform