<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Diras Labs: CVE Radar</title>
  <link>https://labs.diras.sa/cve/</link>
  <atom:link href="https://labs.diras.sa/cve/feed.xml" rel="self" type="application/rss+xml"/>
  <description>Analyst-curated feed of new and actively exploited CVEs, with a Diras take on exposure in the region.</description>
  <language>en</language>
  <lastBuildDate>Wed, 30 Sep 2026 07:46:07 GMT</lastBuildDate>
  <item>
    <title>CVE-2026-67378: Microsoft SQL Server untrusted pointer dereference leads to remote code execution (Critical 9)</title>
    <link>https://labs.diras.sa/cve/cve-2026-67378/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-67378/</guid>
    <pubDate>Wed, 30 Sep 2026 07:46:07 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated attacker can execute arbitrary code on Microsoft SQL Server instances by exploiting an untrusted pointer dereference vulnerability (CVE-2026-67378). Affected builds include Microsoft SQL Server 2019, 2022, and 2025 releases listed as earlier than the fixed builds (for example 15.0.4490.9, 16.0.4275.2, 17.0.4085.5); see vendor advisories for full affected-build ranges. The flaw can be triggered remotely over the network without valid credentials or user interaction. Diras take: Urgent: treat this as high priority because the vulnerability allows unauthenticated remote code execution over the network; apply the vendor fixes or block access to SQL Server instances until patched.</description>
  </item>
  <item>
    <title>CVE-2026-67636: Microsoft SQL Server out-of-bounds read leads to remote code execution (Critical 9)</title>
    <link>https://labs.diras.sa/cve/cve-2026-67636/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-67636/</guid>
    <pubDate>Wed, 30 Sep 2026 07:45:57 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated attacker can trigger a memory out-of-bounds read in Microsoft SQL Server and potentially execute code over a network. CVE-2026-67636 affects multiple SQL Server branches: 2019 (CU32) 15.x before 15.0.4490.9, 2019 (GDR) 15.x before 15.0.2190.7, 2022 (CU26) 16.x before 16.0.4275.2, 2022 (GDR) 16.x before 16.0.1200.5, 2025 (CU8) 17.x before 17.0.4085.5, and 2025 (GDR) 17.x 17.0.1050.2–before 17.0.1135.8; fixed builds are listed by the vendor. Exploitation requires network access but no valid credentials or user interaction. Diras take: Urgent: this flaw can be exploited without authentication, so prioritize installing the vendor fixes for your branch or immediately restrict SQL Server network exposure until you can update.</description>
  </item>
  <item>
    <title>CVE-2026-76420: Cisco Secure FMC AJP connector pre-auth remote root execution (Critical 9)</title>
    <link>https://labs.diras.sa/cve/cve-2026-76420/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-76420/</guid>
    <pubDate>Wed, 30 Sep 2026 07:45:44 GMT</pubDate>
    <category>Cisco</category>
    <description>An unauthenticated remote attacker can send crafted AJP packets to Cisco Secure Firewall Management Center (FMC) to execute commands as root and gain full control of the FMC REST APIs, tracked as CVE-2026-76420. The flaw affects multiple 7.x FMC releases including 7.0.0 through 7.0.4 and 7.2.0 / 7.2.0.1 as listed by the vendor. Exploitation requires network access to the AJP connector and only works when the sftunnel connection between FMC and Secure FTD is down; no authenticated account or user interaction is required. Diras take: Urgent: this is a remote, unauthenticated root-capable flaw with no patch available for affected 7.x releases; immediately restrict access to the AJP connector and follow the vendor&#39;s mitigation guidance.</description>
  </item>
  <item>
    <title>CVE-2026-67278: RouterOS RSA signature verification allows TLS/SSH impersonation (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-67278/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-67278/</guid>
    <pubDate>Wed, 30 Sep 2026 07:45:34 GMT</pubDate>
    <category>MikroTik</category>
    <description>An unauthenticated remote attacker can trick MikroTik RouterOS into accepting forged RSA/PKCS#1 v1.5 signatures and thereby impersonate TLS servers or undermine RSA-based SSH host-key checks. This is tracked as CVE-2026-67278. The flaw affects RouterOS 7.x releases 7.0.0 through before 7.23.6 and 7.24 up to before 7.24.3; an attacker needs the ability to control or redirect RouterOS outbound TLS connections or otherwise present malformed RSA signatures to the device. Diras take: Urgent: no authentication is required to exploit this verification bypass, so prioritize updates; MikroTik published fixes in 7.23.6 and 7.24.3. If you cannot patch immediately, restrict exposure of affected devices and monitor connections for suspicious TLS/SSH activity.</description>
  </item>
  <item>
    <title>CVE-2026-86131: WatchGuard Fireware OS BOVPN Over TLS code injection remote root execution (Critical 9.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-86131/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-86131/</guid>
    <pubDate>Wed, 30 Sep 2026 07:45:23 GMT</pubDate>
    <category>WatchGuard</category>
    <description>A remote attacker who controls a BOVPN Over TLS server can execute arbitrary commands as root on a connecting WatchGuard Fireware OS device (CVE-2026-86131). Affected releases include 2026.3 before 2026.3.2, 2025.0 before 2026.2.3, and 12.0 branches before 12.12.3 and 12.5.21. The attacker only needs the Firebox to initiate a BOVPN Over TLS connection to a malicious or compromised VPN server. Diras take: Urgent — this is a remote root code execution triggered by a malicious BOVPN Over TLS server and fixed builds are available; prioritize installing the listed fixes or block untrusted BOVPN endpoints immediately.</description>
  </item>
  <item>
    <title>CVE-2026-101891: WatchGuard AP improper access control allows unauthenticated API session (Critical 9.3)</title>
    <link>https://labs.diras.sa/cve/cve-2026-101891/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-101891/</guid>
    <pubDate>Wed, 30 Sep 2026 07:45:13 GMT</pubDate>
    <category>WatchGuard</category>
    <description>An unauthenticated attacker with network access to a WatchGuard AP can obtain a valid API session, allowing access to the device&#39;s internal API and potentially perform privileged actions. This is tracked as CVE-2026-101891. The flaw affects WatchGuard AP firmware from 1.0 up to, but not including, 3.4.8; an attacker only needs network access to the AP and does not need valid credentials or user interaction. Diras take: Urgent: this vulnerability lets an unauthenticated actor get an API session simply by reaching the AP on the network; apply the vendor fix (3.4.8) or isolate AP management interfaces immediately.</description>
  </item>
  <item>
    <title>CVE-2026-86102: WatchGuard AP OS command injection in internal API allows remote code execution (Critical 9.3)</title>
    <link>https://labs.diras.sa/cve/cve-2026-86102/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-86102/</guid>
    <pubDate>Wed, 30 Sep 2026 07:45:04 GMT</pubDate>
    <category>WatchGuard</category>
    <description>An unauthenticated attacker with network access to a WatchGuard AP can execute arbitrary shell commands on the device, resulting in remote code execution (CVE-2026-86102). The flaw affects WatchGuard AP 3.x releases from 1.0 up to but not including 3.4.8; the vendor fixed the issue in 3.4.8. An attacker only needs network reachability to the AP’s internal API service to exploit the vulnerability—no credentials or user interaction are required. Diras take: Urgent: this is a pre-auth remote command injection that lets an attacker run shell commands if they can reach the AP’s internal API; upgrade to 3.4.8 immediately or block access to the API from untrusted networks.</description>
  </item>
  <item>
    <title>CVE-2026-76969: SAP Cloud Application Programming Model unauthenticated credential disclosure (Critical 9.4)</title>
    <link>https://labs.diras.sa/cve/cve-2026-76969/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-76969/</guid>
    <pubDate>Wed, 30 Sep 2026 07:44:55 GMT</pubDate>
    <category>SAP</category>
    <description>An unauthenticated attacker can send crafted requests to SAP Cloud Application Programming Model (CAP) components and obtain sensitive credentials, then use them to modify or delete tenant data, impacting integrity and availability. CVE-2026-76969 affects CAP components including @sap/cds-mtxs versions up to 1.18.3 and CAP releases up to 2.7.6, 3.9.6, and 4.0.2. Exploitation requires network access to a vulnerable CAP deployment and no valid account or user interaction. Diras take: Urgent: this is a remote, unauthenticated flaw that can expose credentials and let attackers alter or delete tenant data; prioritize mitigation for internet-facing CAP services immediately. The highest-risk fact is that no authentication is required to trigger the issue (pre-auth access).</description>
  </item>
  <item>
    <title>CVE-2026-20212: Cisco NX-OS Silicon One integration unauthenticated remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-20212/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-20212/</guid>
    <pubDate>Wed, 30 Sep 2026 07:44:46 GMT</pubDate>
    <category>Cisco</category>
    <description>An unauthenticated remote attacker can execute code as root on Cisco NX-OS devices running the Silicon One integration by connecting to exposed TCP ports 43210 or 43211. CVE-2026-20212 affects multiple 10.x NX-OS releases, including listed builds such as 10.3(1), 10.3(2), 10.3(3), 10.4(1), 10.3(4) and several 10.3 series variants. The attacker only needs network access to those ports in the device&#39;s default Layer 3 VRF to send crafted input that may be executed or crash the S1HAL process, possibly causing a reload. Diras take: Treat this as urgent: public exploit code exists for an unauthenticated, root-impact flaw in an internet-facing component, so immediately limit access to TCP ports 43210/43211 and follow vendor guidance.</description>
  </item>
  <item>
    <title>CVE-2026-62916: Microsoft Entra authentication bypass lets unauthenticated attacker elevate privileges (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-62916/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-62916/</guid>
    <pubDate>Wed, 30 Sep 2026 07:44:37 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated attacker can bypass authentication in Microsoft Entra to elevate privileges over the network, allowing full confidentiality, integrity, and availability impact. CVE-2026-62916 is an authentication-bypass flaw (CWE-288) in Microsoft Entra; vendor guidance lists the issue but does not specify fixed versions in the published affected data. Exploitation requires network access and does not require prior valid credentials or user interaction according to the supplied analysis. Diras take: Treat this as urgent: the flaw allows privilege elevation without prior credentials, so immediately restrict network exposure to Microsoft Entra endpoints and follow Microsoft’s mitigation and patch guidance.</description>
  </item>
  <item>
    <title>CVE-2026-77092: Commvault Cloud deserialization of untrusted data privilege escalation (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-77092/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-77092/</guid>
    <pubDate>Wed, 30 Sep 2026 07:44:28 GMT</pubDate>
    <category>Commvault</category>
    <description>An unauthenticated attacker can exploit a deserialization of untrusted data flaw in Commvault Cloud to impact privilege management and gain elevated control over the affected component. CVE-2026-77092 is a CWE-502 issue affecting Commvault Cloud releases in the 11.x line: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71 and 11.36.0–11.36.122. The vulnerability requires only the ability to reach the vulnerable service; no user interaction or credentials are listed in the available facts. Diras take: Treat this as high urgency: the flaw scores 9.8 and no fixes are published for the affected 11.x releases, so immediately reduce exposure and prepare to apply vendor updates when released.</description>
  </item>
  <item>
    <title>CVE-2026-77098: Commvault Cloud SQL injection in Private Metrics Server (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-77098/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-77098/</guid>
    <pubDate>Wed, 30 Sep 2026 07:44:18 GMT</pubDate>
    <category>Commvault</category>
    <description>Remote attackers can execute SQL injection against Commvault Cloud&#39;s Private Metrics Server and potentially read or manipulate its database; see CVE-2026-77098. The report lists multiple affected 11.x release ranges: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71, and 11.36.0–11.36.122. According to the CVSS vector, exploitation can be performed over the network without authentication or user interaction, allowing high-impact confidentiality, integrity, and availability consequences. Diras take: Urgent: this is an unauthenticated, network-accessible SQL injection (no login required), which can let attackers access or alter backend data; immediately reduce exposure and prepare to apply vendor fixes or mitigations when released.</description>
  </item>
  <item>
    <title>CVE-2026-77089: Commvault Cloud Command Center pre-auth authentication bypass (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-77089/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-77089/</guid>
    <pubDate>Wed, 30 Sep 2026 07:44:06 GMT</pubDate>
    <category>Commvault</category>
    <description>An unauthenticated attacker can bypass authentication checks in the Commvault Cloud Command Center API and affect privilege management, allowing privileged actions against the product. This is tracked as CVE-2026-77089 and has a CVSS 3.1 score of 9.8. Affected releases include multiple 11.x maintenance ranges: 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19; the flaw can be triggered remotely without prior credentials or user interaction. Diras take: Treat this as urgent: the issue allows unauthenticated privilege bypass and there is no fixed release listed, so immediately reduce exposure and apply compensating controls while awaiting vendor fixes.</description>
  </item>
  <item>
    <title>CVE-2026-12745: Ivanti Neurons for ITSM pre-auth remote code execution (deserialization) (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-12745/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-12745/</guid>
    <pubDate>Wed, 30 Sep 2026 07:43:54 GMT</pubDate>
    <category>Ivanti</category>
    <description>An unauthenticated remote attacker can execute arbitrary code on Ivanti Neurons for ITSM servers via a deserialization flaw; this is tracked as CVE-2026-12745. All versions of Neurons for ITSM are listed as affected. The vulnerability requires no prior authentication or user interaction and can be triggered remotely by sending crafted data to the affected service. Diras take: Urgent: the issue affects all versions and there is currently no patch available, so prioritize reducing exposure of Neurons for ITSM to untrusted networks and applying compensating controls immediately.</description>
  </item>
  <item>
    <title>CVE-2026-12744: Neurons for ITSM deserialization remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-12744/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-12744/</guid>
    <pubDate>Wed, 30 Sep 2026 07:43:43 GMT</pubDate>
    <category>Ivanti</category>
    <description>A remote, unauthenticated attacker can execute arbitrary code on Ivanti Neurons for ITSM servers via a deserialization of untrusted data flaw tracked as CVE-2026-12744. This is a CWE-502 deserialization issue with a critical CVSS 3.1 rating indicating network access is sufficient and no privileges or user interaction are required. Vendor data lists all Neurons for ITSM versions as affected and no fixed release is provided, so attackers only need network reachability to the vulnerable service to attempt exploitation. Diras take: Urgent: prioritize mitigation because all Neurons for ITSM versions are affected and no fixed release is listed; immediately restrict exposure and apply vendor guidance while awaiting a patch.</description>
  </item>
  <item>
    <title>CVE-2026-67631: Microsoft SQL Server heap-based buffer overflow allows remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-67631/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-67631/</guid>
    <pubDate>Wed, 30 Sep 2026 07:43:27 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated attacker can execute arbitrary code on Microsoft SQL Server instances by exploiting a heap-based buffer overflow (CVE-2026-67631). The flaw affects multiple SQL Server branches: 2017, 2019, 2022 and 2025 builds before the fixed updates listed by the vendor (see fixed builds). Exploitation requires network access to the SQL Server service but does not require valid credentials or user interaction. The vulnerability is rated critical and allows full system compromise if exploited. Diras take: Treat this as urgent: the flaw permits remote code execution without authentication, so prioritize applying the vendor updates that contain the listed fixes or otherwise restrict network exposure to SQL Server immediately.</description>
  </item>
  <item>
    <title>CVE-2026-67643: Microsoft SQL Server 2022/2025 heap buffer overflow pre-auth remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-67643/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-67643/</guid>
    <pubDate>Wed, 30 Sep 2026 07:43:17 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated attacker can execute arbitrary code on Microsoft SQL Server 2022 and 2025 instances over a network. CVE-2026-67643 is a heap-based buffer overflow that affects specific 16.x and 17.x builds; affected ranges include 16.0.0.0–before 16.0.4275.2 and 16.0.0–before 16.0.1200.5 for SQL Server 2022, and 17.0.0.0–before 17.0.4085.5 and 17.0.1050.2–before 17.0.1135.8 for SQL Server 2025. An attacker only needs network access to a vulnerable SQL Server instance; no credentials or user interaction are required according to the provided advisory data. Diras take: Treat this as urgent: the flaw allows remote, unauthenticated code execution (no privileges required), so prioritize patching externally reachable SQL Server instances or apply immediate network restrictions until fixed builds are installed.</description>
  </item>
  <item>
    <title>CVE-2026-78509: Microsoft 365 Apps heap buffer overflow remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-78509/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-78509/</guid>
    <pubDate>Wed, 30 Sep 2026 07:43:06 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated attacker can execute arbitrary code on Microsoft 365 Apps for Enterprise components (notably Outlook) over a network. CVE-2026-78509 is a heap-based buffer overflow that can lead to full compromise of affected Office and Microsoft 365 client installs. Affected branches include Microsoft 365 Apps for Enterprise 16.0.1 through before 16.0.20326.20138 and multiple Office and LTSC 16.x releases listed by the vendor; the attacker requires only network access and no user interaction or credentials. Diras take: Treat this as urgent: the flaw allows unauthenticated remote code execution (no credentials required), so prioritize applying vendor fixes or isolating vulnerable clients from untrusted networks immediately.</description>
  </item>
  <item>
    <title>CVE-2026-81352: Web Media Extensions heap buffer overflow allows pre-auth remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-81352/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-81352/</guid>
    <pubDate>Wed, 30 Sep 2026 07:42:57 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated attacker can trigger a heap-based buffer overflow in Microsoft Web Media Extensions to execute arbitrary code or crash the host. CVE-2026-81352 affects Web Media Extensions versions 1.0.0.0 through 1.2.41.0; the issue is fixed in 1.2.42.0. The vulnerability is exploitable over a network and does not require user interaction or valid credentials. Diras take: Urgent: apply the available fix immediately because this is a network-accessible, pre-auth remote code execution vulnerability with a critical 9.8 CVSS score.</description>
  </item>
  <item>
    <title>CVE-2026-66302: Skype for Business Server remote code execution via file path control (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-66302/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-66302/</guid>
    <pubDate>Wed, 30 Sep 2026 07:42:46 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated remote attacker can execute arbitrary code on Skype for Business Server using crafted input that controls a file name or path, tracked as CVE-2026-66302. Affected products include Skype for Business Server 2015 CU13 (6.0.9319.0 through before 6.0.9319.885), Skype for Business Server 2019 CU8 (7.0.2046.0 through before 7.0.2046.569) and Skype for Business Server Subscription Edition CU1 (7.0.2046.0 through before 7.0.2046.879). Exploitation requires only network access; no valid account or user interaction is required. Diras take: Treat this as high priority because the flaw allows unauthenticated remote code execution against Skype for Business Server. Prioritize patching servers reachable from untrusted networks and apply vendor updates immediately.</description>
  </item>
  <item>
    <title>CVE-2026-85103: Quantum Security Gateway heap buffer overflow in certificate parsing (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-85103/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-85103/</guid>
    <pubDate>Wed, 30 Sep 2026 07:42:37 GMT</pubDate>
    <category>Check Point</category>
    <description>Remote attackers can crash or run code on Check Point Quantum Security Gateway and Quantum Security Management appliances by supplying malformed VPN certificate data that overflows a heap buffer (CVE-2026-85103). Affected releases include R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below across both Gateway and Management branches. Exploitation only requires network access to the vulnerable VPN/certificate handling service; no user authentication is needed. Diras take: Urgent: this flaw allows unauthenticated remote code execution against VPN/management interfaces, so immediately restrict exposure of those services to trusted networks.</description>
  </item>
  <item>
    <title>CVE-2026-84390: FortiMonitorOnSight source-code sensitive information disclosure (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-84390/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-84390/</guid>
    <pubDate>Wed, 30 Sep 2026 07:42:19 GMT</pubDate>
    <category>Fortinet</category>
    <description>An attacker may gain improper access to Fortinet FortiMonitorOnSight due to sensitive information included in product source code, tracked as CVE-2026-84390. The issue affects FortiMonitorOnSight versions 7.2.0 through 7.2.2 and 7.2.4 through 7.2.7. The flaw can enable improper access control decisions because sensitive data in source code may be exposed; vendor guidance and exact attack prerequisites are not specified in the available facts. Diras take: Treat this as urgent: no fix is available for the affected FortiMonitorOnSight releases, so isolate or restrict access to affected instances and monitor for updates from Fortinet until a patch is released.</description>
  </item>
  <item>
    <title>CVE-2026-20353: Cisco Secure Email pre-auth remote compromise via resource-lifetime bug (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-20353/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-20353/</guid>
    <pubDate>Wed, 30 Sep 2026 07:42:10 GMT</pubDate>
    <category>Cisco</category>
    <description>An unauthenticated remote attacker with network access to Cisco Secure Email can exploit CVE-2026-20353 to take control of the appliance. The issue is a resource lifetime management bug (CWE-664) that may allow full compromise of the product. Cisco lists multiple affected builds across 13.x, 14.x and 15.x branches, including 13.0.0-392, 13.5.1-277, 13.0.5-007, 13.5.4-038, 14.0.0-698, 14.2.0-620, 14.2.1-020, 14.3.0-032, 15.0.0-104 and 15.0.1-030. Exploitation requires only network reachability; no authentication or user interaction is needed. Diras take: Urgent: because this can be triggered without credentials and reachable services increase risk, immediately restrict external access to Cisco Secure Email and prepare to apply vendor updates when available.</description>
  </item>
  <item>
    <title>CVE-2026-76443: Cisco Secure Email remote code execution via improper neutralization (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-76443/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-76443/</guid>
    <pubDate>Wed, 30 Sep 2026 07:41:50 GMT</pubDate>
    <category>Cisco</category>
    <description>Remote attackers can execute arbitrary code on Cisco Secure Email appliances with no authentication or user interaction required; this vulnerability is tracked as CVE-2026-76443. Affected builds span Cisco Secure Email 13.x, 14.x and 15.x (examples include 13.0.0-392, 13.0.5-007, 13.5.1-277, 13.5.4-038, 14.0.0-698, 14.2.0-620, 14.2.1-020, 14.3.0-032, 15.0.0-104 and 15.0.1-030). An attacker only needs network access to vulnerable appliances to exploit this improper-neutralization flaw (CWE-707). Diras take: Urgently treat this as high priority: the flaw allows unauthenticated remote code execution and the vendor has no fixed releases listed for these builds. Immediately reduce network exposure and follow the vendor&#39;s guidance while monitoring for signs of compromise.</description>
  </item>
  <item>
    <title>CVE-2026-76441: Cisco Secure Email and Web Manager improper access control allows remote takeover (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-76441/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-76441/</guid>
    <pubDate>Wed, 30 Sep 2026 07:41:41 GMT</pubDate>
    <category>Cisco</category>
    <description>Remote, unauthenticated attackers can bypass access controls and gain complete control over Cisco Secure Email and Web Manager, tracked as CVE-2026-76441. The flaw stems from improper access control (CWE-284) and affects multiple builds across 12.x, 13.x and 14.x branches (examples include 12.8.1-002, several 13.0 and 13.6 builds, and 14.0/14.1 builds listed by Cisco). Exploitation requires only network access to the product; no user interaction or valid credentials are required according to the vulnerability data and CVSS vector. Diras take: Urgent: treat this as high priority because the flaw allows unauthenticated remote access and no fixes are listed; immediately reduce internet exposure and follow vendor advisories for mitigations.</description>
  </item>
  <item>
    <title>CVE-2026-76440: Cisco Secure Email path traversal vulnerability, unauthenticated remote impact (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-76440/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-76440/</guid>
    <pubDate>Wed, 30 Sep 2026 07:41:32 GMT</pubDate>
    <category>Cisco</category>
    <description>An unauthenticated remote attacker can exploit a path traversal flaw in Cisco Secure Email to access or overwrite files on affected appliances; this issue is tracked as CVE-2026-76440. The vendor lists multiple affected builds across Cisco Secure Email 13.x, 14.x and 15.x (for example 13.0.0-392, 13.5.1-277, 14.0.0-698, 14.2.1-020 and 15.0.1-030 among others). Exploitation requires network access to the product and does not require valid credentials or user interaction. Diras take: Treat this as urgent: the flaw is unauthenticated and remotely reachable (CVSS 9.8). Immediately reduce external exposure, follow Cisco&#39;s guidance, and prepare to apply vendor fixes as soon as they are released.</description>
  </item>
  <item>
    <title>CVE-2026-91843: Quantum Security Management stack overflow allows unauthenticated remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-91843/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-91843/</guid>
    <pubDate>Wed, 30 Sep 2026 07:41:20 GMT</pubDate>
    <category>Check Point</category>
    <description>An unauthenticated remote attacker can trigger a stack overflow in Check Point Quantum Security Management and execute arbitrary code as root. CVE-2026-91843 affects many released branches of Quantum Security Management including R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, several R81/R80.x EOS releases and other listed builds. The flaw occurs during the login process and requires only network access to the management interface; no user interaction or valid credentials are needed. Diras take: Treat this as urgent: public exploit code exists for a remotely triggerable, unauthenticated root code execution bug against an internet-facing management product. Immediately reduce exposure and follow vendor guidance.</description>
  </item>
  <item>
    <title>CVE-2026-20242: Cisco Secure Firewall Management Center insecure deserialization remote root execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-20242/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-20242/</guid>
    <pubDate>Wed, 30 Sep 2026 07:41:10 GMT</pubDate>
    <category>Cisco</category>
    <description>An unauthenticated remote attacker can execute arbitrary commands as root on Cisco Secure Firewall Management Center (FMC), tracked as CVE-2026-20242. The flaw is insecure deserialization in the External Database Access feature and affects multiple 7.x releases (examples in vendor advisory include 7.0.0 through 7.2.0.1). Exploitation requires network access to the FMC&#39;s specific TCP service and control of a host that appears in the FMC external database access list. Diras take: Urgent: this is a high-impact remote root execution with no vendor patch available; immediately reduce exposure by removing untrusted hosts from the external database access list and blocking access to the affected TCP port from untrusted networks.</description>
  </item>
  <item>
    <title>CVE-2026-20326: Cisco Nexus Dashboard missing authentication for critical functions (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-20326/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-20326/</guid>
    <pubDate>Wed, 30 Sep 2026 07:40:57 GMT</pubDate>
    <category>Cisco</category>
    <description>Unauthenticated remote attackers can access critical functions on Cisco Nexus Dashboard, enabling full compromise of affected systems. CVE-2026-20326 is a missing-authentication weakness (CWE-306) affecting multiple 2.x Nexus Dashboard releases, including builds such as 2.1(1d), 2.1(1e), 2.1(2d), 2.2(1h), 2.2(1e), 2.2(2d), 2.1(2f), 2.3(1c), 2.3(2b) and 2.3(2c). An attacker needs network access to the Nexus Dashboard instance and does not require valid credentials or user interaction to exploit the issue. Diras take: Urgent: treat systems running affected Nexus Dashboard builds as high risk because critical functions lack authentication and no fixed software is listed; immediately restrict network exposure to management interfaces and follow Cisco&#39;s guidance.</description>
  </item>
  <item>
    <title>CVE-2026-28324: SolarWinds Observability Self-Hosted unauthenticated remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-28324/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-28324/</guid>
    <pubDate>Wed, 30 Sep 2026 07:40:47 GMT</pubDate>
    <category>SolarWinds</category>
    <description>An unauthenticated attacker can run arbitrary code against SolarWinds Observability Self-Hosted installations, exploiting insufficient integrity checks; this is tracked as CVE-2026-28324. The vulnerability affects 2026.x releases before 2026.2.3 and applies to installations that are configured in non-default and non-secure ways. An attacker only needs network access to the product—no credentials or user interaction are required—to exploit the flaw. Diras take: Urgent: this is a pre-auth remote code execution with no login required, so prioritize patching exposed systems; the vendor published a fixed release (2026.2.3).</description>
  </item>
  <item>
    <title>CVE-2026-26084: FortiSandbox improper access control allows unauthenticated sensitive data access (Critical 9.9)</title>
    <link>https://labs.diras.sa/cve/cve-2026-26084/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-26084/</guid>
    <pubDate>Wed, 30 Sep 2026 07:40:38 GMT</pubDate>
    <category>Fortinet</category>
    <description>An unauthenticated remote attacker can access sensitive information on Fortinet FortiSandbox products using crafted HTTP requests; this is tracked as CVE-2026-26084. Affected releases include FortiSandbox 5.0.0–5.0.5, FortiSandbox PaaS 5.0.4–5.0.5, FortiSandbox Cloud 5.0.4–5.0.5, and FortiSandbox 4.2.1–4.2.8 and 4.4.0–4.4.8. The flaw requires only network access to the FortiSandbox HTTP interfaces and does not require valid credentials or user interaction. Diras take: Urgent: this is a pre-auth access control flaw that lets unauthenticated actors retrieve sensitive data, so immediately limit network exposure to FortiSandbox HTTP services while Fortinet releases a fix.</description>
  </item>
  <item>
    <title>CVE-2026-80098: Microsoft Copilot Studio signature verification flaw allows remote privilege escalation (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-80098/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-80098/</guid>
    <pubDate>Wed, 30 Sep 2026 07:40:28 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated network attacker can elevate privileges in Microsoft Copilot Studio due to improper verification of cryptographic signatures, tracked as CVE-2026-80098. Microsoft reports the issue affects Microsoft Copilot Studio but does not list specific fixed versions in the advisory. Exploitation requires network access and no valid credentials or user interaction, allowing remote attackers to present malformed or forged signatures to bypass integrity checks and gain higher privileges. Diras take: Urgent: this is a pre-auth remote privilege escalation (no login required), so prioritize containment and applying vendor guidance or patches as soon as they are available.</description>
  </item>
  <item>
    <title>CVE-2026-83711: Entra authorization bypass via user-controlled key (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-83711/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-83711/</guid>
    <pubDate>Wed, 30 Sep 2026 07:40:18 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated attacker can bypass authorization in Microsoft Entra and gain elevated privileges, potentially accessing or modifying tenant resources; this issue is tracked as CVE-2026-83711. The flaw is a user-controlled key authorization bypass (CWE-639) affecting Entra (vendor branch listed as Entra) with no fixed versions published in the available data. Exploitation requires network access to the affected Entra endpoint and does not require prior credentials or user interaction. Diras take: Treat this as high urgency: the flaw permits privilege elevation without credentials (pre-auth), so immediately reduce external exposure and prepare to apply vendor fixes or mitigations as they are released.</description>
  </item>
  <item>
    <title>CVE-2026-44756: SAP Extended Passport (EPP) Processing memory safety flaw allows unauthenticated remote crash (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-44756/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-44756/</guid>
    <pubDate>Wed, 30 Sep 2026 07:40:10 GMT</pubDate>
    <category>SAP</category>
    <description>An unauthenticated remote attacker can send a crafted EPP network request to SAP Extended Passport (EPP) Processing and trigger a memory-safety failure that may crash or destabilize the service and impact confidentiality, integrity, and availability. CVE-2026-44756 is a CWE-120 memory safety vulnerability that can be triggered by a malformed EPP header. Affected builds include KRNL64NUC 7.22, KRNL64UC 7.22, KERNEL 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, and 9.18–9.20; the attacker needs only network access and does not require authentication. Diras take: Urgent: this is a remote, unauthenticated flaw with a maximum CVSS score and no fixes published; immediately reduce network exposure of EPP services and follow vendor guidance to mitigate risk.</description>
  </item>
  <item>
    <title>CVE-2026-80462: Chef Automate unauthenticated privilege escalation via API gateway (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-80462/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-80462/</guid>
    <pubDate>Wed, 30 Sep 2026 07:39:59 GMT</pubDate>
    <category>Progress Software</category>
    <description>An unauthenticated attacker can gain elevated access to protected Chef Automate functionality by abusing the API gateway and identity validation path, allowing full control of impacted instances. CVE-2026-80462 affects Chef Automate 4.x releases from 4.13.516 up to but not including 4.13.520; the issue is fixed in 4.13.520. The vulnerability requires only network access to the affected service and no valid account or user interaction, and it can lead to complete confidentiality, integrity, and availability loss on vulnerable servers. Diras take: Treat this as high urgency: an unauthenticated access flaw grants elevated access and Progress published a fixed release (4.13.520). Prioritize upgrading internet-facing or broadly reachable Chef Automate instances to 4.13.520 immediately.</description>
  </item>
  <item>
    <title>CVE-2026-20130: Cisco Identity Services Engine pre-auth remote code execution (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-20130/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-20130/</guid>
    <pubDate>Wed, 30 Sep 2026 07:39:50 GMT</pubDate>
    <category>Cisco</category>
    <description>An unauthenticated network attacker can execute arbitrary code and take full control of Cisco Identity Services Engine Software; tracked as CVE-2026-20130. The flaw stems from improper neutralization of special elements (CWE-74) and affects Cisco ISE 3.1.0, 3.1.0 p1 through p6, 3.2.0 and 3.2.0 p1–p2. An attacker only needs network access to a vulnerable ISE instance; no credentials or user interaction are required. Diras take: Urgent: this is a remote, unauthenticated full‑compromise bug (CVSS 10.0) that can be triggered over the network, so immediately isolate vulnerable ISE instances from untrusted networks and apply Cisco guidance as a priority.</description>
  </item>
  <item>
    <title>CVE-2026-20192: Cisco Identity Services Engine improper access control vulnerability (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-20192/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-20192/</guid>
    <pubDate>Wed, 30 Sep 2026 07:39:41 GMT</pubDate>
    <category>Cisco</category>
    <description>An unauthenticated remote attacker can fully compromise Cisco Identity Services Engine Software, leading to complete confidentiality, integrity, and availability loss; this is tracked as CVE-2026-20192. Affected releases include 3.1.0 (and service packs p1 through p6) and 3.2.0 (including p1 and p2). The vulnerability requires only network access and does not require valid credentials or user interaction, per the published CVSS vector. Diras take: Urgent: this is a remote, unauthenticated flaw that can yield full system compromise (CVSS 10.0 with PR:N/UI:N). Immediately limit network exposure of ISE and prepare to apply vendor updates or mitigations as soon as Cisco publishes fixed software.</description>
  </item>
  <item>
    <title>CVE-2026-76423: Cisco Identity Services Engine unauthenticated admin access via REST API (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-76423/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-76423/</guid>
    <pubDate>Wed, 30 Sep 2026 07:39:12 GMT</pubDate>
    <category>Cisco</category>
    <description>Unauthenticated remote attackers can obtain full administrative control of Cisco Identity Services Engine Software under CVE-2026-76423. The flaw affects releases in the 3.x line identified as 3.1.0 (including p1–p6) and 3.2.0 (including p1–p2). The REST API endpoint does not enforce adequate authorization, so an attacker with network reach to that API port can send a specially crafted HTTP request to read and change ISE configuration and identity records with admin privileges. Diras take: Urgent: treat this as high priority because no login is required and successful attacks grant administrative control; immediately block or restrict access to the REST API and follow any Cisco guidance when published.</description>
  </item>
  <item>
    <title>CVE-2026-69843: Microsoft Fabric authentication bypass by spoofing allows privilege elevation (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-69843/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-69843/</guid>
    <pubDate>Wed, 30 Sep 2026 07:38:55 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated remote attacker can bypass authentication and elevate privileges in Microsoft Fabric, potentially gaining full control of affected instances. CVE-2026-69843 is reported as an authentication bypass (CWE-290) with a CVSS 3.1 score of 10.0. The vendor identifies the issue in the Microsoft Fabric branch; specific fixed versions are not listed in the available data. Exploitation requires network access to the product and does not require valid credentials or user interaction. Diras take: Urgent: treat this as high priority because the flaw allows unauthenticated network access to bypass authentication. Immediately follow vendor guidance and reduce external exposure while you prepare to apply updates.</description>
  </item>
  <item>
    <title>CVE-2026-75528: Broken Link Checker stored cross-site scripting via comment author URL (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-75528/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-75528/</guid>
    <pubDate>Wed, 30 Sep 2026 07:38:46 GMT</pubDate>
    <category>wpmudev</category>
    <description>Unauthenticated attackers can store and later execute arbitrary web scripts in the Broken Link Checker WordPress plugin, enabling script execution in pages viewed by administrators or other users. CVE-2026-75528 affects Broken Link Checker 2.x, specifically version 2.4.13 and earlier. The issue arises when an attacker supplies a crafted comment author URL that is stored in the plugin&#39;s link log and later triggered after an administrator performs the plugin’s dismiss-and-recheck workflow. Diras take: Urgent: this is a stored XSS that can be injected without login and there is no patch available for 2.4.13 and earlier, so immediately limit administrative exposure and avoid the plugin workflow that processes untrusted links.</description>
  </item>
  <item>
    <title>CVE-2026-77263: Iubenda plugin stored cross-site scripting via comment content (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-77263/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-77263/</guid>
    <pubDate>Wed, 30 Sep 2026 07:38:36 GMT</pubDate>
    <category>iubenda</category>
    <description>An unauthenticated attacker can inject and store malicious JavaScript in pages served by the iubenda All-in-one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin, allowing that script to run in visitors&#39; browsers. CVE-2026-77263 affects versions 3.13.4 and earlier (3.x branch). The issue is reachable via submitted comment content on sites using the plugin; an attacker only needs the ability to post a comment, no login or special privileges are required. Diras take: Treat this as high priority if your site exposes the plugin to public comments: the flaw allows unauthenticated injection of scripts and there is no vendor-fixed release listed. Immediately restrict comment submission and harden exposure while awaiting a vendor patch.</description>
  </item>
  <item>
    <title>CVE-2026-77233: Iubenda plugin stored cross-site scripting via AdSense regex rewrite (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-77233/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-77233/</guid>
    <pubDate>Wed, 30 Sep 2026 07:38:27 GMT</pubDate>
    <category>iubenda</category>
    <description>Unauthenticated attackers can inject persistent JavaScript into pages served by the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin, enabling script execution in visitors&#39; browsers (CVE-2026-77233). The flaw affects versions 3.13.4 and earlier and arises from insufficient input sanitization and output escaping in the AdSense regex rewrite handling. The issue only occurs when the plugin is running its Secondary parser engine (parser_engine=default); an attacker needs only network access and the plugin configured with that parser to exploit it. Diras take: Urgent: treat as high priority because exploitation requires no authentication and allows persistent script injection when the Secondary parser is enabled. If you expose the plugin on the public web and use the Secondary parser, mitigate immediately.</description>
  </item>
  <item>
    <title>CVE-2026-19769: Ninja Forms stored cross-site scripting via file upload (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-19769/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-19769/</guid>
    <pubDate>Wed, 30 Sep 2026 07:38:18 GMT</pubDate>
    <category>kstover</category>
    <description>Unauthenticated attackers can store and serve malicious JavaScript from WordPress sites using the Ninja Forms plugin, enabling script execution in visitors’ browsers; this issue is tracked as CVE-2026-19769. The flaw impacts Ninja Forms 3.x (versions 3.15.1 and earlier) and depends on the Ninja Forms File Uploads add-on being active. An attacker uses the add-on’s upload handling to place attacker-controlled HTML/JS into any directory the web server can write to (including the site root), so remote access to the site and the File Uploads add-on are required for exploitation. Diras take: Treat this as high priority if your public WordPress sites use the File Uploads add-on: an unauthenticated upload path can place executable files in the webroot, so disable the add-on or block write access to web-facing directories until a vendor patch is available.</description>
  </item>
  <item>
    <title>CVE-2026-18406: SureForms stored cross-site scripting vulnerability (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-18406/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-18406/</guid>
    <pubDate>Wed, 30 Sep 2026 07:38:02 GMT</pubDate>
    <category>brainstormforce</category>
    <description>An unauthenticated attacker can inject persistent JavaScript into pages served by the SureForms – Contact Form Builder, AI Forms, Payment Form, Survey &amp; Quiz WordPress plugin, enabling stored cross-site scripting (CWE-79). CVE-2026-18406 affects SureForms branch 2.x, specifically versions 2.12.2 and earlier. The flaw results from insufficient input sanitization and output escaping on text fields; an attacker only needs the ability to submit form input (no login required) and a victim to view the injected page to trigger the script. Diras take: Urgent: treat this as high priority because the flaw allows unauthenticated, persistent script injection into pages users visit. Immediately limit exposure and prepare to apply the vendor&#39;s fix when released.</description>
  </item>
  <item>
    <title>CVE-2026-77830: Spam protection, Honeypot, Anti-Spam by CleanTalk stored XSS in comments (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-77830/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-77830/</guid>
    <pubDate>Wed, 30 Sep 2026 07:37:53 GMT</pubDate>
    <category>cleantalk</category>
    <description>Malicious actors can store JavaScript inside comments on sites using the Spam protection, Honeypot, Anti-Spam by CleanTalk WordPress plugin, leading to script execution in visitors’ browsers (CVE-2026-77830). The flaw affects the 6.x line through 6.86 and stems from inadequate filtering and escaping of comment-related input. An attacker able to create or submit comments can persist a payload; unauthenticated comment submission can deliver the payload and it runs when non-logged-in visitors view the page. If comments are moderated, a published comment is required before other users see it. Diras take: High priority: public comment submission can deliver the payload and it executes for anonymous visitors, so immediately reduce exposure by disabling the plugin or enforcing strict moderation and access controls until a vendor fix exists.</description>
  </item>
  <item>
    <title>CVE-2026-78438: W3 Total Cache stored cross-site scripting via lazy load background images (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-78438/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-78438/</guid>
    <pubDate>Wed, 30 Sep 2026 07:37:36 GMT</pubDate>
    <category>boldgrid</category>
    <description>Attackers with no account access can store malicious JavaScript that later runs in visitors’ browsers on sites using the W3 Total Cache WordPress plugin. This is CVE-2026-78438. The vulnerability exists in W3 Total Cache 2.x up to and including 2.10.5. Successful exploitation requires the plugin’s lazy-load feature to be active with the option that processes background images enabled, and the attacker’s crafted comment must be accepted by a moderator so the payload is served to users. Diras take: Prioritise mitigation because there is no vendor fix for affected releases and the flaw allows unauthenticated script injection that executes for site visitors once a comment is approved.</description>
  </item>
  <item>
    <title>CVE-2026-18405: Jeg Kit for Elementor stored cross-site scripting via comments (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-18405/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-18405/</guid>
    <pubDate>Wed, 30 Sep 2026 07:37:21 GMT</pubDate>
    <category>jegtheme</category>
    <description>Unauthenticated attackers can inject persistent JavaScript into pages served by the Jeg Kit for Elementor plugin, enabling stored cross-site scripting. CVE-2026-18405 affects Jeg Kit for Elementor versions 3.x — 3.2.16 and earlier — and results from insufficient input sanitization and output escaping of comment content. Successful exploitation requires that the targeted post renders a Jeg Kit Countdown widget so the plugin&#39;s frontend script initializes and executes forged widget markup placed in a comment; network access to the site and the ability to submit comments are required. Diras take: High urgency: this is an unauthenticated stored XSS in an internet-facing WordPress plugin and there is no fixed release listed for versions up to 3.2.16, so apply mitigations immediately.</description>
  </item>
  <item>
    <title>CVE-2026-87915: Popup Maker stored cross-site scripting in values[Name] parameter (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-87915/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-87915/</guid>
    <pubDate>Wed, 30 Sep 2026 07:37:12 GMT</pubDate>
    <category>danieliser</category>
    <description>Unauthenticated attackers can inject persistent JavaScript into sites using the Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin and cause that script to run when a page with the injected content is viewed. This is tracked as CVE-2026-87915. Versions 1.24.0 and earlier of the 1.x branch are affected; the issue stems from insufficient sanitization and escaping of the values[Name] parameter, and an attacker only needs network access to submit crafted input that will be stored and later executed in a victim’s browser. Diras take: Urgent: public exploit code exists, so prioritize mitigation now; treat sites with this plugin as high risk until a vendor fix is available.</description>
  </item>
  <item>
    <title>CVE-2026-13354: Asset CleanUp: Page Speed Booster stored cross-site scripting via comments (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-13354/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-13354/</guid>
    <pubDate>Wed, 30 Sep 2026 07:37:03 GMT</pubDate>
    <category>gabelivan</category>
    <description>Unauthenticated attackers can inject persistent JavaScript into pages served by the Asset CleanUp: Page Speed Booster WordPress plugin, enabling script execution in visitors&#39; browsers (CVE-2026-13354). The flaw affects versions 1.4.0.5 and earlier on the 1.x branch and is exploitable when the plugin option combine_loaded_css is enabled; an attacker does not need an account, and injected scripts run whenever a user views an affected page. Diras take: Act urgently: this is a stored XSS that requires no login to inject and can persistently affect visitors; prioritize disabling the vulnerable feature and applying vendor guidance as soon as a fix is released.</description>
  </item>
  <item>
    <title>CVE-2026-89412: TranslatePress Stored cross-site scripting in suggestion panel (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-89412/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-89412/</guid>
    <pubDate>Wed, 30 Sep 2026 07:36:54 GMT</pubDate>
    <category>cozmoslabs</category>
    <description>Unauthenticated attackers can store and later execute arbitrary JavaScript in sites using the TranslatePress – Translate Multilingual sites with AI Translation plugin, tracked as CVE-2026-89412. The flaw affects branch 3.x, versions 3.3.5 and earlier, and arises from improper sanitization and output escaping in the Translation Memory Suggestion Panel where original text can include executable HTML. An attacker only needs network access to a site that accepts translation suggestions to inject payloads that will run when a victim loads an affected page or an administrator views the suggestion. Diras take: Urgent: this is a pre-auth stored XSS that requires no login, so attackers can seed persistent payloads remotely; mitigate exposure immediately and prioritize protective controls for admin and suggestion interfaces.</description>
  </item>
  <item>
    <title>CVE-2026-94504: Ninja Forms stored cross-site scripting in submission editor (High 7.2)</title>
    <link>https://labs.diras.sa/cve/cve-2026-94504/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-94504/</guid>
    <pubDate>Wed, 30 Sep 2026 07:36:44 GMT</pubDate>
    <category>kstover</category>
    <description>An unauthenticated attacker can store JavaScript in Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures &amp; AI Form Builder that executes when an administrator views the legacy submission editor; this is tracked as CVE-2026-94504. The vulnerability affects Ninja Forms 3.15.3 and earlier in the 3.x branch and arises from an anonymous non-RTE textarea value rendered without safe HTML encoding. An attacker only needs the ability to submit a crafted form entry and an administrator to open the attacker-controlled submission URL. Diras take: Urgent: public exploit code exists for this flaw, so restrict admin access to submission pages immediately and treat exposed sites as high priority to remediate or mitigate.</description>
  </item>
  <item>
    <title>CVE-2026-18561: Unlimited Elements For Elementor unauthenticated SQL injection (High 7.5)</title>
    <link>https://labs.diras.sa/cve/cve-2026-18561/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-18561/</guid>
    <pubDate>Wed, 30 Sep 2026 07:36:35 GMT</pubDate>
    <category>unitecms</category>
    <description>An unauthenticated attacker can run SQL injection against the Unlimited Elements For Elementor WordPress plugin, allowing database disclosure and data extraction. CVE-2026-18561 affects versions 2.0.16 and earlier in the 2.x branch. The flaw stems from unsafe handling of the addontype parameter that is incorporated into a WHERE clause without proper sanitization; no login, user interaction, or privileges are required beyond network access to a site that exposes the vulnerable plugin endpoints. Diras take: Urgent: this is a remote, unauthenticated SQL injection with no vendor fix listed for 2.0.16 and earlier, so immediately reduce exposure and monitor for suspicious database queries.</description>
  </item>
  <item>
    <title>CVE-2026-89406: Modula Image Gallery disclosure of private galleries and media (High 7.5)</title>
    <link>https://labs.diras.sa/cve/cve-2026-89406/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-89406/</guid>
    <pubDate>Wed, 30 Sep 2026 07:36:21 GMT</pubDate>
    <category>wpchill</category>
    <description>Unauthenticated attackers can retrieve metadata and original URLs for private galleries and their images in Modula Image Gallery – Photo Grid &amp; Video Gallery, CVE-2026-89406. Versions 3.0.1 and earlier on the 3.x branch are affected. The plugin emits Open Graph/Twitter meta tags for a gallery identified by a modula_gallery_id request parameter without verifying the gallery&#39;s publication status or the requester&#39;s permissions, enabling remote enumeration and direct download of private image files over the network with no user interaction or account required. Diras take: Urgent: this is a publicly reachable, unauthenticated information-disclosure bug that exposes private media; treat sites hosting Modula 3.0.1 or earlier as at immediate risk and reduce exposure until a vendor fix is available.</description>
  </item>
  <item>
    <title>CVE-2026-66047: ProfilePress unauthenticated remote code execution (High 8.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-66047/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-66047/</guid>
    <pubDate>Wed, 30 Sep 2026 07:36:12 GMT</pubDate>
    <category>Proper Fraction</category>
    <description>An unauthenticated attacker can run PHP code on a WordPress site using a vulnerability in the ProfilePress plugin (CVE-2026-66047). The issue arises from a weak 32-bit connection token handled by the plugin&#39;s ppress_connect_process AJAX endpoint, allowing an attacker to supply a crafted file URL and trigger automatic download and activation of a plugin which leads to code execution as the web server user. The flaw affects ProfilePress 4.x releases before 4.17.2. The attacker only needs network access to a site running the vulnerable plugin; no account or user interaction is required. Diras take: High urgency: this is an unauthenticated RCE that allows code execution without credentials, so immediately update internet-facing ProfilePress instances to 4.17.2.</description>
  </item>
  <item>
    <title>CVE-2025-39964: Linux Kernel AF_ALG concurrent-write race condition in af_alg_sendmsg (High 7.8)</title>
    <link>https://labs.diras.sa/cve/cve-2025-39964/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2025-39964/</guid>
    <pubDate>Wed, 30 Sep 2026 07:35:56 GMT</pubDate>
    <category>Linux</category>
    <description>Local attackers can trigger a race by performing simultaneous write operations to the same AF_ALG socket, which may cause data from separate writes to mix unpredictably and leave the socket in an inconsistent state, risking confidentiality, integrity, and availability. CVE-2025-39964 affects multiple Linux kernel branches with fixes committed for several lines (see affected[] for commit IDs); the 2.x branch entry lists version 2.6.38 without a provided fix. Exploitation requires local ability to open and write to AF_ALG sockets; no user interaction or network access is needed. Diras take: Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2026-09-18 with a remediation deadline of 2026-09-21, so prioritize applying fixes or mitigations immediately.</description>
  </item>
  <item>
    <title>CVE-2026-84324: Chrome Proxy use-after-free allows remote code execution (Critical 9)</title>
    <link>https://labs.diras.sa/cve/cve-2026-84324/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-84324/</guid>
    <pubDate>Wed, 30 Sep 2026 07:35:10 GMT</pubDate>
    <category>Google</category>
    <description>Remote attackers can execute arbitrary code in Google Chrome via a use-after-free in the Proxy component (CVE-2026-84324). The flaw impacts Chrome 152.x releases prior to 152.0.7977.75 and can be triggered by crafted network traffic; an attacker only needs network access to deliver the malicious traffic. Successful exploitation can run code outside the browser sandbox, risking confidentiality, integrity, and availability of the host running the affected Chrome version. Diras take: Urgent: this is a network-triggered, no-interaction remote code execution (no authentication and no user interaction required), so update immediately to the fixed build 152.0.7977.75 or later.</description>
  </item>
  <item>
    <title>CVE-2026-87613: Chrome incorrect reference resolution in Extensions allows remote code execution (Critical 9)</title>
    <link>https://labs.diras.sa/cve/cve-2026-87613/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-87613/</guid>
    <pubDate>Wed, 30 Sep 2026 07:35:00 GMT</pubDate>
    <category>Google</category>
    <description>A remote attacker can execute arbitrary code in Google Chrome by exploiting an incorrect reference resolution in Extensions; tracked as CVE-2026-87613. The flaw affects Chrome 153.x releases before 153.0.8010.36 and can be triggered by crafted network traffic, requiring no user interaction or privileges but network access and a successful complex request to the browser. Diras take: Urgently update Chrome to 153.0.8010.36 or later — this issue carries a critical CVSS 9.0 rating and has been fixed in that release. If immediate update is not possible, restrict network exposure to untrusted sources and monitor for anomalous browser activity.</description>
  </item>
  <item>
    <title>CVE-2026-73475: Commerce PayPal forceful browsing lets unauthenticated users access (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-73475/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-73475/</guid>
    <pubDate>Wed, 30 Sep 2026 07:34:50 GMT</pubDate>
    <category>Drupal</category>
    <description>Unauthenticated remote attackers can use forceful browsing to access or act on Commerce PayPal resources in Drupal. CVE-2026-73475 is an improper-authorization flaw that affects Commerce PayPal 1.x before 1.12.0 and 2.x from 2.0.0 before 2.1.3; an attacker only needs network access and does not require a valid account or user interaction to exploit it. Diras take: Treat this as urgent because the flaw requires no login and allows unauthenticated access; prioritize patching or mitigation immediately for any internet-facing Drupal sites running the module.</description>
  </item>
  <item>
    <title>CVE-2026-85043: Chrome network cleanup bypass allows remote system access bypass (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-85043/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-85043/</guid>
    <pubDate>Wed, 30 Sep 2026 07:34:38 GMT</pubDate>
    <category>Google</category>
    <description>A remote attacker can bypass system access restrictions in Google Chrome via crafted network traffic, affecting Chrome versions in the 152.x branch prior to 152.0.7977.82 (CVE-2026-85043). The flaw arises from incomplete cleanup in the network component and can be triggered over the network without prior authentication or user interaction. Affected installations of Chrome 152.x should be updated because an attacker only needs network access to exploit this vulnerability. Diras take: Urgent: apply the vendor fix 152.0.7977.82 immediately because this is a remotely reachable bypass that requires no authentication or user interaction.</description>
  </item>
  <item>
    <title>CVE-2026-88056: Angular Server-Side Rendering SSRF and credential disclosure (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-88056/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-88056/</guid>
    <pubDate>Wed, 30 Sep 2026 07:34:25 GMT</pubDate>
    <category>angular</category>
    <description>An attacker can cause server-side request forgery and exfiltrate server-side credentials from applications using Angular Server-Side Rendering in @angular/platform-server. CVE-2026-88056 affects multiple Angular releases: versions &lt;= 19.2.25, and the ranges &gt;= 20.0.0 and &lt; 20.3.30, &gt;= 21.0.0 and &lt; 21.2.22, and &gt;= 22.0.0 and &lt; 22.1.4. The flaw occurs when user-controlled URLs are processed after a same-origin check and can convert relative paths into attacker-controlled origins; an attacker only needs to supply a crafted resource or request URL to trigger the issue in vulnerable apps. Diras take: Urgent: vulnerable Angular SSR code can cause SSRF that discloses attached server credentials and the facts show no fixed releases listed here; immediately reduce exposure of SSR endpoints and follow vendor guidance when patches are published.</description>
  </item>
  <item>
    <title>CVE-2026-43790: MacOS kernel out-of-bounds write lets remote attacker corrupt memory or crash (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-43790/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-43790/</guid>
    <pubDate>Wed, 30 Sep 2026 07:34:12 GMT</pubDate>
    <category>Apple</category>
    <description>A remote attacker can trigger an out-of-bounds write in the macOS kernel, potentially causing unexpected system termination or corruption of kernel memory; this is tracked as CVE-2026-43790. Affected releases are macOS Golden Gate 27 before 27, macOS Tahoe 26.x before 26.7, and macOS Sequoia 15.x before 15.8. The issue requires network access and does not require authentication or user interaction according to the published CVSS vector, and a kernel memory corruption could lead to more severe impacts. Diras take: Treat this as a high-priority patch: the flaw is remotely reachable without authentication or user interaction (CVSS vector shows PR:N/UI:N), and vendor updates are available for the affected branches.</description>
  </item>
  <item>
    <title>CVE-2026-84625: IOS and iPadOS permissions issue lets an app fingerprint the user (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-84625/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-84625/</guid>
    <pubDate>Wed, 30 Sep 2026 07:34:01 GMT</pubDate>
    <category>Apple</category>
    <description>An app can fingerprint users on affected Apple platforms, allowing user-identifying data to be collected; this is tracked as CVE-2026-84625. The issue affects builds before 27 for iOS and iPadOS (also macOS, visionOS, and watchOS before 27) and was fixed in the vendor&#39;s 27 releases. An attacker needs to run or install a malicious or compromised application on the device — no network access or privileged account is required. Diras take: Urgently install the vendor updates: Apple fixed the issue in version 27 across affected platforms, so apply those updates promptly to remove the vulnerability.</description>
  </item>
  <item>
    <title>CVE-2026-86881: IOS and iPadOS certificate validation bypass (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-86881/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-86881/</guid>
    <pubDate>Wed, 30 Sep 2026 07:33:51 GMT</pubDate>
    <category>Apple</category>
    <description>An attacker who controls or has compromised an intermediate certificate authority can issue forged certificates that iOS and iPadOS may accept, allowing impersonation of services or interception of TLS connections, tracked as CVE-2026-86881. Affected releases include iOS and iPadOS before 26.7 and before 27 (fixed in 26.7 and 27), and related Apple platforms listed below; an attacker needs control of an intermediate CA to exploit this certificate validation flaw. The issue stems from improper certificate validation that permits certificates with arbitrary extended key usages. Diras take: Urgently install Apple’s updates: fixes are available for iOS/iPadOS (26.7 and 27) and other Apple platforms. Treat exposed TLS services and systems that trust external CAs as high priority because a compromised intermediate CA can enable broad impersonation.</description>
  </item>
  <item>
    <title>CVE-2026-92034: Firefox site isolation flaw allows remote code execution (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-92034/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-92034/</guid>
    <pubDate>Wed, 30 Sep 2026 07:33:32 GMT</pubDate>
    <category>Mozilla</category>
    <description>A remote attacker can execute code in affected builds of Firefox via a site isolation issue in the Graphics component (CVE-2026-92034). The vendor-supplied data here does not include a definitive list of affected releases; patch availability is currently listed as false. Exploitation requires only network access and no authentication or user interaction, according to the published CVSS vector. Diras take: Urgent: the vulnerability has a CVSS 9.1 critical rating and no patch is listed, so isolate or block exposure of Firefox instances and apply vendor guidance as soon as a fix is released.</description>
  </item>
  <item>
    <title>CVE-2026-92038: Firefox mitigation bypass in Remote Settings Client (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-92038/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-92038/</guid>
    <pubDate>Wed, 30 Sep 2026 07:33:18 GMT</pubDate>
    <category>Mozilla</category>
    <description>An unauthenticated remote attacker can bypass security mitigations in Firefox&#39;s Remote Settings Client to achieve high-impact compromise (CVE-2026-92038). The flaw is a mitigation bypass (CWE-693) that allows remote, network-based attacks without user interaction or privileges. Specific affected Firefox and Thunderbird builds are not listed in the available data; an attacker only needs network access to the product to attempt exploitation. Diras take: Urgent: this is remotely exploitable without authentication, so reduce exposure immediately and prioritize vendor updates when available.</description>
  </item>
  <item>
    <title>CVE-2026-92041: Firefox mitigation bypass in DOM networking component (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-92041/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-92041/</guid>
    <pubDate>Wed, 30 Sep 2026 07:33:02 GMT</pubDate>
    <category>Mozilla</category>
    <description>A remote attacker can bypass mitigations in Firefox&#39;s DOM networking component and impact the confidentiality and integrity of the browser and its data; this issue is tracked as CVE-2026-92041. The supplied facts do not list specific affected Firefox releases. The CVSS vector shows the issue can be exploited over the network without authentication or user interaction, so any exposed Firefox instance could be at risk until vendor guidance or a patch is applied. Diras take: Act urgently: this is a high-impact, network-exploitable vulnerability (CVSS 9.1) and no patch is listed in the provided facts—reduce exposure and follow Mozilla guidance as soon as it is published.</description>
  </item>
  <item>
    <title>CVE-2026-92051: Firefox null pointer dereference in Graphics component causes high-impact failures (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-92051/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-92051/</guid>
    <pubDate>Wed, 30 Sep 2026 07:32:33 GMT</pubDate>
    <category>Mozilla</category>
    <description>A remote, unauthenticated attacker can trigger a null pointer dereference in Mozilla Firefox&#39;s Graphics component and cause serious integrity and availability impacts (CVE-2026-92051). Mozilla addressed the underlying bug in Firefox 156 and Thunderbird 156; the vendor notes the fix in those releases. Exploitation requires only network access and no user interaction or valid account, according to the vulnerability metrics provided. Diras take: Treat this as urgent: the flaw scores critical and Mozilla has not published a broadly available patch timeline in the provided facts, so restrict exposure of affected browsers and prepare to apply vendor fixes as soon as they are released.</description>
  </item>
  <item>
    <title>CVE-2026-92050: Firefox sandbox escape via XPConnect race condition (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-92050/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-92050/</guid>
    <pubDate>Wed, 30 Sep 2026 07:32:21 GMT</pubDate>
    <category>Mozilla</category>
    <description>Remote attackers can escape Firefox&#39;s sandbox and execute high-impact code due to a race condition in the XPConnect component. CVE-2026-92050 scores 9.1 (critical) and requires no authentication or user interaction to exploit, according to the published CVSS vector. The facts provided do not list specific affected Firefox versions or fixed releases; administrators should treat all deployed Firefox installs as potentially at risk until vendor guidance or patches identify affected and fixed versions. Diras take: Urgent: CVE-2026-92050 allows remote, unauthenticated exploitation without user interaction per the CVSS vector, so prioritize reducing exposure and preparing to apply a vendor update as soon as one is released.</description>
  </item>
  <item>
    <title>CVE-2026-92057: Firefox Enterprise Policies mitigation bypass (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-92057/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-92057/</guid>
    <pubDate>Wed, 30 Sep 2026 07:32:06 GMT</pubDate>
    <category>Mozilla</category>
    <description>An attacker can bypass the Enterprise Policies component in Mozilla Firefox, undermining policy controls on affected installations; this is tracked as CVE-2026-92057. The available facts do not list specific affected Firefox versions or required attacker access, and no patch is available in the provided data. Administrators should assume enterprise policy controls could be circumvented until a vendor update is released. Diras take: Treat this as high priority: there is no patch available in the provided facts while the issue enables bypass of enterprise policy controls, so restrict exposure and monitor until Mozilla publishes a fix.</description>
  </item>
  <item>
    <title>CVE-2026-92075: Firefox mitigation bypass in Networking component (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-92075/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-92075/</guid>
    <pubDate>Wed, 30 Sep 2026 07:31:50 GMT</pubDate>
    <category>Mozilla</category>
    <description>Remote attackers can bypass networking mitigations in Mozilla Firefox, potentially allowing high-impact compromise of confidentiality and integrity; this is tracked as CVE-2026-92075. The provided data does not list specific affected Firefox versions; the vulnerability has a critical CVSS 3.1 score and requires only network access (no privileges or user interaction reported in the data). Diras take: Treat this as high priority: the flaw is remotely exploitable with no privileges or UI required and there is no patch listed in the provided data, so restrict exposure and prepare to apply vendor updates immediately when released.</description>
  </item>
  <item>
    <title>CVE-2026-92079: Firefox Widget Win32 mitigation bypass (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-92079/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-92079/</guid>
    <pubDate>Wed, 30 Sep 2026 07:31:40 GMT</pubDate>
    <category>Mozilla</category>
    <description>An unauthenticated remote attacker can bypass mitigations in Firefox&#39;s Widget: Win32 component, enabling high-impact code or control over the browser (CVE-2026-92079). The vendor has not published an affected-version list in the provided facts; the vulnerability scoring indicates it is exploitable remotely without privileges or user interaction, and no patch is available as of 2026-09-30. Diras take: Treat this as urgent: the flaw requires no authentication and allows remote impact, so immediately restrict exposure of Firefox instances and follow vendor guidance until a patch is released.</description>
  </item>
  <item>
    <title>CVE-2026-83944: Azure Logic Apps pre-auth privilege escalation via improper access control (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-83944/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-83944/</guid>
    <pubDate>Wed, 30 Sep 2026 07:31:28 GMT</pubDate>
    <category>Microsoft</category>
    <description>An unauthenticated attacker can elevate privileges on Azure Logic Apps, potentially gaining higher-level access to workflows and resources; this is tracked as CVE-2026-83944. Microsoft lists the issue as affecting the Azure Logic Apps branch but does not name specific versions; the flaw requires network access and does not require valid credentials or user interaction. A patch is available from the vendor. Diras take: Urgent: this bypass requires no authentication, so exposed Logic Apps endpoints should be treated as high risk — apply Microsoft’s update or follow vendor mitigation guidance immediately.</description>
  </item>
  <item>
    <title>CVE-2026-93765: Mongoid unsafe reflection allows unauthenticated method invocation (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-93765/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-93765/</guid>
    <pubDate>Wed, 30 Sep 2026 07:31:18 GMT</pubDate>
    <category>MongoDB</category>
    <description>An unauthenticated party can send crafted input keys that, when passed through by an embedding application, trigger unintended internal method invocation in Mongoid, potentially causing removal of stored records or application unresponsiveness. CVE-2026-93765 affects Mongoid 8.0.0–8.0.12, 8.1.0–8.1.12, 9.0.0–9.0.11 and 9.1.0. Exploitation requires an attacker-controlled input whose keys are forwarded into Mongoid by the host application; no credentials are required within Mongoid itself. Diras take: Urgent: treat this as high priority because the flaw can be triggered without authentication and no fixed release is yet listed; immediately block or validate untrusted keys forwarded into Mongoid and limit public exposure of services that accept user-supplied document data.</description>
  </item>
  <item>
    <title>CVE-2026-89282: Apache Lounge Windows insecure install directory permissions allow file modification (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-89282/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-89282/</guid>
    <pubDate>Wed, 30 Sep 2026 07:31:08 GMT</pubDate>
    <category>Apache HTTP Server Project</category>
    <description>Authenticated users can write to the default Apache Lounge Windows installation directory, allowing modification of server files and configuration on affected installs; tracked as CVE-2026-89282. The flaw affects the Apache Lounge Windows distribution before Apache 2.4.68-260920 Win64. An attacker needs an authenticated account on the host (a member of the Windows Authenticated Users group) to exploit the improper access control on the C:&#92; install directory. Diras take: Urgent: install the fixed Apache 2.4.68-260920 Win64 build or correct NTFS permissions immediately because the default C:&#92; install directory grants write access to Authenticated Users.</description>
  </item>
  <item>
    <title>CVE-2026-86350: Apache Tomcat HTTP/2 request smuggling regression (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-86350/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-86350/</guid>
    <pubDate>Wed, 30 Sep 2026 07:30:56 GMT</pubDate>
    <category>Apache Software Foundation</category>
    <description>Unauthenticated remote attackers can exploit an HTTP/2 parsing regression in Apache Tomcat to confuse how the server separates and forwards client requests, potentially allowing one client&#39;s request data to be mixed with another&#39;s and leading to high-impact request handling errors; this is tracked as CVE-2026-86350. Affected releases include Tomcat 11.0.22–11.0.25, 10.1.55–10.1.59, and 9.0.118–9.0.121. Exploitation requires only network access to a Tomcat HTTP/2 endpoint—no credentials or user interaction are needed. Diras take: Treat this as urgent: public exploit code exists and the flaw can be triggered without authentication, so immediately limit exposure and follow vendor mitigation guidance.</description>
  </item>
  <item>
    <title>CVE-2026-86246: Apache Tomcat Native insecure-default TLS options (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-86246/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-86246/</guid>
    <pubDate>Wed, 30 Sep 2026 07:30:38 GMT</pubDate>
    <category>Apache Software Foundation</category>
    <description>Remote, unauthenticated attackers can encounter insecure default TLS behavior in Apache Tomcat Native (CVE-2026-86246), which enables unsafe options by default. Affected releases include branch 2.x: 2.0.0 through 2.0.15 and branch 1.x: 1.3.0 through 1.3.8. The issue requires network access and no authentication, and it may allow attackers to weaken or bypass recommended TLS protections because several insecure options are enabled out of the box. Diras take: Treat this as high priority: the vulnerability is remotely reachable without authentication (CVSS vector AV:N/PR:N/UI:N), so immediately limit exposure of Tomcat Native instances and apply vendor guidance as available.</description>
  </item>
  <item>
    <title>CVE-2026-77987: GitHub Enterprise Server SSRF leads to remote code execution (Critical 9.3)</title>
    <link>https://labs.diras.sa/cve/cve-2026-77987/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-77987/</guid>
    <pubDate>Wed, 30 Sep 2026 07:30:20 GMT</pubDate>
    <category>GitHub</category>
    <description>Attackers can abuse an SSRF weakness in GitHub Enterprise Server to probe internal services, recover secrets by observing response timing, and then use those secrets to trigger remote code execution on the appliance; this issue is catalogued as CVE-2026-77987. Versions 3.17 through 3.22 are impacted. Successful exploitation requires network reachability to the instance; when private mode is turned off the exploit can be carried out without any account, while with private mode enabled any authenticated user can carry out the attack. Diras take: Urgent: this flaw can enable unauthenticated RCE when private mode is off, so treat systems exposed to untrusted networks as high priority for patching. Install the vendor fixes for affected 3.17–3.22 branches now or block access to the appliance until patched.</description>
  </item>
  <item>
    <title>CVE-2026-70757: Oracle WebLogic Server unauthenticated remote code execution via T3/IIOP (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-70757/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-70757/</guid>
    <pubDate>Wed, 30 Sep 2026 07:30:05 GMT</pubDate>
    <category>Oracle</category>
    <description>Unauthenticated attackers can remotely compromise Oracle WebLogic Server and gain full control; this is tracked as CVE-2026-70757. Affected releases include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The flaw can be reached over the network using the T3 or IIOP protocols and does not require valid credentials, enabling confidentiality, integrity and availability impacts consistent with a critical 9.8 CVSS rating. Diras take: Urgent: this is a remote, unauthenticated flaw that allows full server compromise, so prioritize mitigations now because the vulnerability is easily exploitable without credentials. If you cannot immediately apply vendor guidance, restrict or block T3/IIOP exposure and increase monitoring for suspicious activity.</description>
  </item>
  <item>
    <title>CVE-2026-70748: Oracle WebLogic Server unauthenticated remote takeover via T3/IIOP (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-70748/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-70748/</guid>
    <pubDate>Wed, 30 Sep 2026 07:29:56 GMT</pubDate>
    <category>Oracle</category>
    <description>An unauthenticated attacker with network access can remotely compromise Oracle WebLogic Server and achieve full takeover; the flaw is tracked as CVE-2026-70748. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The vulnerability is reachable over network protocols T3 and IIOP and requires no valid credentials or user interaction to exploit. Diras take: Urgent: this is a pre-auth remote compromise of an internet-reachable service with a CVSS 9.8 rating, so prioritize isolating and restricting T3/IIOP exposure immediately and apply vendor fixes when released.</description>
  </item>
  <item>
    <title>CVE-2026-70756: Oracle WebLogic Server unauthenticated remote takeover via T3/IIOP (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-70756/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-70756/</guid>
    <pubDate>Wed, 30 Sep 2026 07:29:47 GMT</pubDate>
    <category>Oracle</category>
    <description>An unauthenticated remote attacker can fully compromise Oracle WebLogic Server over network-accessible management protocols; this is tracked as CVE-2026-70756. Affected releases include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The flaw requires only network access to T3 or IIOP services and no valid credentials or user interaction. Successful exploitation can lead to complete takeover of the WebLogic Server, impacting confidentiality, integrity, and availability of hosted applications. Diras take: Urgent: this allows unauthenticated remote compromise via T3/IIOP, so immediately reduce exposure of WebLogic management interfaces and apply vendor guidance as soon as patches are released.</description>
  </item>
  <item>
    <title>CVE-2026-76183: Apache Tomcat authentication bypass for WebSocket endpoints (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-76183/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-76183/</guid>
    <pubDate>Wed, 30 Sep 2026 07:29:38 GMT</pubDate>
    <category>Apache Software Foundation</category>
    <description>Remote attackers can bypass authentication controls on Apache Tomcat WebSocket endpoints, allowing access to protected resources and operations; this is tracked as CVE-2026-76183. A wide range of Tomcat releases are affected: 11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, 9.0.0.M1 through 9.0.121, 8.5.0 through 8.5.100, and 7.0.43 through 7.0.109. Exploitation requires only network access to a vulnerable Tomcat instance hosting WebSocket endpoints; no credentials or user interaction are required. Diras take: Urgent: this is a pre-auth bypass affecting many common Tomcat releases, so prioritize mitigation — the bug lets unauthenticated network attackers reach protected WebSocket endpoints. Reduce internet exposure and apply vendor updates or guidance immediately.</description>
  </item>
  <item>
    <title>CVE-2026-86248: Apache Tomcat CLIENT_CERT authentication bypass (pre-auth) (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-86248/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-86248/</guid>
    <pubDate>Wed, 30 Sep 2026 07:29:27 GMT</pubDate>
    <category>Apache Software Foundation</category>
    <description>An unauthenticated network attacker can bypass CLIENT_CERT authentication in Apache Tomcat, allowing access control to fail unexpectedly (CVE-2026-86248). Affects Tomcat 11.x releases 11.0.0-M14 through 11.0.25, 10.x releases 10.1.22 through 10.1.59, and 9.x releases 9.0.92 through 9.0.121. The issue occurs in scenarios involving CLIENT_CERT processing when soft-fail is disabled and requires only network access to a vulnerable Tomcat instance; no user interaction or credentials are needed. Diras take: Treat this as high priority for internet-facing Tomcat servers because the flaw can be triggered without credentials; if you expose CLIENT_CERT-protected endpoints, immediately restrict access and follow vendor guidance.</description>
  </item>
  <item>
    <title>CVE-2026-83021: Oracle WebLogic Server unauthenticated HTTP remote takeover (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-83021/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-83021/</guid>
    <pubDate>Wed, 30 Sep 2026 07:29:15 GMT</pubDate>
    <category>Oracle</category>
    <description>An unauthenticated attacker with network access over HTTP can fully compromise Oracle WebLogic Server, leading to takeover of the server and potential impact to additional products. CVE-2026-83021 affects Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; the flaw requires only network access via HTTP and no valid credentials. The vulnerability has a CVSS 3.1 base score of 10.0 indicating complete confidentiality, integrity and availability loss on vulnerable instances. Diras take: Urgent: treat this as a high-priority mitigation because the flaw allows unauthenticated HTTP access to full server compromise and no fixes are listed for affected releases. Immediately restrict network exposure and follow Oracle’s guidance until a patch is available.</description>
  </item>
  <item>
    <title>CVE-2026-96587: Dashcam Android Application embedded cloud credentials allow full storage access (Critical 10)</title>
    <link>https://labs.diras.sa/cve/cve-2026-96587/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-96587/</guid>
    <pubDate>Wed, 30 Sep 2026 07:29:03 GMT</pubDate>
    <category>Viidure</category>
    <description>Anyone who extracts credentials baked into the Dashcam Android Application can obtain full control over the product’s cloud storage and so read, alter, or remove critical files such as firmware and application binaries. CVE-2026-96587 covers permanent plaintext cloud credentials compiled into the app. The flaw affects branch 3.x — 3.3.1.260403 and earlier — and can be exploited without logging in or convincing a user to act if an attacker can get hold of the app package or a device image containing the embedded secrets. Diras take: High priority: this is an unauthenticated, high-impact exposure because recovered plaintext credentials provide complete storage access; immediately rotate credentials and tighten storage access while awaiting a vendor fix.</description>
  </item>
  <item>
    <title>CVE-2026-92229: Forminator Forms pre-auth shortcode execution (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-92229/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-92229/</guid>
    <pubDate>Wed, 30 Sep 2026 07:28:45 GMT</pubDate>
    <category>wpmudev</category>
    <description>An unauthenticated attacker can execute arbitrary shortcodes on sites running the Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder plugin, enabling remote code paths via WordPress shortcode handling. CVE-2026-92229 affects the 1.x branch, specifically versions 1.57.2 and earlier. Exploitation requires only network access to a site hosting the vulnerable plugin and no valid account or user interaction. Diras take: Urgent: public exploit code exists, so patching or mitigations should be prioritised immediately; treat internet-facing WordPress sites with this plugin as exposed. Apply access restrictions and monitoring now and install the vendor fix as soon as it is released.</description>
  </item>
  <item>
    <title>CVE-2026-93485: WordPress DOM-based cross-site scripting vulnerability (High 7.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-93485/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-93485/</guid>
    <pubDate>Wed, 30 Sep 2026 07:28:35 GMT</pubDate>
    <category>Automattic</category>
    <description>Attackers can run JavaScript in site visitors&#39; browsers on vulnerable WordPress installs, enabling session theft, redirection, or other client-side impacts. CVE-2026-93485 is a DOM-based XSS in WordPress core that affects multiple 6.x and 7.x releases, including 7.1 before 7.1.1 and several 7.0 and 6.x ranges listed by the vendor. Exploitation requires network access to the site and user interaction (a victim visiting a crafted page or clicking a link). Diras take: Treat this as high priority: public exploit code exists for CVE-2026-93485, so sites reachable by untrusted users should be updated or mitigated immediately.</description>
  </item>
  <item>
    <title>CVE-2026-89055: Customer Reviews for WooCommerce authorization bypass deletes media (Critical 9.1)</title>
    <link>https://labs.diras.sa/cve/cve-2026-89055/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-89055/</guid>
    <pubDate>Wed, 30 Sep 2026 07:28:23 GMT</pubDate>
    <category>ivole</category>
    <description>Unauthenticated attackers can delete attachments from a WordPress site&#39;s Media Library in the Customer Reviews for WooCommerce plugin, tracked as CVE-2026-89055. Versions 5.120.0 and earlier on the 5.x branch are affected. Exploitation does not require a WordPress account; an attacker only needs access to a public review-form link that exposes the nonce used by the plugin&#39;s deletion handler. Diras take: Urgent: public exploit code is available, so immediately mitigate exposure to public review-form links and harden access to the Media Library while awaiting a vendor fix.</description>
  </item>
  <item>
    <title>CVE-2026-64703: MacOS use-after-free lets an app cause denial-of-service (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64703/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64703/</guid>
    <pubDate>Tue, 29 Sep 2026 17:57:13 GMT</pubDate>
    <category>Apple</category>
    <description>An app can trigger a use-after-free vulnerability in macOS that may cause a denial-of-service; tracked as CVE-2026-64703. The flaw affects macOS Sonoma 14.x before 14.8.8, Sequoia 15.x before 15.7.8, and Tahoe 26.x before 26.6. Exploitation requires running or convincing a user to run a malicious or specially crafted app on the targeted macOS system; no network access or elevated privileges are documented as prerequisites in the available information. Apple fixed the issue by improving memory management in the listed updates. Diras take: Apply Apple’s published updates for Sonoma 14.8.8, Sequoia 15.7.8 and Tahoe 26.6 promptly — patched builds are available and remove the vulnerability.</description>
  </item>
  <item>
    <title>CVE-2026-64695: IOS and iPadOS kernel memory corruption over network (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64695/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64695/</guid>
    <pubDate>Tue, 29 Sep 2026 17:56:46 GMT</pubDate>
    <category>Apple</category>
    <description>Remote actors can trigger kernel memory corruption or force unexpected device crashes on Apple iOS, iPadOS and supported macOS releases; this issue is tracked as CVE-2026-64695. Affected releases include iOS and iPadOS 18.x prior to 18.7.10 and several macOS branches before their listed fixes. Exploitation requires only network access and does not need an authenticated account or user interaction, so any reachable device running an affected version could be targeted remotely. Diras take: High urgency — the bug can be reached over the network without credentials, so prioritize installing the vendor updates (for example iOS/iPadOS 18.7.10) on exposed devices immediately.</description>
  </item>
  <item>
    <title>CVE-2026-64697: MacOS kernel memory corruption remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64697/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64697/</guid>
    <pubDate>Tue, 29 Sep 2026 17:56:28 GMT</pubDate>
    <category>Apple</category>
    <description>An unauthenticated remote attacker can cause kernel memory corruption and achieve remote code execution on macOS, potentially crashing the system or corrupting kernel memory. CVE-2026-64697 affects macOS Sonoma 14.x before 14.8.8, Sequoia 15.x before 15.7.8, and Tahoe 26.x before 26.6. According to the vendor fixes, exploitation requires only network access and does not require a logged-in user or additional privileges; the vulnerability was addressed by improved memory handling in the listed fixed releases. Diras take: Urgent: apply vendor updates immediately — the flaw allows unauthenticated remote kernel memory corruption and Apple published fixes for 14.8.8, 15.7.8 and 26.6. If you cannot update, restrict network exposure to macOS hosts and increase monitoring.</description>
  </item>
  <item>
    <title>CVE-2026-64704: MacOS type confusion pre-auth remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64704/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64704/</guid>
    <pubDate>Tue, 29 Sep 2026 17:56:17 GMT</pubDate>
    <category>Apple</category>
    <description>An unauthenticated attacker can execute arbitrary code on macOS via a type confusion flaw (CVE-2026-64704). Affected releases include macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6; the vulnerability requires no user interaction or login. Apple fixed the issue by improving memory handling in the listed updates. Diras take: Urgent: this is a remote, no-login-needed vulnerability with a critical CVSS rating; apply the vendor updates named below immediately to exposed systems.</description>
  </item>
  <item>
    <title>CVE-2026-64702: MacOS sandbox escape lets an app break out of its sandbox (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64702/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64702/</guid>
    <pubDate>Tue, 29 Sep 2026 17:56:04 GMT</pubDate>
    <category>Apple</category>
    <description>A malicious or vulnerable app can break out of the macOS application sandbox, allowing local code to gain broader privileges on the system; see CVE-2026-64702. The issue affects macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires an app running on the affected macOS host. Diras take: Urgently install the vendor fixes: this is a critical (CVSS 9.8) sandbox-escape bug that lets an app escalate beyond its sandbox; apply the listed macOS updates immediately.</description>
  </item>
  <item>
    <title>CVE-2026-64700: IOS and iPadOS use-after-free may let an app terminate the system (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64700/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64700/</guid>
    <pubDate>Tue, 29 Sep 2026 17:55:53 GMT</pubDate>
    <category>Apple</category>
    <description>A malicious app can cause unexpected system termination on Apple platforms; CVE-2026-64700. The issue affects iOS and iPadOS (before 18.7.10 and before 26.6) and also macOS, tvOS, visionOS and watchOS releases listed below. An attacker needs a local app running on the device (the vulnerability is triggered by an app) rather than remote network access or user interaction beyond running the app. Diras take: Urgent: install the vendor fixes because Apple has released patched builds for each affected branch (for example iOS/iPadOS 18.7.10 and 26.6). Applying those updates closes the reported use-after-free memory bug.</description>
  </item>
  <item>
    <title>CVE-2026-64694: MacOS integer overflow leads to remote code execution potential (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64694/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64694/</guid>
    <pubDate>Tue, 29 Sep 2026 17:55:40 GMT</pubDate>
    <category>Apple</category>
    <description>A remote attacker can trigger an integer overflow in macOS and cause application or system instability, potentially leading to code execution. CVE-2026-64694 affects macOS Sequoia 15.x before 15.7.8, macOS Sonoma 14.x before 14.8.8, and macOS Tahoe 26.x before 26.6. The CVSS vector shows network attackability without authentication or user interaction, so attackers reachable over the network can attempt to exploit the flaw. Diras take: Treat this as urgent: the flaw is remotely reachable without authentication (CVSS AV:N/PR:N/UI:N) and vendor fixes are available for the affected branches; apply the updates immediately to exposed systems.</description>
  </item>
  <item>
    <title>CVE-2026-64698: MacOS kernel memory bug lets local apps crash or read kernel memory (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64698/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64698/</guid>
    <pubDate>Tue, 29 Sep 2026 17:55:28 GMT</pubDate>
    <category>Apple</category>
    <description>Local applications can crash the kernel or disclose kernel memory on macOS, tracked as CVE-2026-64698. Apple resolved the vulnerability by changing kernel memory handling; affected releases are macOS Sonoma 14.x before 14.8.8, macOS Sequoia 15.x before 15.7.8, and macOS Tahoe 26.x before 26.6. Exploitation requires running a malicious or specially crafted app on the target machine—no network access is needed but code execution on the host is required to trigger the flaw. Diras take: Urgent: this is a critical kernel memory flaw — apply the vendor updates for affected macOS releases immediately to remove the attack surface.</description>
  </item>
  <item>
    <title>CVE-2026-64720: IOS and iPadOS race condition lets remote attacker crash system (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64720/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64720/</guid>
    <pubDate>Tue, 29 Sep 2026 17:55:05 GMT</pubDate>
    <category>Apple</category>
    <description>An unauthenticated remote attacker can cause unexpected system termination on Apple iOS and iPadOS (CVE-2026-64720). The issue affects iOS and iPadOS 26.x releases before 26.6 and similar builds of macOS, tvOS, and watchOS listed by Apple; it was fixed in 26.6. According to the vendor-provided details and the CVSS vector, exploitation requires no privileges and no user interaction, meaning network access to a vulnerable device is sufficient for an attack that can crash the system. Diras take: Urgent: the flaw requires no authentication or user interaction and is fixed in 26.6; apply the vendor updates promptly to remove remote crash risk.</description>
  </item>
  <item>
    <title>CVE-2026-64727: MacOS type confusion in kernel memory handling allows an app to crash system (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64727/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64727/</guid>
    <pubDate>Tue, 29 Sep 2026 17:54:56 GMT</pubDate>
    <category>Apple</category>
    <description>An attacker-controlled app can cause unexpected system termination on macOS and tvOS, tracked as CVE-2026-64727. The flaw is a type confusion in memory handling and is fixed in macOS 26.6 and tvOS 26.6; versions before 26.6 are affected. Exploitation requires the ability to run a malicious or crafted app on the target system rather than network access or authentication. Diras take: Treat this as high priority: the bug requires no privileges to trigger and is fixed in macOS 26.6 and tvOS 26.6, so apply vendor updates promptly.</description>
  </item>
  <item>
    <title>CVE-2026-64726: IOS and iPadOS memory corruption allows remote code execution (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64726/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64726/</guid>
    <pubDate>Tue, 29 Sep 2026 17:54:43 GMT</pubDate>
    <category>Apple</category>
    <description>An unauthenticated attacker can trigger memory corruption in Apple iOS and iPadOS and achieve remote code execution; this is tracked as CVE-2026-64726. The flaw affects iOS and iPadOS before 18.7.10 and before 26.6, and related Apple platforms listed below also have fixes. According to the CVSS vector the issue is exploitable over the network without privileges or user interaction, so an attacker only needs network access to a vulnerable device to attempt exploitation. Diras take: Urgent: this is a pre-auth, network-exploitable memory corruption that can lead to remote code execution; apply Apple&#39;s available updates immediately to affected devices.</description>
  </item>
  <item>
    <title>CVE-2026-64729: IOS and iPadOS use-after-free lets an app cause system termination (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64729/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64729/</guid>
    <pubDate>Tue, 29 Sep 2026 17:54:33 GMT</pubDate>
    <category>Apple</category>
    <description>A locally-run app can trigger a use-after-free vulnerability to cause unexpected system termination or potentially worse on Apple platforms; this is tracked as CVE-2026-64729. The issue affects iOS and iPadOS 26.x before 26.6 and also macOS, tvOS, visionOS and watchOS 26.x releases before 26.6. An attacker needs the ability to run a crafted app on the target device; no additional privileges or user interaction are indicated in the reported data. Diras take: Urgent: this is rated critical (CVSS 9.8) and Apple released fixes in 26.6 for all affected branches — apply the 26.6 updates promptly to remove the vulnerability.</description>
  </item>
  <item>
    <title>CVE-2026-64733: IOS and iPadOS app fingerprinting information disclosure (Critical 9.8)</title>
    <link>https://labs.diras.sa/cve/cve-2026-64733/</link>
    <guid isPermaLink="true">https://labs.diras.sa/cve/cve-2026-64733/</guid>
    <pubDate>Tue, 29 Sep 2026 17:54:19 GMT</pubDate>
    <category>Apple</category>
    <description>An attacker can fingerprint users of Apple iOS and iPadOS apps to obtain sensitive device or user-identifying data; this is tracked as CVE-2026-64733. The issue affects iOS and iPadOS 26.x releases before 26.6 (also macOS, tvOS, visionOS, and watchOS 26.x before 26.6). Exploitation requires only network access to an affected device through an app or service and does not require user interaction or an authenticated session. Diras take: Urgent: this is rated critical with network, no-auth, no-UI attack vectors (CVSS 9.8), so prioritize deploying the vendor fix 26.6 immediately for internet-facing and high-risk devices.</description>
  </item>
</channel>
</rss>
