{
  "generated": "2026-09-30T07:46:07Z",
  "count": 441,
  "source": "https://labs.diras.sa/cve/",
  "items": [
    {
      "id": "CVE-2026-67378",
      "url": "https://labs.diras.sa/cve/cve-2026-67378/",
      "title": "Microsoft SQL Server untrusted pointer dereference leads to remote code execution",
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2019 (CU 32)",
      "cwe": "CWE-822",
      "cvss": {
        "version": "3.1",
        "score": 9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00707,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SQL Server 2019 (CU 32) 15.x",
          "affected": "15.0.0.0 – before 15.0.4490.9",
          "fixed": "15.0.4490.9"
        },
        {
          "branch": "Microsoft SQL Server 2019 (GDR) 15.x",
          "affected": "15.0.0 – before 15.0.2190.7",
          "fixed": "15.0.2190.7"
        },
        {
          "branch": "Microsoft SQL Server 2022 (CU 26) 16.x",
          "affected": "16.0.0.0 – before 16.0.4275.2",
          "fixed": "16.0.4275.2"
        },
        {
          "branch": "Microsoft SQL Server 2022 (GDR) 16.x",
          "affected": "16.0.0 – before 16.0.1200.5",
          "fixed": "16.0.1200.5"
        },
        {
          "branch": "Microsoft SQL Server 2025 (CU8) 17.x",
          "affected": "17.0.0.0 – before 17.0.4085.5",
          "fixed": "17.0.4085.5"
        },
        {
          "branch": "Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.x",
          "affected": "17.0.1050.2 – before 17.0.1135.8",
          "fixed": "17.0.1135.8"
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because the vulnerability allows unauthenticated remote code execution over the network; apply the vendor fixes or block access to SQL Server instances until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-67378",
        "https://www.cve.org/CVERecord?id=CVE-2026-67378",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67378"
      ],
      "published": "2026-09-30T07:46:07Z",
      "updated": "2026-09-30T07:46:07Z"
    },
    {
      "id": "CVE-2026-67636",
      "url": "https://labs.diras.sa/cve/cve-2026-67636/",
      "title": "Microsoft SQL Server out-of-bounds read leads to remote code execution",
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2019 (CU 32)",
      "cwe": "CWE-125",
      "cvss": {
        "version": "3.1",
        "score": 9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00707,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SQL Server 2019 (CU 32) 15.x",
          "affected": "15.0.0.0 – before 15.0.4490.9",
          "fixed": "15.0.4490.9"
        },
        {
          "branch": "Microsoft SQL Server 2019 (GDR) 15.x",
          "affected": "15.0.0 – before 15.0.2190.7",
          "fixed": "15.0.2190.7"
        },
        {
          "branch": "Microsoft SQL Server 2022 (CU 26) 16.x",
          "affected": "16.0.0.0 – before 16.0.4275.2",
          "fixed": "16.0.4275.2"
        },
        {
          "branch": "Microsoft SQL Server 2022 (GDR) 16.x",
          "affected": "16.0.0 – before 16.0.1200.5",
          "fixed": "16.0.1200.5"
        },
        {
          "branch": "Microsoft SQL Server 2025 (CU8) 17.x",
          "affected": "17.0.0.0 – before 17.0.4085.5",
          "fixed": "17.0.4085.5"
        },
        {
          "branch": "Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.x",
          "affected": "17.0.1050.2 – before 17.0.1135.8",
          "fixed": "17.0.1135.8"
        }
      ],
      "dirasTake": "Urgent: this flaw can be exploited without authentication, so prioritize installing the vendor fixes for your branch or immediately restrict SQL Server network exposure until you can update.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-67636",
        "https://www.cve.org/CVERecord?id=CVE-2026-67636",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67636"
      ],
      "published": "2026-09-30T07:45:57Z",
      "updated": "2026-09-30T07:45:57Z"
    },
    {
      "id": "CVE-2026-76420",
      "url": "https://labs.diras.sa/cve/cve-2026-76420/",
      "title": "Cisco Secure FMC AJP connector pre-auth remote root execution",
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-285",
      "cvss": {
        "version": "3.1",
        "score": 9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00378,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.0.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.3",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.4",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated root-capable flaw with no patch available for affected 7.x releases; immediately restrict access to the AJP connector and follow the vendor's mitigation guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76420",
        "https://www.cve.org/CVERecord?id=CVE-2026-76420",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc2-multivulns-HXgcqRG"
      ],
      "published": "2026-09-30T07:45:44Z",
      "updated": "2026-09-30T07:45:44Z"
    },
    {
      "id": "CVE-2026-67278",
      "url": "https://labs.diras.sa/cve/cve-2026-67278/",
      "title": "RouterOS RSA signature verification allows TLS/SSH impersonation",
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-347",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00252,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.24 – before 7.24.3",
          "fixed": "7.24.3"
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – before 7.23.6",
          "fixed": "7.23.6"
        }
      ],
      "dirasTake": "Urgent: no authentication is required to exploit this verification bypass, so prioritize updates; MikroTik published fixes in 7.23.6 and 7.24.3. If you cannot patch immediately, restrict exposure of affected devices and monitor connections for suspicious TLS/SSH activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-67278",
        "https://www.cve.org/CVERecord?id=CVE-2026-67278",
        "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
        "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
        "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/",
        "https://mikrotik.com/supportsec/september-2026-vulnerability/",
        "https://forum.mikrotik.com/t/7-23-6-long-term-is-released/273139",
        "https://forum.mikrotik.com/t/7-24-3-stable-is-released/273138"
      ],
      "published": "2026-09-30T07:45:34Z",
      "updated": "2026-09-30T07:45:34Z"
    },
    {
      "id": "CVE-2026-86131",
      "url": "https://labs.diras.sa/cve/cve-2026-86131/",
      "title": "WatchGuard Fireware OS BOVPN Over TLS code injection remote root execution",
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-295",
      "cvss": {
        "version": "4.0",
        "score": 9.2,
        "severity": "critical",
        "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": null,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "2026.x",
          "affected": "2026.3 – before 2026.3.2",
          "fixed": "2026.3.2"
        },
        {
          "branch": "2026.x",
          "affected": "2025.0 – before 2026.2.3",
          "fixed": "2026.2.3"
        },
        {
          "branch": "12.x",
          "affected": "12.0 – before 12.12.3",
          "fixed": "12.12.3"
        },
        {
          "branch": "12.x",
          "affected": "12.0 – before 12.5.21",
          "fixed": "12.5.21"
        }
      ],
      "dirasTake": "Urgent — this is a remote root code execution triggered by a malicious BOVPN Over TLS server and fixed builds are available; prioritize installing the listed fixes or block untrusted BOVPN endpoints immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-86131",
        "https://www.cve.org/CVERecord?id=CVE-2026-86131",
        "https://psirt.watchguard.com/CVE-2026-86131"
      ],
      "published": "2026-09-30T07:45:23Z",
      "updated": "2026-09-30T07:45:23Z"
    },
    {
      "id": "CVE-2026-101891",
      "url": "https://labs.diras.sa/cve/cve-2026-101891/",
      "title": "WatchGuard AP improper access control allows unauthenticated API session",
      "vendor": "WatchGuard",
      "product": "WatchGuard AP",
      "cwe": "CWE-284",
      "cvss": {
        "version": "4.0",
        "score": 9.3,
        "severity": "critical",
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": 0.00273,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "3.x",
          "affected": "1.0 – before 3.4.8",
          "fixed": "3.4.8"
        }
      ],
      "dirasTake": "Urgent: this vulnerability lets an unauthenticated actor get an API session simply by reaching the AP on the network; apply the vendor fix (3.4.8) or isolate AP management interfaces immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-101891",
        "https://www.cve.org/CVERecord?id=CVE-2026-101891",
        "https://psirt.watchguard.com/CVE-2026-101891"
      ],
      "published": "2026-09-30T07:45:13Z",
      "updated": "2026-09-30T07:45:13Z"
    },
    {
      "id": "CVE-2026-86102",
      "url": "https://labs.diras.sa/cve/cve-2026-86102/",
      "title": "WatchGuard AP OS command injection in internal API allows remote code execution",
      "vendor": "WatchGuard",
      "product": "WatchGuard AP",
      "cwe": "CWE-78",
      "cvss": {
        "version": "4.0",
        "score": 9.3,
        "severity": "critical",
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": 0.01824,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "3.x",
          "affected": "1.0 – before 3.4.8",
          "fixed": "3.4.8"
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth remote command injection that lets an attacker run shell commands if they can reach the AP’s internal API; upgrade to 3.4.8 immediately or block access to the API from untrusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-86102",
        "https://www.cve.org/CVERecord?id=CVE-2026-86102",
        "https://psirt.watchguard.com/CVE-2026-86102"
      ],
      "published": "2026-09-30T07:45:04Z",
      "updated": "2026-09-30T07:45:04Z"
    },
    {
      "id": "CVE-2026-76969",
      "url": "https://labs.diras.sa/cve/cve-2026-76969/",
      "title": "SAP Cloud Application Programming Model unauthenticated credential disclosure",
      "vendor": "SAP",
      "product": "SAP Cloud Application Programming Model (CAP)",
      "cwe": "CWE-522",
      "cvss": {
        "version": "3.1",
        "score": 9.4,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
      },
      "epss": 0.00443,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "SAP Cloud Application Programming Model (CAP)",
          "affected": "@sap/cds-mtxs <=1.18.3",
          "fixed": null
        },
        {
          "branch": "SAP Cloud Application Programming Model (CAP)",
          "affected": "<=2.7.6",
          "fixed": null
        },
        {
          "branch": "SAP Cloud Application Programming Model (CAP)",
          "affected": "<=3.9.6",
          "fixed": null
        },
        {
          "branch": "SAP Cloud Application Programming Model (CAP)",
          "affected": "<=4.0.2",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated flaw that can expose credentials and let attackers alter or delete tenant data; prioritize mitigation for internet-facing CAP services immediately. The highest-risk fact is that no authentication is required to trigger the issue (pre-auth access).",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76969",
        "https://www.cve.org/CVERecord?id=CVE-2026-76969",
        "https://me.sap.com/notes/3798315",
        "https://url.sap/sapsecuritypatchday"
      ],
      "published": "2026-09-30T07:44:55Z",
      "updated": "2026-09-30T07:44:55Z"
    },
    {
      "id": "CVE-2026-20212",
      "url": "https://labs.diras.sa/cve/cve-2026-20212/",
      "title": "Cisco NX-OS Silicon One integration unauthenticated remote code execution",
      "vendor": "Cisco",
      "product": "Cisco NX-OS Software",
      "cwe": "CWE-1327",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00721,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "10.x",
          "affected": "10.3(1)",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.3(2)",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.3(3)",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.4(1)",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.3(99w)",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.3(3w)",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.3(99x)",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.3(3o)",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.3(4)",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.3(3p)",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: public exploit code exists for an unauthenticated, root-impact flaw in an internet-facing component, so immediately limit access to TCP ports 43210/43211 and follow vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20212",
        "https://www.cve.org/CVERecord?id=CVE-2026-20212",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr"
      ],
      "published": "2026-09-30T07:44:46Z",
      "updated": "2026-09-30T07:44:46Z"
    },
    {
      "id": "CVE-2026-62916",
      "url": "https://labs.diras.sa/cve/cve-2026-62916/",
      "title": "Microsoft Entra authentication bypass lets unauthenticated attacker elevate privileges",
      "vendor": "Microsoft",
      "product": "Microsoft Entra",
      "cwe": "CWE-288",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00865,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft Entra",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw allows privilege elevation without prior credentials, so immediately restrict network exposure to Microsoft Entra endpoints and follow Microsoft’s mitigation and patch guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62916",
        "https://www.cve.org/CVERecord?id=CVE-2026-62916",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62916"
      ],
      "published": "2026-09-30T07:44:37Z",
      "updated": "2026-09-30T07:44:37Z"
    },
    {
      "id": "CVE-2026-77092",
      "url": "https://labs.diras.sa/cve/cve-2026-77092/",
      "title": "Commvault Cloud deserialization of untrusted data privilege escalation",
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00323,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "11.x",
          "affected": "11.46.0 – 11.46.19",
          "fixed": null
        },
        {
          "branch": "11.x",
          "affected": "11.44.0 – 11.44.19",
          "fixed": null
        },
        {
          "branch": "11.x",
          "affected": "11.40.0 – 11.40.71",
          "fixed": null
        },
        {
          "branch": "11.x",
          "affected": "11.36.0 – 11.36.122",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high urgency: the flaw scores 9.8 and no fixes are published for the affected 11.x releases, so immediately reduce exposure and prepare to apply vendor updates when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77092",
        "https://www.cve.org/CVERecord?id=CVE-2026-77092",
        "https://documentation.commvault.com/securityadvisories/CV_2026_07_6.html"
      ],
      "published": "2026-09-30T07:44:28Z",
      "updated": "2026-09-30T07:44:28Z"
    },
    {
      "id": "CVE-2026-77098",
      "url": "https://labs.diras.sa/cve/cve-2026-77098/",
      "title": "Commvault Cloud SQL injection in Private Metrics Server",
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-89",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00468,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "11.x",
          "affected": "11.46.0 – 11.46.19",
          "fixed": null
        },
        {
          "branch": "11.x",
          "affected": "11.44.0 – 11.44.19",
          "fixed": null
        },
        {
          "branch": "11.x",
          "affected": "11.40.0 – 11.40.71",
          "fixed": null
        },
        {
          "branch": "11.x",
          "affected": "11.36.0 – 11.36.122",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is an unauthenticated, network-accessible SQL injection (no login required), which can let attackers access or alter backend data; immediately reduce exposure and prepare to apply vendor fixes or mitigations when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77098",
        "https://www.cve.org/CVERecord?id=CVE-2026-77098",
        "https://documentation.commvault.com/securityadvisories/CV_2026_08_2.html"
      ],
      "published": "2026-09-30T07:44:18Z",
      "updated": "2026-09-30T07:44:18Z"
    },
    {
      "id": "CVE-2026-77089",
      "url": "https://labs.diras.sa/cve/cve-2026-77089/",
      "title": "Commvault Cloud Command Center pre-auth authentication bypass",
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-290",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00611,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "11.x",
          "affected": "11.46.0 – 11.46.19",
          "fixed": null
        },
        {
          "branch": "11.x",
          "affected": "11.44.0 – 11.44.19",
          "fixed": null
        },
        {
          "branch": "11.x",
          "affected": "11.40.0 – 11.40.71",
          "fixed": null
        },
        {
          "branch": "11.x",
          "affected": "11.36.0 – 11.36.122",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: the issue allows unauthenticated privilege bypass and there is no fixed release listed, so immediately reduce exposure and apply compensating controls while awaiting vendor fixes.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77089",
        "https://www.cve.org/CVERecord?id=CVE-2026-77089",
        "https://documentation.commvault.com/securityadvisories/CV_2026_07_1.html"
      ],
      "published": "2026-09-30T07:44:06Z",
      "updated": "2026-09-30T07:44:06Z"
    },
    {
      "id": "CVE-2026-12745",
      "url": "https://labs.diras.sa/cve/cve-2026-12745/",
      "title": "Ivanti Neurons for ITSM pre-auth remote code execution (deserialization)",
      "vendor": "Ivanti",
      "product": "Neurons for ITSM",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.02179,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Neurons for ITSM",
          "affected": "all versions",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: the issue affects all versions and there is currently no patch available, so prioritize reducing exposure of Neurons for ITSM to untrusted networks and applying compensating controls immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-12745",
        "https://www.cve.org/CVERecord?id=CVE-2026-12745",
        "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
      ],
      "published": "2026-09-30T07:43:54Z",
      "updated": "2026-09-30T07:43:54Z"
    },
    {
      "id": "CVE-2026-12744",
      "url": "https://labs.diras.sa/cve/cve-2026-12744/",
      "title": "Neurons for ITSM deserialization remote code execution",
      "vendor": "Ivanti",
      "product": "Neurons for ITSM",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.02255,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Neurons for ITSM",
          "affected": "all versions",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: prioritize mitigation because all Neurons for ITSM versions are affected and no fixed release is listed; immediately restrict exposure and apply vendor guidance while awaiting a patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-12744",
        "https://www.cve.org/CVERecord?id=CVE-2026-12744",
        "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
      ],
      "published": "2026-09-30T07:43:43Z",
      "updated": "2026-09-30T07:43:43Z"
    },
    {
      "id": "CVE-2026-67631",
      "url": "https://labs.diras.sa/cve/cve-2026-67631/",
      "title": "Microsoft SQL Server heap-based buffer overflow allows remote code execution",
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SQL Server 2017 (CU 31) 14.x",
          "affected": "14.0.0 – before 14.0.3550.4",
          "fixed": "14.0.3550.4"
        },
        {
          "branch": "Microsoft SQL Server 2017 (GDR) 14.x",
          "affected": "14.0.0 – before 14.0.2130.4",
          "fixed": "14.0.2130.4"
        },
        {
          "branch": "Microsoft SQL Server 2019 (CU 32) 15.x",
          "affected": "15.0.0.0 – before 15.0.4490.9",
          "fixed": "15.0.4490.9"
        },
        {
          "branch": "Microsoft SQL Server 2019 (GDR) 15.x",
          "affected": "15.0.0 – before 15.0.2190.7",
          "fixed": "15.0.2190.7"
        },
        {
          "branch": "Microsoft SQL Server 2022 (CU 26) 16.x",
          "affected": "16.0.0.0 – before 16.0.4275.2",
          "fixed": "16.0.4275.2"
        },
        {
          "branch": "Microsoft SQL Server 2022 (GDR) 16.x",
          "affected": "16.0.0 – before 16.0.1200.5",
          "fixed": "16.0.1200.5"
        },
        {
          "branch": "Microsoft SQL Server 2025 (CU8) 17.x",
          "affected": "17.0.0.0 – before 17.0.4085.5",
          "fixed": "17.0.4085.5"
        },
        {
          "branch": "Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.x",
          "affected": "17.0.1050.2 – before 17.0.1135.8",
          "fixed": "17.0.1135.8"
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw permits remote code execution without authentication, so prioritize applying the vendor updates that contain the listed fixes or otherwise restrict network exposure to SQL Server immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-67631",
        "https://www.cve.org/CVERecord?id=CVE-2026-67631",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67631"
      ],
      "published": "2026-09-30T07:43:27Z",
      "updated": "2026-09-30T07:43:27Z"
    },
    {
      "id": "CVE-2026-67643",
      "url": "https://labs.diras.sa/cve/cve-2026-67643/",
      "title": "Microsoft SQL Server 2022/2025 heap buffer overflow pre-auth remote code execution",
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2022 (CU 26)",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SQL Server 2022 (CU 26) 16.x",
          "affected": "16.0.0.0 – before 16.0.4275.2",
          "fixed": "16.0.4275.2"
        },
        {
          "branch": "Microsoft SQL Server 2022 (GDR) 16.x",
          "affected": "16.0.0 – before 16.0.1200.5",
          "fixed": "16.0.1200.5"
        },
        {
          "branch": "Microsoft SQL Server 2025 (CU8) 17.x",
          "affected": "17.0.0.0 – before 17.0.4085.5",
          "fixed": "17.0.4085.5"
        },
        {
          "branch": "Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.x",
          "affected": "17.0.1050.2 – before 17.0.1135.8",
          "fixed": "17.0.1135.8"
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw allows remote, unauthenticated code execution (no privileges required), so prioritize patching externally reachable SQL Server instances or apply immediate network restrictions until fixed builds are installed.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-67643",
        "https://www.cve.org/CVERecord?id=CVE-2026-67643",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67643"
      ],
      "published": "2026-09-30T07:43:17Z",
      "updated": "2026-09-30T07:43:17Z"
    },
    {
      "id": "CVE-2026-78509",
      "url": "https://labs.diras.sa/cve/cve-2026-78509/",
      "title": "Microsoft 365 Apps heap buffer overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft 365 Apps for Enterprise 16.x",
          "affected": "16.0.1 – before 16.0.20326.20138",
          "fixed": "16.0.20326.20138"
        },
        {
          "branch": "Microsoft Office 2019 16.x",
          "affected": "19.0.0 – before 16.0.10417.20207",
          "fixed": "16.0.10417.20207"
        },
        {
          "branch": "Microsoft Office 365 for Mac 16.x",
          "affected": "1.0.0 – before 16.113.26091433",
          "fixed": "16.113.26091433"
        },
        {
          "branch": "Microsoft Office LTSC 2021 16.x",
          "affected": "16.0.1 – before 16.0.14334.20906",
          "fixed": "16.0.14334.20906"
        },
        {
          "branch": "Microsoft Office LTSC 2024 16.x",
          "affected": "16.0.0 – before 16.0.17932.20976",
          "fixed": "16.0.17932.20976"
        },
        {
          "branch": "Microsoft Office LTSC for Mac 2021 16.x",
          "affected": "16.0.1 – before 16.113.26091433",
          "fixed": "16.113.26091433"
        },
        {
          "branch": "Microsoft Office LTSC for Mac 2024 16.x",
          "affected": "16.0.0 – before 16.113.26091433",
          "fixed": "16.113.26091433"
        },
        {
          "branch": "Microsoft Word 2016 16.x",
          "affected": "16.0.1 – before 16.0.5569.1000",
          "fixed": "16.0.5569.1000"
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw allows unauthenticated remote code execution (no credentials required), so prioritize applying vendor fixes or isolating vulnerable clients from untrusted networks immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-78509",
        "https://www.cve.org/CVERecord?id=CVE-2026-78509",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78509"
      ],
      "published": "2026-09-30T07:43:06Z",
      "updated": "2026-09-30T07:43:06Z"
    },
    {
      "id": "CVE-2026-81352",
      "url": "https://labs.diras.sa/cve/cve-2026-81352/",
      "title": "Web Media Extensions heap buffer overflow allows pre-auth remote code execution",
      "vendor": "Microsoft",
      "product": "Web Media Extensions",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0048,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0.0 – before 1.2.42.0",
          "fixed": "1.2.42.0"
        }
      ],
      "dirasTake": "Urgent: apply the available fix immediately because this is a network-accessible, pre-auth remote code execution vulnerability with a critical 9.8 CVSS score.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-81352",
        "https://www.cve.org/CVERecord?id=CVE-2026-81352",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81352"
      ],
      "published": "2026-09-30T07:42:57Z",
      "updated": "2026-09-30T07:42:57Z"
    },
    {
      "id": "CVE-2026-66302",
      "url": "https://labs.diras.sa/cve/cve-2026-66302/",
      "title": "Skype for Business Server remote code execution via file path control",
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-73",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Skype for Business Server 2015 CU13 6.x",
          "affected": "9319.0 – before 6.0.9319.885",
          "fixed": "6.0.9319.885"
        },
        {
          "branch": "Skype for Business Server 2019 CU8 7.x",
          "affected": "2046.0 – before 7.0.2046.569",
          "fixed": "7.0.2046.569"
        },
        {
          "branch": "Skype for Business Server Subscription Edition CU1 7.x",
          "affected": "2046.0 – before 7.0.2046.879",
          "fixed": "7.0.2046.879"
        }
      ],
      "dirasTake": "Treat this as high priority because the flaw allows unauthenticated remote code execution against Skype for Business Server. Prioritize patching servers reachable from untrusted networks and apply vendor updates immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-66302",
        "https://www.cve.org/CVERecord?id=CVE-2026-66302",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66302"
      ],
      "published": "2026-09-30T07:42:46Z",
      "updated": "2026-09-30T07:42:46Z"
    },
    {
      "id": "CVE-2026-85103",
      "url": "https://labs.diras.sa/cve/cve-2026-85103/",
      "title": "Quantum Security Gateway heap buffer overflow in certificate parsing",
      "vendor": "Check Point",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.03652,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Quantum Security Gateway",
          "affected": "R82.10 with Jumbo Hotfix Take 43 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Gateway",
          "affected": "R82 with Jumbo Hotfix Take 125 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Gateway",
          "affected": "R81.20 with Jumbo Hotfix Take 165 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R82.10 with Jumbo Hotfix Take 43 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R82 with Jumbo Hotfix Take 125 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R81.20 with Jumbo Hotfix Take 165 or below",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this flaw allows unauthenticated remote code execution against VPN/management interfaces, so immediately restrict exposure of those services to trusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85103",
        "https://www.cve.org/CVERecord?id=CVE-2026-85103",
        "https://support.checkpoint.com/results/sk/sk1000118"
      ],
      "published": "2026-09-30T07:42:37Z",
      "updated": "2026-09-30T07:42:37Z"
    },
    {
      "id": "CVE-2026-84390",
      "url": "https://labs.diras.sa/cve/cve-2026-84390/",
      "title": "FortiMonitorOnSight source-code sensitive information disclosure",
      "vendor": "Fortinet",
      "product": "FortiMonitorOnSight",
      "cwe": "CWE-540",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00522,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.2.4 – 7.2.7",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0 – 7.2.2",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: no fix is available for the affected FortiMonitorOnSight releases, so isolate or restrict access to affected instances and monitor for updates from Fortinet until a patch is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84390",
        "https://www.cve.org/CVERecord?id=CVE-2026-84390",
        "https://fortiguard.fortinet.com/psirt/FG-IR-26-170"
      ],
      "published": "2026-09-30T07:42:19Z",
      "updated": "2026-09-30T07:42:19Z"
    },
    {
      "id": "CVE-2026-20353",
      "url": "https://labs.diras.sa/cve/cve-2026-20353/",
      "title": "Cisco Secure Email pre-auth remote compromise via resource-lifetime bug",
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-664",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00396,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "14.x",
          "affected": "14.0.0-698",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.5.1-277",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.0.0-392",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.2.0-620",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.0.5-007",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.5.4-038",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.2.1-020",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.3.0-032",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15.0.0-104",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15.0.1-030",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: because this can be triggered without credentials and reachable services increase risk, immediately restrict external access to Cisco Secure Email and prepare to apply vendor updates when available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20353",
        "https://www.cve.org/CVERecord?id=CVE-2026-20353",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
      ],
      "published": "2026-09-30T07:42:10Z",
      "updated": "2026-09-30T07:42:10Z"
    },
    {
      "id": "CVE-2026-76443",
      "url": "https://labs.diras.sa/cve/cve-2026-76443/",
      "title": "Cisco Secure Email remote code execution via improper neutralization",
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-707",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0053,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Cisco Secure Email 14.x",
          "affected": "14.0.0-698",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 13.x",
          "affected": "13.5.1-277",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 13.x",
          "affected": "13.0.0-392",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 14.x",
          "affected": "14.2.0-620",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 13.x",
          "affected": "13.0.5-007",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 13.x",
          "affected": "13.5.4-038",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 14.x",
          "affected": "14.2.1-020",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 14.x",
          "affected": "14.3.0-032",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 15.x",
          "affected": "15.0.0-104",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 15.x",
          "affected": "15.0.1-030",
          "fixed": null
        }
      ],
      "dirasTake": "Urgently treat this as high priority: the flaw allows unauthenticated remote code execution and the vendor has no fixed releases listed for these builds. Immediately reduce network exposure and follow the vendor's guidance while monitoring for signs of compromise.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76443",
        "https://www.cve.org/CVERecord?id=CVE-2026-76443",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
      ],
      "published": "2026-09-30T07:41:50Z",
      "updated": "2026-09-30T07:41:50Z"
    },
    {
      "id": "CVE-2026-76441",
      "url": "https://labs.diras.sa/cve/cve-2026-76441/",
      "title": "Cisco Secure Email and Web Manager improper access control allows remote takeover",
      "vendor": "Cisco",
      "product": "Cisco Secure Email and Web Manager",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00533,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "13.x",
          "affected": "13.6.2-023",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.6.2-078",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.0.0-249",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.0.0-277",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.8.1-052",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.8.1-068",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.8.1-074",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.0.0-404",
          "fixed": null
        },
        {
          "branch": "12.x",
          "affected": "12.8.1-002",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.1.0-227",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because the flaw allows unauthenticated remote access and no fixes are listed; immediately reduce internet exposure and follow vendor advisories for mitigations.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76441",
        "https://www.cve.org/CVERecord?id=CVE-2026-76441",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
      ],
      "published": "2026-09-30T07:41:41Z",
      "updated": "2026-09-30T07:41:41Z"
    },
    {
      "id": "CVE-2026-76440",
      "url": "https://labs.diras.sa/cve/cve-2026-76440/",
      "title": "Cisco Secure Email path traversal vulnerability, unauthenticated remote impact",
      "vendor": "Cisco",
      "product": "Cisco Secure Email",
      "cwe": "CWE-23",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00623,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Cisco Secure Email 14.x",
          "affected": "14.0.0-698",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 13.x",
          "affected": "13.5.1-277",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 13.x",
          "affected": "13.0.0-392",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 14.x",
          "affected": "14.2.0-620",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 13.x",
          "affected": "13.0.5-007",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 13.x",
          "affected": "13.5.4-038",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 14.x",
          "affected": "14.2.1-020",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 14.x",
          "affected": "14.3.0-032",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 15.x",
          "affected": "15.0.0-104",
          "fixed": null
        },
        {
          "branch": "Cisco Secure Email 15.x",
          "affected": "15.0.1-030",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw is unauthenticated and remotely reachable (CVSS 9.8). Immediately reduce external exposure, follow Cisco's guidance, and prepare to apply vendor fixes as soon as they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76440",
        "https://www.cve.org/CVERecord?id=CVE-2026-76440",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
      ],
      "published": "2026-09-30T07:41:32Z",
      "updated": "2026-09-30T07:41:32Z"
    },
    {
      "id": "CVE-2026-91843",
      "url": "https://labs.diras.sa/cve/cve-2026-91843/",
      "title": "Quantum Security Management stack overflow allows unauthenticated remote code execution",
      "vendor": "Check Point",
      "product": "Quantum Security Management",
      "cwe": "CWE-121",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00519,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "Quantum Security Management",
          "affected": "R82.10 with Jumbo Hotfix Take 44 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R82 with Jumbo Hotfix Take 126 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R81.20 with Jumbo Hotfix Take 166 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R81.10 (EOS) with Jumbo Hotfix Take 190 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R81 (EOS)",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R80.40 (EOS)",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R80.30 (EOS)",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R80.20 (EOS)",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R80.10 (EOS)",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R80 (EOS)",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: public exploit code exists for a remotely triggerable, unauthenticated root code execution bug against an internet-facing management product. Immediately reduce exposure and follow vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-91843",
        "https://www.cve.org/CVERecord?id=CVE-2026-91843",
        "https://support.checkpoint.com/results/sk/sk1000155"
      ],
      "published": "2026-09-30T07:41:20Z",
      "updated": "2026-09-30T07:41:20Z"
    },
    {
      "id": "CVE-2026-20242",
      "url": "https://labs.diras.sa/cve/cve-2026-20242/",
      "title": "Cisco Secure Firewall Management Center insecure deserialization remote root execution",
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00639,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.0.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.3",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.4",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a high-impact remote root execution with no vendor patch available; immediately reduce exposure by removing untrusted hosts from the external database access list and blocking access to the affected TCP port from untrusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20242",
        "https://www.cve.org/CVERecord?id=CVE-2026-20242",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk"
      ],
      "published": "2026-09-30T07:41:10Z",
      "updated": "2026-09-30T07:41:10Z"
    },
    {
      "id": "CVE-2026-20326",
      "url": "https://labs.diras.sa/cve/cve-2026-20326/",
      "title": "Cisco Nexus Dashboard missing authentication for critical functions",
      "vendor": "Cisco",
      "product": "Cisco Nexus Dashboard",
      "cwe": "CWE-306",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00387,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.1(1d)",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.1(1e)",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.1(2d)",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.2(1h)",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.2(1e)",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.2(2d)",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.1(2f)",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.3(1c)",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.3(2b)",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.3(2c)",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat systems running affected Nexus Dashboard builds as high risk because critical functions lack authentication and no fixed software is listed; immediately restrict network exposure to management interfaces and follow Cisco's guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20326",
        "https://www.cve.org/CVERecord?id=CVE-2026-20326",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg"
      ],
      "published": "2026-09-30T07:40:57Z",
      "updated": "2026-09-30T07:40:57Z"
    },
    {
      "id": "CVE-2026-28324",
      "url": "https://labs.diras.sa/cve/cve-2026-28324/",
      "title": "SolarWinds Observability Self-Hosted unauthenticated remote code execution",
      "vendor": "SolarWinds",
      "product": "Observability Self-Hosted",
      "cwe": "CWE-345",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00654,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "2026.x",
          "affected": "before 2026.2.3",
          "fixed": "2026.2.3"
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth remote code execution with no login required, so prioritize patching exposed systems; the vendor published a fixed release (2026.2.3).",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-28324",
        "https://www.cve.org/CVERecord?id=CVE-2026-28324",
        "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm",
        "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28324",
        "https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm",
        "https://documentation.solarwinds.com/en/success_center/wpm/content/orionwpmagaddingalocation.htm"
      ],
      "published": "2026-09-30T07:40:47Z",
      "updated": "2026-09-30T07:40:47Z"
    },
    {
      "id": "CVE-2026-26084",
      "url": "https://labs.diras.sa/cve/cve-2026-26084/",
      "title": "FortiSandbox improper access control allows unauthenticated sensitive data access",
      "vendor": "Fortinet",
      "product": "FortiSandbox PaaS",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 9.9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H"
      },
      "epss": 0.0039,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "FortiSandbox PaaS 5.x",
          "affected": "5.0.4 – 5.0.5",
          "fixed": null
        },
        {
          "branch": "FortiSandbox 5.x",
          "affected": "5.0.0 – 5.0.5",
          "fixed": null
        },
        {
          "branch": "FortiSandbox 4.x",
          "affected": "4.4.0 – 4.4.8",
          "fixed": null
        },
        {
          "branch": "FortiSandbox 4.x",
          "affected": "4.2.1 – 4.2.8",
          "fixed": null
        },
        {
          "branch": "FortiSandbox Cloud 5.x",
          "affected": "5.0.4 – 5.0.5",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth access control flaw that lets unauthenticated actors retrieve sensitive data, so immediately limit network exposure to FortiSandbox HTTP services while Fortinet releases a fix.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-26084",
        "https://www.cve.org/CVERecord?id=CVE-2026-26084",
        "https://fortiguard.fortinet.com/psirt/FG-IR-26-166"
      ],
      "published": "2026-09-30T07:40:38Z",
      "updated": "2026-09-30T07:40:38Z"
    },
    {
      "id": "CVE-2026-80098",
      "url": "https://labs.diras.sa/cve/cve-2026-80098/",
      "title": "Microsoft Copilot Studio signature verification flaw allows remote privilege escalation",
      "vendor": "Microsoft",
      "product": "Microsoft Copilot Studio",
      "cwe": "CWE-347",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00488,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft Copilot Studio",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth remote privilege escalation (no login required), so prioritize containment and applying vendor guidance or patches as soon as they are available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-80098",
        "https://www.cve.org/CVERecord?id=CVE-2026-80098",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80098"
      ],
      "published": "2026-09-30T07:40:28Z",
      "updated": "2026-09-30T07:40:28Z"
    },
    {
      "id": "CVE-2026-83711",
      "url": "https://labs.diras.sa/cve/cve-2026-83711/",
      "title": "Entra authorization bypass via user-controlled key",
      "vendor": "Microsoft",
      "product": "Entra",
      "cwe": "CWE-639",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00815,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Entra",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high urgency: the flaw permits privilege elevation without credentials (pre-auth), so immediately reduce external exposure and prepare to apply vendor fixes or mitigations as they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-83711",
        "https://www.cve.org/CVERecord?id=CVE-2026-83711",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83711"
      ],
      "published": "2026-09-30T07:40:18Z",
      "updated": "2026-09-30T07:40:18Z"
    },
    {
      "id": "CVE-2026-44756",
      "url": "https://labs.diras.sa/cve/cve-2026-44756/",
      "title": "SAP Extended Passport (EPP) Processing memory safety flaw allows unauthenticated remote crash",
      "vendor": "SAP",
      "product": "SAP Extended Passport (EPP) Processing",
      "cwe": "CWE-120",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00678,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "SAP Extended Passport (EPP) Processing",
          "affected": "KRNL64NUC 7.22",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.22EXT",
          "fixed": null
        },
        {
          "branch": "SAP Extended Passport (EPP) Processing",
          "affected": "KRNL64UC 7.22",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.53",
          "fixed": null
        },
        {
          "branch": "8.x",
          "affected": "8.04",
          "fixed": null
        },
        {
          "branch": "SAP Extended Passport (EPP) Processing",
          "affected": "WEBDISP 9.16",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.18",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.19",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.20",
          "fixed": null
        },
        {
          "branch": "SAP Extended Passport (EPP) Processing",
          "affected": "KERNEL 7.22",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated flaw with a maximum CVSS score and no fixes published; immediately reduce network exposure of EPP services and follow vendor guidance to mitigate risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-44756",
        "https://www.cve.org/CVERecord?id=CVE-2026-44756",
        "https://me.sap.com/notes/3747649",
        "https://url.sap/sapsecuritypatchday"
      ],
      "published": "2026-09-30T07:40:10Z",
      "updated": "2026-09-30T07:40:10Z"
    },
    {
      "id": "CVE-2026-80462",
      "url": "https://labs.diras.sa/cve/cve-2026-80462/",
      "title": "Chef Automate unauthenticated privilege escalation via API gateway",
      "vendor": "Progress Software",
      "product": "Chef Automate",
      "cwe": "CWE-306",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00483,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "4.x",
          "affected": "4.13.516 – before 4.13.520",
          "fixed": "4.13.520"
        }
      ],
      "dirasTake": "Treat this as high urgency: an unauthenticated access flaw grants elevated access and Progress published a fixed release (4.13.520). Prioritize upgrading internet-facing or broadly reachable Chef Automate instances to 4.13.520 immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-80462",
        "https://www.cve.org/CVERecord?id=CVE-2026-80462",
        "https://community.progress.com/s/article/Critical-Security-Bulletin---August-2026---Chef-Automate-Security-Vulnerability"
      ],
      "published": "2026-09-30T07:39:59Z",
      "updated": "2026-09-30T07:39:59Z"
    },
    {
      "id": "CVE-2026-20130",
      "url": "https://labs.diras.sa/cve/cve-2026-20130/",
      "title": "Cisco Identity Services Engine pre-auth remote code execution",
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-74",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00395,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p1",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p3",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p2",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p4",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p5",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0 p1",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p6",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0 p2",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated full‑compromise bug (CVSS 10.0) that can be triggered over the network, so immediately isolate vulnerable ISE instances from untrusted networks and apply Cisco guidance as a priority.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20130",
        "https://www.cve.org/CVERecord?id=CVE-2026-20130",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T"
      ],
      "published": "2026-09-30T07:39:50Z",
      "updated": "2026-09-30T07:39:50Z"
    },
    {
      "id": "CVE-2026-20192",
      "url": "https://labs.diras.sa/cve/cve-2026-20192/",
      "title": "Cisco Identity Services Engine improper access control vulnerability",
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00458,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p1",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p3",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p2",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p4",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p5",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0 p1",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p6",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0 p2",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated flaw that can yield full system compromise (CVSS 10.0 with PR:N/UI:N). Immediately limit network exposure of ISE and prepare to apply vendor updates or mitigations as soon as Cisco publishes fixed software.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20192",
        "https://www.cve.org/CVERecord?id=CVE-2026-20192",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T"
      ],
      "published": "2026-09-30T07:39:41Z",
      "updated": "2026-09-30T07:39:41Z"
    },
    {
      "id": "CVE-2026-76423",
      "url": "https://labs.diras.sa/cve/cve-2026-76423/",
      "title": "Cisco Identity Services Engine unauthenticated admin access via REST API",
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-290",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
      },
      "epss": 0.00583,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p1",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p3",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p2",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p4",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p5",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0 p1",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p6",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0 p2",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because no login is required and successful attacks grant administrative control; immediately block or restrict access to the REST API and follow any Cisco guidance when published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76423",
        "https://www.cve.org/CVERecord?id=CVE-2026-76423",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ"
      ],
      "published": "2026-09-30T07:39:12Z",
      "updated": "2026-09-30T07:39:12Z"
    },
    {
      "id": "CVE-2026-69843",
      "url": "https://labs.diras.sa/cve/cve-2026-69843/",
      "title": "Microsoft Fabric authentication bypass by spoofing allows privilege elevation",
      "vendor": "Microsoft",
      "product": "Microsoft Fabric",
      "cwe": "CWE-290",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00901,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft Fabric",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because the flaw allows unauthenticated network access to bypass authentication. Immediately follow vendor guidance and reduce external exposure while you prepare to apply updates.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69843",
        "https://www.cve.org/CVERecord?id=CVE-2026-69843",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69843"
      ],
      "published": "2026-09-30T07:38:55Z",
      "updated": "2026-09-30T07:38:55Z"
    },
    {
      "id": "CVE-2026-75528",
      "url": "https://labs.diras.sa/cve/cve-2026-75528/",
      "title": "Broken Link Checker stored cross-site scripting via comment author URL",
      "vendor": "wpmudev",
      "product": "Broken Link Checker",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00527,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.4.13 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a stored XSS that can be injected without login and there is no patch available for 2.4.13 and earlier, so immediately limit administrative exposure and avoid the plugin workflow that processes untrusted links.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-75528",
        "https://www.cve.org/CVERecord?id=CVE-2026-75528",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/ec96308f-3944-48c5-94be-b1555c0830b7?source=cve",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/includes/admin/table-printer.php#L658",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/includes/links.php#L485",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/modules/checkers/http.php#L291",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/modules/checkers/http.php#L432",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/modules/containers/comment.php#L228",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/includes/admin/table-printer.php#L658",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/includes/links.php#L485",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/modules/checkers/http.php#L291",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/modules/checkers/http.php#L432",
        "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/modules/containers/comment.php#L228",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3662785%40broken-link-checker%2Ftags%2F2.4.13.1&old=3644192%40broken-link-checker%2Ftags%2F2.4.13",
        "https://plugins.trac.wordpress.org/changeset?old_path=%2Fbroken-link-checker/tags/2.4.13&new_path=%2Fbroken-link-checker/tags/2.4.13.1"
      ],
      "published": "2026-09-30T07:38:46Z",
      "updated": "2026-09-30T07:38:46Z"
    },
    {
      "id": "CVE-2026-77263",
      "url": "https://labs.diras.sa/cve/cve-2026-77263/",
      "title": "Iubenda plugin stored cross-site scripting via comment content",
      "vendor": "iubenda",
      "product": "iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00428,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.13.4 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority if your site exposes the plugin to public comments: the flaw allows unauthenticated injection of scripts and there is no vendor-fixed release listed. Immediately restrict comment submission and harden exposure while awaiting a vendor patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77263",
        "https://www.cve.org/CVERecord?id=CVE-2026-77263",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/f8d18aaa-c8f4-4688-841d-2a77b71b60b0?source=cve",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php#L941",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php#L381",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda_cookie_solution.php#L857",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda_cookie_solution.php#L834",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3675630%40iubenda-cookie-law-solution%2Ftags%2F3.13.5&old=3663183%40iubenda-cookie-law-solution%2Ftags%2F3.13.4",
        "https://plugins.trac.wordpress.org/changeset/3675630/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php",
        "https://plugins.trac.wordpress.org/changeset?old_path=%2Fiubenda-cookie-law-solution/tags/3.13.4&new_path=%2Fiubenda-cookie-law-solution/tags/3.13.5"
      ],
      "published": "2026-09-30T07:38:36Z",
      "updated": "2026-09-30T07:38:36Z"
    },
    {
      "id": "CVE-2026-77233",
      "url": "https://labs.diras.sa/cve/cve-2026-77233/",
      "title": "Iubenda plugin stored cross-site scripting via AdSense regex rewrite",
      "vendor": "iubenda",
      "product": "iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00508,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.13.4 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat as high priority because exploitation requires no authentication and allows persistent script injection when the Secondary parser is enabled. If you expose the plugin on the public web and use the Secondary parser, mitigate immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77233",
        "https://www.cve.org/CVERecord?id=CVE-2026-77233",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/af459f28-a058-42d3-8818-43603c6a14eb?source=cve",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda-cookie-class/iubenda.class.php#L570",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda-cookie-class/iubenda.class.php#L557",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda_cookie_solution.php#L986",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda-cookie-class/iubenda.class.php#L570",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda-cookie-class/iubenda.class.php#L557",
        "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda_cookie_solution.php#L986",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3675630%40iubenda-cookie-law-solution%2Ftags%2F3.13.5&old=3663183%40iubenda-cookie-law-solution%2Ftags%2F3.13.4",
        "https://plugins.trac.wordpress.org/changeset/3675630/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php",
        "https://plugins.trac.wordpress.org/changeset?old_path=%2Fiubenda-cookie-law-solution/tags/3.13.4&new_path=%2Fiubenda-cookie-law-solution/tags/3.13.5"
      ],
      "published": "2026-09-30T07:38:27Z",
      "updated": "2026-09-30T07:38:27Z"
    },
    {
      "id": "CVE-2026-19769",
      "url": "https://labs.diras.sa/cve/cve-2026-19769/",
      "title": "Ninja Forms stored cross-site scripting via file upload",
      "vendor": "kstover",
      "product": "Ninja Forms – The Contact Form Builder That Grows With You",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00247,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.15.1 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority if your public WordPress sites use the File Uploads add-on: an unauthenticated upload path can place executable files in the webroot, so disable the add-on or block write access to web-facing directories until a vendor patch is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-19769",
        "https://www.cve.org/CVERecord?id=CVE-2026-19769",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/2330e381-7db3-4b79-8827-818d2ea954b5?source=cve",
        "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L609",
        "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L303",
        "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L55",
        "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L61",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3674413%40ninja-forms%2Ftags%2F3.15.2&old=3663678%40ninja-forms%2Ftags%2F3.15.1",
        "https://plugins.trac.wordpress.org/changeset/3674413/ninja-forms/trunk/includes/AJAX/Controllers/Submission.php",
        "https://plugins.trac.wordpress.org/changeset?old_path=%2Fninja-forms/tags/3.15.1&new_path=%2Fninja-forms/tags/3.15.2"
      ],
      "published": "2026-09-30T07:38:18Z",
      "updated": "2026-09-30T07:38:18Z"
    },
    {
      "id": "CVE-2026-18406",
      "url": "https://labs.diras.sa/cve/cve-2026-18406/",
      "title": "SureForms stored cross-site scripting vulnerability",
      "vendor": "brainstormforce",
      "product": "SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00285,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.12.2 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because the flaw allows unauthenticated, persistent script injection into pages users visit. Immediately limit exposure and prepare to apply the vendor's fix when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-18406",
        "https://www.cve.org/CVERecord?id=CVE-2026-18406",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/8583c1f2-0820-492c-9fa1-d96e0ce2ddf2?source=cve",
        "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/assets/build/entries.js#L172",
        "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/form-submit.php#L1451",
        "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/form-submit.php#L229",
        "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/form-submit.php#L93",
        "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/helper.php#L241",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3636000%40sureforms%2Ftags%2F2.12.3&old=3618798%40sureforms%2Ftags%2F2.12.2",
        "https://plugins.trac.wordpress.org/changeset/3635980/sureforms/trunk/inc/form-submit.php",
        "https://plugins.trac.wordpress.org/changeset?old_path=%2Fsureforms/tags/2.12.2&new_path=%2Fsureforms/tags/2.12.3"
      ],
      "published": "2026-09-30T07:38:02Z",
      "updated": "2026-09-30T07:38:02Z"
    },
    {
      "id": "CVE-2026-77830",
      "url": "https://labs.diras.sa/cve/cve-2026-77830/",
      "title": "Spam protection, Honeypot, Anti-Spam by CleanTalk stored XSS in comments",
      "vendor": "cleantalk",
      "product": "Spam protection, Honeypot, Anti-Spam by CleanTalk",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00474,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "6.x",
          "affected": "6.86 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "High priority: public comment submission can deliver the payload and it executes for anonymous visitors, so immediately reduce exposure by disabling the plugin or enforcing strict moderation and access controls until a vendor fix exists.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77830",
        "https://www.cve.org/CVERecord?id=CVE-2026-77830",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/10e7000b-597a-4165-8604-cb6b29714abb?source=cve",
        "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L914",
        "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L933",
        "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/ApbctWP/ContactsEncoder/ContactsEncoder.php#L114",
        "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/cleantalk.php#L234",
        "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L914",
        "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L933",
        "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/ApbctWP/ContactsEncoder/ContactsEncoder.php#L114",
        "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/cleantalk.php#L234",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3677388%40cleantalk-spam-protect%2Ftags%2F6.87&old=3654120%40cleantalk-spam-protect%2Ftags%2F6.86",
        "https://plugins.trac.wordpress.org/changeset/3677388/cleantalk-spam-protect/trunk/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php",
        "https://plugins.trac.wordpress.org/changeset?old_path=%2Fcleantalk-spam-protect/tags/6.86&new_path=%2Fcleantalk-spam-protect/tags/6.87"
      ],
      "published": "2026-09-30T07:37:53Z",
      "updated": "2026-09-30T07:37:53Z"
    },
    {
      "id": "CVE-2026-78438",
      "url": "https://labs.diras.sa/cve/cve-2026-78438/",
      "title": "W3 Total Cache stored cross-site scripting via lazy load background images",
      "vendor": "boldgrid",
      "product": "W3 Total Cache",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00498,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.10.5 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Prioritise mitigation because there is no vendor fix for affected releases and the flaw allows unauthenticated script injection that executes for site visitors once a comment is approved.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-78438",
        "https://www.cve.org/CVERecord?id=CVE-2026-78438",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/5580ad05-af50-4899-9cbf-39ad8000eb6a?source=cve",
        "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L293",
        "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L255",
        "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L91",
        "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Plugin.php#L87",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3680101%40w3-total-cache%2Ftags%2F2.10.6&old=3653442%40w3-total-cache%2Ftags%2F2.10.5",
        "https://plugins.trac.wordpress.org/changeset?old_path=%2Fw3-total-cache/tags/2.10.5&new_path=%2Fw3-total-cache/tags/2.10.6",
        "https://plugins.trac.wordpress.org/changeset/3680101/w3-total-cache/tags/2.10.6/UserExperience_LazyLoad_Mutator.php"
      ],
      "published": "2026-09-30T07:37:36Z",
      "updated": "2026-09-30T07:37:36Z"
    },
    {
      "id": "CVE-2026-18405",
      "url": "https://labs.diras.sa/cve/cve-2026-18405/",
      "title": "Jeg Kit for Elementor stored cross-site scripting via comments",
      "vendor": "jegtheme",
      "product": "Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00292,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.2.16 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "High urgency: this is an unauthenticated stored XSS in an internet-facing WordPress plugin and there is no fixed release listed for versions up to 3.2.16, so apply mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-18405",
        "https://www.cve.org/CVERecord?id=CVE-2026-18405",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/2e4a9e9a-7bdc-4f51-ac3f-d6627b4f62c7?source=cve",
        "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.10/assets/js/elements/countdown.js#L1",
        "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.10/helper.php#L868",
        "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.10/lib/jeg-framework/util/framework-helper.php#L153",
        "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.10/class/elements/views/class-countdown-view.php#L107",
        "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.7/assets/js/elements/countdown.js#L1",
        "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.7/helper.php#L868",
        "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.7/lib/jeg-framework/util/framework-helper.php#L153",
        "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.7/class/elements/views/class-countdown-view.php#L107",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3690125%40jeg-elementor-kit%2Ftags%2F3.2.17&old=3679095%40jeg-elementor-kit%2Ftags%2F3.2.16",
        "https://plugins.trac.wordpress.org/changeset/3690125/jeg-elementor-kit/trunk/class/elements/views/class-countdown-view.php"
      ],
      "published": "2026-09-30T07:37:21Z",
      "updated": "2026-09-30T07:37:21Z"
    },
    {
      "id": "CVE-2026-87915",
      "url": "https://labs.diras.sa/cve/cve-2026-87915/",
      "title": "Popup Maker stored cross-site scripting in values[Name] parameter",
      "vendor": "danieliser",
      "product": "Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00494,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.24.0 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize mitigation now; treat sites with this plugin as high risk until a vendor fix is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-87915",
        "https://www.cve.org/CVERecord?id=CVE-2026-87915",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/ea8b1eee-2e3f-4d61-b815-4ea0aaa188b5?source=cve",
        "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Admin/Subscribers/Table.php#L281",
        "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/ListTable.php#L1408",
        "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Newsletters.php#L74",
        "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Newsletters.php#L273",
        "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Abstract/Database.php#L359",
        "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Newsletters.php#L59",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3690634%40popup-maker%2Ftags%2F1.25.0&old=3648112%40popup-maker%2Ftags%2F1.24.0",
        "https://plugins.trac.wordpress.org/changeset/3690634/popup-maker/trunk/classes/Admin/Subscribers/Table.php"
      ],
      "published": "2026-09-30T07:37:12Z",
      "updated": "2026-09-30T07:37:12Z"
    },
    {
      "id": "CVE-2026-13354",
      "url": "https://labs.diras.sa/cve/cve-2026-13354/",
      "title": "Asset CleanUp: Page Speed Booster stored cross-site scripting via comments",
      "vendor": "gabelivan",
      "product": "Asset CleanUp: Page Speed Booster",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00241,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.4.0.5 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Act urgently: this is a stored XSS that requires no login to inject and can persistently affect visitors; prioritize disabling the vulnerable feature and applying vendor guidance as soon as a fix is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-13354",
        "https://www.cve.org/CVERecord?id=CVE-2026-13354",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/4cc8ec2b-f203-4c7c-8720-043f8634a447?source=cve",
        "https://plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.4/classes/OptimiseAssets/OptimizeCss.php#L579",
        "https://plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.4/classes/OptimiseAssets/OptimizeJs.php#L824",
        "https://plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.3/classes/OptimiseAssets/OptimizeCss.php#L579",
        "https://plugins.trac.wordpress.org/browser/wp-asset-clean-up/tags/1.4.0.3/classes/OptimiseAssets/OptimizeJs.php#L824",
        "https://research.cleantalk.org/cve-2026-13354",
        "https://plugins.trac.wordpress.org/changeset?reponame=&old=3699024%40wp-asset-clean-up&new=3699024%40wp-asset-clean-up"
      ],
      "published": "2026-09-30T07:37:03Z",
      "updated": "2026-09-30T07:37:03Z"
    },
    {
      "id": "CVE-2026-89412",
      "url": "https://labs.diras.sa/cve/cve-2026-89412/",
      "title": "TranslatePress Stored cross-site scripting in suggestion panel",
      "vendor": "cozmoslabs",
      "product": "TranslatePress – Translate Multilingual sites with AI Translation",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00527,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.3.5 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth stored XSS that requires no login, so attackers can seed persistent payloads remotely; mitigate exposure immediately and prioritize protective controls for admin and suggestion interfaces.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-89412",
        "https://www.cve.org/CVERecord?id=CVE-2026-89412",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/717e8479-921b-4f18-8fbe-32e0d8a37590?source=cve",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/assets/src/js/components/translation-memory.vue#L12",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-memory.php#L47",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-memory.php#L60",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-render.php#L1024",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.5/includes/class-translation-render.php#L996",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/assets/src/js/components/translation-memory.vue#L12",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-memory.php#L47",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-memory.php#L60",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-render.php#L1024",
        "https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.3.3/includes/class-translation-render.php#L996",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3697206%40translatepress-multilingual%2Ftags%2F3.3.6&old=3686891%40translatepress-multilingual%2Ftags%2F3.3.5",
        "https://plugins.trac.wordpress.org/changeset/3697206/translatepress-multilingual/trunk/assets/src/js/components/translation-memory.vue"
      ],
      "published": "2026-09-30T07:36:54Z",
      "updated": "2026-09-30T07:36:54Z"
    },
    {
      "id": "CVE-2026-94504",
      "url": "https://labs.diras.sa/cve/cve-2026-94504/",
      "title": "Ninja Forms stored cross-site scripting in submission editor",
      "vendor": "kstover",
      "product": "Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00412,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.15.3 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this flaw, so restrict admin access to submission pages immediately and treat exposed sites as high priority to remediate or mitigate.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-94504",
        "https://www.cve.org/CVERecord?id=CVE-2026-94504",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/c599a562-5218-4b37-bcf7-0e82008a4e68?source=cve",
        "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Fields/Textarea.php#L35",
        "https://plugins.trac.wordpress.org/browser/ninja-forms/trunk/includes/Fields/Textarea.php#L35",
        "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Templates/admin-metabox-sub-fields.html.php#L23",
        "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Database/Models/Submission.php#L205",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3705719%40ninja-forms%2Ftags%2F3.15.4&old=3685242%40ninja-forms%2Ftags%2F3.15.3"
      ],
      "published": "2026-09-30T07:36:44Z",
      "updated": "2026-09-30T07:36:44Z"
    },
    {
      "id": "CVE-2026-18561",
      "url": "https://labs.diras.sa/cve/cve-2026-18561/",
      "title": "Unlimited Elements For Elementor unauthenticated SQL injection",
      "vendor": "unitecms",
      "product": "Unlimited Elements For Elementor",
      "cwe": "CWE-89",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
      },
      "epss": 0.0033,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.0.16 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated SQL injection with no vendor fix listed for 2.0.16 and earlier, so immediately reduce exposure and monitor for suspicious database queries.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-18561",
        "https://www.cve.org/CVERecord?id=CVE-2026-18561",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/969d605d-e093-447c-abf7-0d56cb3ac569?source=cve",
        "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/framework/db.class.php#L216",
        "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_actions.class.php#L87",
        "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addons.class.php#L1387",
        "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addon.class.php#L304",
        "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/provider/provider_functions.class.php#L611",
        "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3661670%40unlimited-elements-for-elementor%2Ftrunk&old=3628543%40unlimited-elements-for-elementor%2Ftrunk&sfp_email=&sfph_mail="
      ],
      "published": "2026-09-30T07:36:35Z",
      "updated": "2026-09-30T07:36:35Z"
    },
    {
      "id": "CVE-2026-89406",
      "url": "https://labs.diras.sa/cve/cve-2026-89406/",
      "title": "Modula Image Gallery disclosure of private galleries and media",
      "vendor": "wpchill",
      "product": "Modula Image Gallery – Photo Grid & Video Gallery",
      "cwe": "CWE-862",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
      },
      "epss": 0.00394,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.0.1 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a publicly reachable, unauthenticated information-disclosure bug that exposes private media; treat sites hosting Modula 3.0.1 or earlier as at immediate risk and reduce exposure until a vendor fix is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-89406",
        "https://www.cve.org/CVERecord?id=CVE-2026-89406",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/a369dff6-feca-47cf-8511-dc75c4ffdd29?source=cve",
        "https://plugins.trac.wordpress.org/browser/modula-best-grid-gallery/tags/3.0.1/includes/public/meta/class-modula-meta.php#L142",
        "https://plugins.trac.wordpress.org/browser/modula-best-grid-gallery/tags/3.0.1/includes/public/meta/class-modula-meta.php#L50",
        "https://plugins.trac.wordpress.org/browser/modula-best-grid-gallery/tags/3.0.1/includes/public/meta/class-modula-meta.php#L26",
        "https://plugins.trac.wordpress.org/browser/modula-best-grid-gallery/tags/3.0.1/includes/public/meta/social_meta.php#L8",
        "https://plugins.trac.wordpress.org/changeset?reponame=&old=3697043%40modula-best-grid-gallery&new=3697043%40modula-best-grid-gallery"
      ],
      "published": "2026-09-30T07:36:21Z",
      "updated": "2026-09-30T07:36:21Z"
    },
    {
      "id": "CVE-2026-66047",
      "url": "https://labs.diras.sa/cve/cve-2026-66047/",
      "title": "ProfilePress unauthenticated remote code execution",
      "vendor": "Proper Fraction",
      "product": "ProfilePress",
      "cwe": "CWE-306",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00924,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "4.x",
          "affected": "before 4.17.2",
          "fixed": "4.17.2"
        }
      ],
      "dirasTake": "High urgency: this is an unauthenticated RCE that allows code execution without credentials, so immediately update internet-facing ProfilePress instances to 4.17.2.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-66047",
        "https://www.cve.org/CVERecord?id=CVE-2026-66047",
        "https://profilepress.com/changelog/",
        "https://wordpress.org/plugins/wp-user-avatar/",
        "https://www.vulncheck.com/advisories/profilepress-wordpress-plugin-unauthenticated-arbitrary-plugin-installation-rce"
      ],
      "published": "2026-09-30T07:36:12Z",
      "updated": "2026-09-30T07:36:12Z"
    },
    {
      "id": "CVE-2025-39964",
      "url": "https://labs.diras.sa/cve/cve-2025-39964/",
      "title": "Linux Kernel AF_ALG concurrent-write race condition in af_alg_sendmsg",
      "vendor": "Linux",
      "product": "Kernel",
      "cwe": null,
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00996,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-18",
        "dueDate": "2026-09-21"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "0.x",
          "affected": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
          "fixed": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce"
        },
        {
          "branch": "Linux",
          "affected": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
          "fixed": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9"
        },
        {
          "branch": "1.x",
          "affected": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
          "fixed": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8"
        },
        {
          "branch": "7.x",
          "affected": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 7c4491b5644e3a3708f3dbd7591be0a570135b84",
          "fixed": "7c4491b5644e3a3708f3dbd7591be0a570135b84"
        },
        {
          "branch": "9.x",
          "affected": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 9aee87da5572b3a14075f501752e209801160d3d",
          "fixed": "9aee87da5572b3a14075f501752e209801160d3d"
        },
        {
          "branch": "45.x",
          "affected": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 45bcf60fe49b37daab1acee57b27211ad1574042",
          "fixed": "45bcf60fe49b37daab1acee57b27211ad1574042"
        },
        {
          "branch": "1.x",
          "affected": "8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
          "fixed": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
        },
        {
          "branch": "2.x",
          "affected": "2.6.38",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2026-09-18 with a remediation deadline of 2026-09-21, so prioritize applying fixes or mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2025-39964",
        "https://www.cve.org/CVERecord?id=CVE-2025-39964",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964",
        "https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
        "https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
        "https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
        "https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84",
        "https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d",
        "https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042",
        "https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285"
      ],
      "published": "2026-09-30T07:35:56Z",
      "updated": "2026-09-30T07:35:56Z"
    },
    {
      "id": "CVE-2026-84324",
      "url": "https://labs.diras.sa/cve/cve-2026-84324/",
      "title": "Chrome Proxy use-after-free allows remote code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.0047,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.75 – before 152.0.7977.75",
          "fixed": "152.0.7977.75"
        }
      ],
      "dirasTake": "Urgent: this is a network-triggered, no-interaction remote code execution (no authentication and no user interaction required), so update immediately to the fixed build 152.0.7977.75 or later.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84324",
        "https://www.cve.org/CVERecord?id=CVE-2026-84324",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html",
        "https://issues.chromium.org/issues/533534913"
      ],
      "published": "2026-09-30T07:35:10Z",
      "updated": "2026-09-30T07:35:10Z"
    },
    {
      "id": "CVE-2026-87613",
      "url": "https://labs.diras.sa/cve/cve-2026-87613/",
      "title": "Chrome incorrect reference resolution in Extensions allows remote code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-706",
      "cvss": {
        "version": "3.1",
        "score": 9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.0047,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "153.x",
          "affected": "153.0.8010.36 – before 153.0.8010.36",
          "fixed": "153.0.8010.36"
        }
      ],
      "dirasTake": "Urgently update Chrome to 153.0.8010.36 or later — this issue carries a critical CVSS 9.0 rating and has been fixed in that release. If immediate update is not possible, restrict network exposure to untrusted sources and monitor for anomalous browser activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-87613",
        "https://www.cve.org/CVERecord?id=CVE-2026-87613",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html",
        "https://issues.chromium.org/issues/501889544"
      ],
      "published": "2026-09-30T07:35:00Z",
      "updated": "2026-09-30T07:35:00Z"
    },
    {
      "id": "CVE-2026-73475",
      "url": "https://labs.diras.sa/cve/cve-2026-73475/",
      "title": "Commerce PayPal forceful browsing lets unauthenticated users access",
      "vendor": "Drupal",
      "product": "Commerce PayPal",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00404,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "before 1.12.0",
          "fixed": "1.12.0"
        },
        {
          "branch": "2.x",
          "affected": "2.0.0 – before 2.1.3",
          "fixed": "2.1.3"
        }
      ],
      "dirasTake": "Treat this as urgent because the flaw requires no login and allows unauthenticated access; prioritize patching or mitigation immediately for any internet-facing Drupal sites running the module.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-73475",
        "https://www.cve.org/CVERecord?id=CVE-2026-73475",
        "https://www.drupal.org/sa-contrib-2026-095"
      ],
      "published": "2026-09-30T07:34:50Z",
      "updated": "2026-09-30T07:34:50Z"
    },
    {
      "id": "CVE-2026-85043",
      "url": "https://labs.diras.sa/cve/cve-2026-85043/",
      "title": "Chrome network cleanup bypass allows remote system access bypass",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-459",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
      },
      "epss": 0.00441,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.82 – before 152.0.7977.82",
          "fixed": "152.0.7977.82"
        }
      ],
      "dirasTake": "Urgent: apply the vendor fix 152.0.7977.82 immediately because this is a remotely reachable bypass that requires no authentication or user interaction.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85043",
        "https://www.cve.org/CVERecord?id=CVE-2026-85043",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html",
        "https://issues.chromium.org/issues/533502257"
      ],
      "published": "2026-09-30T07:34:38Z",
      "updated": "2026-09-30T07:34:38Z"
    },
    {
      "id": "CVE-2026-88056",
      "url": "https://labs.diras.sa/cve/cve-2026-88056/",
      "title": "Angular Server-Side Rendering SSRF and credential disclosure",
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-918",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00613,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "angular",
          "affected": "<= 19.2.25",
          "fixed": null
        },
        {
          "branch": "angular",
          "affected": ">= 20.0.0, < 20.3.30",
          "fixed": null
        },
        {
          "branch": "angular",
          "affected": ">= 21.0.0, < 21.2.22",
          "fixed": null
        },
        {
          "branch": "angular",
          "affected": ">= 22.0.0, < 22.1.4",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: vulnerable Angular SSR code can cause SSRF that discloses attached server credentials and the facts show no fixed releases listed here; immediately reduce exposure of SSR endpoints and follow vendor guidance when patches are published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-88056",
        "https://www.cve.org/CVERecord?id=CVE-2026-88056",
        "https://github.com/angular/angular/security/advisories/GHSA-f6mr-pjwc-34m4",
        "https://github.com/angular/angular/commit/3e924cc8dbbb57f23b262cb8f0d7e2bd0673034c",
        "https://github.com/angular/angular/commit/5aa6d97deb9ef1de14e23748b7fa74f97d183132",
        "https://github.com/angular/angular/commit/71e52d1396b9cef98652929b73e08c4cde645970",
        "https://github.com/angular/angular/releases/tag/v20.3.30",
        "https://github.com/angular/angular/releases/tag/v21.2.22",
        "https://github.com/angular/angular/releases/tag/v22.1.4"
      ],
      "published": "2026-09-30T07:34:25Z",
      "updated": "2026-09-30T07:34:25Z"
    },
    {
      "id": "CVE-2026-43790",
      "url": "https://labs.diras.sa/cve/cve-2026-43790/",
      "title": "MacOS kernel out-of-bounds write lets remote attacker corrupt memory or crash",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
      },
      "epss": 0.00717,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Treat this as a high-priority patch: the flaw is remotely reachable without authentication or user interaction (CVSS vector shows PR:N/UI:N), and vendor updates are available for the affected branches.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-43790",
        "https://www.cve.org/CVERecord?id=CVE-2026-43790",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-30T07:34:12Z",
      "updated": "2026-09-30T07:34:12Z"
    },
    {
      "id": "CVE-2026-84625",
      "url": "https://labs.diras.sa/cve/cve-2026-84625/",
      "title": "IOS and iPadOS permissions issue lets an app fingerprint the user",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00471,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "macOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "visionOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "watchOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgently install the vendor updates: Apple fixed the issue in version 27 across affected platforms, so apply those updates promptly to remove the vulnerability.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84625",
        "https://www.cve.org/CVERecord?id=CVE-2026-84625",
        "https://support.apple.com/en-us/149034",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149037",
        "https://support.apple.com/en-us/149038"
      ],
      "published": "2026-09-30T07:34:01Z",
      "updated": "2026-09-30T07:34:01Z"
    },
    {
      "id": "CVE-2026-86881",
      "url": "https://labs.diras.sa/cve/cve-2026-86881/",
      "title": "IOS and iPadOS certificate validation bypass",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-295",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00398,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "iOS and iPadOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "macOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "tvOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "visionOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "watchOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgently install Apple’s updates: fixes are available for iOS/iPadOS (26.7 and 27) and other Apple platforms. Treat exposed TLS services and systems that trust external CAs as high priority because a compromised intermediate CA can enable broad impersonation.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-86881",
        "https://www.cve.org/CVERecord?id=CVE-2026-86881",
        "https://support.apple.com/en-us/149034",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149036",
        "https://support.apple.com/en-us/149037",
        "https://support.apple.com/en-us/149038",
        "https://support.apple.com/en-us/149041",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-30T07:33:51Z",
      "updated": "2026-09-30T07:33:51Z"
    },
    {
      "id": "CVE-2026-92034",
      "url": "https://labs.diras.sa/cve/cve-2026-92034/",
      "title": "Firefox site isolation flaw allows remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
      },
      "epss": 0.00293,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: the vulnerability has a CVSS 9.1 critical rating and no patch is listed, so isolate or block exposure of Firefox instances and apply vendor guidance as soon as a fix is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92034",
        "https://www.cve.org/CVERecord?id=CVE-2026-92034",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2060295",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/"
      ],
      "published": "2026-09-30T07:33:32Z",
      "updated": "2026-09-30T07:33:32Z"
    },
    {
      "id": "CVE-2026-92038",
      "url": "https://labs.diras.sa/cve/cve-2026-92038/",
      "title": "Firefox mitigation bypass in Remote Settings Client",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00354,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: this is remotely exploitable without authentication, so reduce exposure immediately and prioritize vendor updates when available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92038",
        "https://www.cve.org/CVERecord?id=CVE-2026-92038",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2068952",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-93/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/",
        "https://www.mozilla.org/security/advisories/mfsa2026-96/"
      ],
      "published": "2026-09-30T07:33:18Z",
      "updated": "2026-09-30T07:33:18Z"
    },
    {
      "id": "CVE-2026-92041",
      "url": "https://labs.diras.sa/cve/cve-2026-92041/",
      "title": "Firefox mitigation bypass in DOM networking component",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00354,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Act urgently: this is a high-impact, network-exploitable vulnerability (CVSS 9.1) and no patch is listed in the provided facts—reduce exposure and follow Mozilla guidance as soon as it is published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92041",
        "https://www.cve.org/CVERecord?id=CVE-2026-92041",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2029482",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-93/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/",
        "https://www.mozilla.org/security/advisories/mfsa2026-96/"
      ],
      "published": "2026-09-30T07:33:02Z",
      "updated": "2026-09-30T07:33:02Z"
    },
    {
      "id": "CVE-2026-92051",
      "url": "https://labs.diras.sa/cve/cve-2026-92051/",
      "title": "Firefox null pointer dereference in Graphics component causes high-impact failures",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-476",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
      },
      "epss": 0.00566,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as urgent: the flaw scores critical and Mozilla has not published a broadly available patch timeline in the provided facts, so restrict exposure of affected browsers and prepare to apply vendor fixes as soon as they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92051",
        "https://www.cve.org/CVERecord?id=CVE-2026-92051",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2061393",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/"
      ],
      "published": "2026-09-30T07:32:33Z",
      "updated": "2026-09-30T07:32:33Z"
    },
    {
      "id": "CVE-2026-92050",
      "url": "https://labs.diras.sa/cve/cve-2026-92050/",
      "title": "Firefox sandbox escape via XPConnect race condition",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-362",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
      },
      "epss": 0.00437,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: CVE-2026-92050 allows remote, unauthenticated exploitation without user interaction per the CVSS vector, so prioritize reducing exposure and preparing to apply a vendor update as soon as one is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92050",
        "https://www.cve.org/CVERecord?id=CVE-2026-92050",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2061387",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/"
      ],
      "published": "2026-09-30T07:32:21Z",
      "updated": "2026-09-30T07:32:21Z"
    },
    {
      "id": "CVE-2026-92057",
      "url": "https://labs.diras.sa/cve/cve-2026-92057/",
      "title": "Firefox Enterprise Policies mitigation bypass",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00282,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as high priority: there is no patch available in the provided facts while the issue enables bypass of enterprise policy controls, so restrict exposure and monitor until Mozilla publishes a fix.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92057",
        "https://www.cve.org/CVERecord?id=CVE-2026-92057",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2065646",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-93/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/",
        "https://www.mozilla.org/security/advisories/mfsa2026-96/"
      ],
      "published": "2026-09-30T07:32:06Z",
      "updated": "2026-09-30T07:32:06Z"
    },
    {
      "id": "CVE-2026-92075",
      "url": "https://labs.diras.sa/cve/cve-2026-92075/",
      "title": "Firefox mitigation bypass in Networking component",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00354,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as high priority: the flaw is remotely exploitable with no privileges or UI required and there is no patch listed in the provided data, so restrict exposure and prepare to apply vendor updates immediately when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92075",
        "https://www.cve.org/CVERecord?id=CVE-2026-92075",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2063814",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-93/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/",
        "https://www.mozilla.org/security/advisories/mfsa2026-96/"
      ],
      "published": "2026-09-30T07:31:50Z",
      "updated": "2026-09-30T07:31:50Z"
    },
    {
      "id": "CVE-2026-92079",
      "url": "https://labs.diras.sa/cve/cve-2026-92079/",
      "title": "Firefox Widget Win32 mitigation bypass",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00282,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as urgent: the flaw requires no authentication and allows remote impact, so immediately restrict exposure of Firefox instances and follow vendor guidance until a patch is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92079",
        "https://www.cve.org/CVERecord?id=CVE-2026-92079",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2067531",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-93/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/",
        "https://www.mozilla.org/security/advisories/mfsa2026-96/"
      ],
      "published": "2026-09-30T07:31:40Z",
      "updated": "2026-09-30T07:31:40Z"
    },
    {
      "id": "CVE-2026-83944",
      "url": "https://labs.diras.sa/cve/cve-2026-83944/",
      "title": "Azure Logic Apps pre-auth privilege escalation via improper access control",
      "vendor": "Microsoft",
      "product": "Azure Logic Apps",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00442,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure Logic Apps",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this bypass requires no authentication, so exposed Logic Apps endpoints should be treated as high risk — apply Microsoft’s update or follow vendor mitigation guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-83944",
        "https://www.cve.org/CVERecord?id=CVE-2026-83944",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83944"
      ],
      "published": "2026-09-30T07:31:28Z",
      "updated": "2026-09-30T07:31:28Z"
    },
    {
      "id": "CVE-2026-93765",
      "url": "https://labs.diras.sa/cve/cve-2026-93765/",
      "title": "Mongoid unsafe reflection allows unauthenticated method invocation",
      "vendor": "MongoDB",
      "product": "Mongoid",
      "cwe": "CWE-470",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
      },
      "epss": 0.00511,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "9.x",
          "affected": "9.1.0",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.0.0 – 9.0.11",
          "fixed": null
        },
        {
          "branch": "8.x",
          "affected": "8.1.0 – 8.1.12",
          "fixed": null
        },
        {
          "branch": "8.x",
          "affected": "8.0.0 – 8.0.12",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because the flaw can be triggered without authentication and no fixed release is yet listed; immediately block or validate untrusted keys forwarded into Mongoid and limit public exposure of services that accept user-supplied document data.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-93765",
        "https://www.cve.org/CVERecord?id=CVE-2026-93765",
        "https://jira.mongodb.org/browse/MONGOID-5973"
      ],
      "published": "2026-09-30T07:31:18Z",
      "updated": "2026-09-30T07:31:18Z"
    },
    {
      "id": "CVE-2026-89282",
      "url": "https://labs.diras.sa/cve/cve-2026-89282/",
      "title": "Apache Lounge Windows insecure install directory permissions allow file modification",
      "vendor": "Apache HTTP Server Project",
      "product": "Apache Lounge Windows",
      "cwe": "CWE-732",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00268,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Apache Lounge Windows",
          "affected": "before Apache 2.4.68-260920 Win64",
          "fixed": "Apache 2.4.68-260920 Win64"
        }
      ],
      "dirasTake": "Urgent: install the fixed Apache 2.4.68-260920 Win64 build or correct NTFS permissions immediately because the default C:\\ install directory grants write access to Authenticated Users.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-89282",
        "https://www.cve.org/CVERecord?id=CVE-2026-89282",
        "https://httpd.apache.org/download.cgi",
        "https://atos.net/en/lp/cybershield/a-tale-of-several-hijacks-and-what-it-taught-me-about-runtime-driven-testing",
        "https://www.apachelounge.com/viewtopic.php?t=9515"
      ],
      "published": "2026-09-30T07:31:08Z",
      "updated": "2026-09-30T07:31:08Z"
    },
    {
      "id": "CVE-2026-86350",
      "url": "https://labs.diras.sa/cve/cve-2026-86350/",
      "title": "Apache Tomcat HTTP/2 request smuggling regression",
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-444",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00313,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "11.x",
          "affected": "11.0.22 – 11.0.25",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.1.55 – 10.1.59",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.0.118 – 9.0.121",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: public exploit code exists and the flaw can be triggered without authentication, so immediately limit exposure and follow vendor mitigation guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-86350",
        "https://www.cve.org/CVERecord?id=CVE-2026-86350",
        "https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc"
      ],
      "published": "2026-09-30T07:30:56Z",
      "updated": "2026-09-30T07:30:56Z"
    },
    {
      "id": "CVE-2026-86246",
      "url": "https://labs.diras.sa/cve/cve-2026-86246/",
      "title": "Apache Tomcat Native insecure-default TLS options",
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat Native",
      "cwe": "CWE-1188",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.0028,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.0.0 – 2.0.15",
          "fixed": null
        },
        {
          "branch": "1.x",
          "affected": "1.3.0 – 1.3.8",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority: the vulnerability is remotely reachable without authentication (CVSS vector AV:N/PR:N/UI:N), so immediately limit exposure of Tomcat Native instances and apply vendor guidance as available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-86246",
        "https://www.cve.org/CVERecord?id=CVE-2026-86246",
        "https://lists.apache.org/thread/dgyvfwb24nbk45ptvlhdyhdhl5o7k5ol"
      ],
      "published": "2026-09-30T07:30:38Z",
      "updated": "2026-09-30T07:30:38Z"
    },
    {
      "id": "CVE-2026-77987",
      "url": "https://labs.diras.sa/cve/cve-2026-77987/",
      "title": "GitHub Enterprise Server SSRF leads to remote code execution",
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-918",
      "cvss": {
        "version": "4.0",
        "score": 9.3,
        "severity": "critical",
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": 0.00891,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.17.0 – before 3.17.*",
          "fixed": "3.17.*"
        },
        {
          "branch": "3.x",
          "affected": "3.18.0 – before 3.18.*",
          "fixed": "3.18.*"
        },
        {
          "branch": "3.x",
          "affected": "3.19.0 – before 3.19.*",
          "fixed": "3.19.*"
        },
        {
          "branch": "3.x",
          "affected": "3.20.0 – before 3.20.*",
          "fixed": "3.20.*"
        },
        {
          "branch": "3.x",
          "affected": "3.21.0 – before 3.21.*",
          "fixed": "3.21.*"
        },
        {
          "branch": "3.x",
          "affected": "3.22.0 – before 3.22.*",
          "fixed": "3.22.*"
        }
      ],
      "dirasTake": "Urgent: this flaw can enable unauthenticated RCE when private mode is off, so treat systems exposed to untrusted networks as high priority for patching. Install the vendor fixes for affected 3.17–3.22 branches now or block access to the appliance until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77987",
        "https://www.cve.org/CVERecord?id=CVE-2026-77987",
        "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21",
        "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.15",
        "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.12",
        "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.8",
        "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.6",
        "https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.1"
      ],
      "published": "2026-09-30T07:30:20Z",
      "updated": "2026-09-30T07:30:20Z"
    },
    {
      "id": "CVE-2026-70757",
      "url": "https://labs.diras.sa/cve/cve-2026-70757/",
      "title": "Oracle WebLogic Server unauthenticated remote code execution via T3/IIOP",
      "vendor": "Oracle",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00508,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "12.x",
          "affected": "12.2.1.4.0",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.1.1.0.0",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.1.2.0.0",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15.1.1.0.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated flaw that allows full server compromise, so prioritize mitigations now because the vulnerability is easily exploitable without credentials. If you cannot immediately apply vendor guidance, restrict or block T3/IIOP exposure and increase monitoring for suspicious activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-70757",
        "https://www.cve.org/CVERecord?id=CVE-2026-70757",
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "published": "2026-09-30T07:30:05Z",
      "updated": "2026-09-30T07:30:05Z"
    },
    {
      "id": "CVE-2026-70748",
      "url": "https://labs.diras.sa/cve/cve-2026-70748/",
      "title": "Oracle WebLogic Server unauthenticated remote takeover via T3/IIOP",
      "vendor": "Oracle",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00483,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "12.x",
          "affected": "12.2.1.4.0",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.1.1.0.0",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.1.2.0.0",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15.1.1.0.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth remote compromise of an internet-reachable service with a CVSS 9.8 rating, so prioritize isolating and restricting T3/IIOP exposure immediately and apply vendor fixes when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-70748",
        "https://www.cve.org/CVERecord?id=CVE-2026-70748",
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "published": "2026-09-30T07:29:56Z",
      "updated": "2026-09-30T07:29:56Z"
    },
    {
      "id": "CVE-2026-70756",
      "url": "https://labs.diras.sa/cve/cve-2026-70756/",
      "title": "Oracle WebLogic Server unauthenticated remote takeover via T3/IIOP",
      "vendor": "Oracle",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00508,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "12.x",
          "affected": "12.2.1.4.0",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.1.1.0.0",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.1.2.0.0",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15.1.1.0.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this allows unauthenticated remote compromise via T3/IIOP, so immediately reduce exposure of WebLogic management interfaces and apply vendor guidance as soon as patches are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-70756",
        "https://www.cve.org/CVERecord?id=CVE-2026-70756",
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "published": "2026-09-30T07:29:47Z",
      "updated": "2026-09-30T07:29:47Z"
    },
    {
      "id": "CVE-2026-76183",
      "url": "https://labs.diras.sa/cve/cve-2026-76183/",
      "title": "Apache Tomcat authentication bypass for WebSocket endpoints",
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-289",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0039,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "11.x",
          "affected": "11.0.0-M1 – 11.0.25",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.1.0-M1 – 10.1.59",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.0.0.M1 – 9.0.121",
          "fixed": null
        },
        {
          "branch": "8.x",
          "affected": "8.5.0 – 8.5.100",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.43 – 7.0.109",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "before 7.0.43",
          "fixed": "7.0.43"
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth bypass affecting many common Tomcat releases, so prioritize mitigation — the bug lets unauthenticated network attackers reach protected WebSocket endpoints. Reduce internet exposure and apply vendor updates or guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76183",
        "https://www.cve.org/CVERecord?id=CVE-2026-76183",
        "https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp"
      ],
      "published": "2026-09-30T07:29:38Z",
      "updated": "2026-09-30T07:29:38Z"
    },
    {
      "id": "CVE-2026-86248",
      "url": "https://labs.diras.sa/cve/cve-2026-86248/",
      "title": "Apache Tomcat CLIENT_CERT authentication bypass (pre-auth)",
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00386,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "11.x",
          "affected": "11.0.0-M14 – 11.0.25",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.1.22 – 10.1.59",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.0.92 – 9.0.121",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority for internet-facing Tomcat servers because the flaw can be triggered without credentials; if you expose CLIENT_CERT-protected endpoints, immediately restrict access and follow vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-86248",
        "https://www.cve.org/CVERecord?id=CVE-2026-86248",
        "https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk"
      ],
      "published": "2026-09-30T07:29:27Z",
      "updated": "2026-09-30T07:29:27Z"
    },
    {
      "id": "CVE-2026-83021",
      "url": "https://labs.diras.sa/cve/cve-2026-83021/",
      "title": "Oracle WebLogic Server unauthenticated HTTP remote takeover",
      "vendor": "Oracle",
      "product": "Oracle WebLogic Server",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00508,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "12.x",
          "affected": "12.2.1.4.0",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.1.1.0.0",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.1.2.0.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat this as a high-priority mitigation because the flaw allows unauthenticated HTTP access to full server compromise and no fixes are listed for affected releases. Immediately restrict network exposure and follow Oracle’s guidance until a patch is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-83021",
        "https://www.cve.org/CVERecord?id=CVE-2026-83021",
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "published": "2026-09-30T07:29:15Z",
      "updated": "2026-09-30T07:29:15Z"
    },
    {
      "id": "CVE-2026-96587",
      "url": "https://labs.diras.sa/cve/cve-2026-96587/",
      "title": "Dashcam Android Application embedded cloud credentials allow full storage access",
      "vendor": "Viidure",
      "product": "Dashcam Android Application",
      "cwe": "CWE-798",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": null,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.3.1.260403 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "High priority: this is an unauthenticated, high-impact exposure because recovered plaintext credentials provide complete storage access; immediately rotate credentials and tighten storage access while awaiting a vendor fix.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-96587",
        "https://www.cve.org/CVERecord?id=CVE-2026-96587",
        "https://viidure.app/",
        "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07",
        "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json"
      ],
      "published": "2026-09-30T07:29:03Z",
      "updated": "2026-09-30T07:29:03Z"
    },
    {
      "id": "CVE-2026-92229",
      "url": "https://labs.diras.sa/cve/cve-2026-92229/",
      "title": "Forminator Forms pre-auth shortcode execution",
      "vendor": "wpmudev",
      "product": "Forminator Forms – Contact Form, Payment Form & Custom Form Builder",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00727,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.57.2 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so patching or mitigations should be prioritised immediately; treat internet-facing WordPress sites with this plugin as exposed. Apply access restrictions and monitoring now and install the vendor fix as soon as it is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92229",
        "https://www.cve.org/CVERecord?id=CVE-2026-92229",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/7c28869c-c880-4322-9f17-09495a08576e?source=cve",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L870",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L837",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L60",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/abstracts/abstract-class-front-action.php#L127",
        "https://plugins.trac.wordpress.org/changeset?reponame=&old=3700724%40forminator&new=3700724%40forminator"
      ],
      "published": "2026-09-30T07:28:45Z",
      "updated": "2026-09-30T07:28:45Z"
    },
    {
      "id": "CVE-2026-93485",
      "url": "https://labs.diras.sa/cve/cve-2026-93485/",
      "title": "WordPress DOM-based cross-site scripting vulnerability",
      "vendor": "Automattic",
      "product": "WordPress",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
      },
      "epss": 0.00375,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.1 – before 7.1.1",
          "fixed": "7.1.1"
        },
        {
          "branch": "7.x",
          "affected": "7.0 – 7.0.4",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.9 – 6.9.7",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.8 – 6.8.8",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.7 – 6.7.7",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.6 – 6.6.7",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.5 – 6.5.10",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.4 – 6.4.10",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.3 – 6.3.10",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.2 – 6.2.11",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority: public exploit code exists for CVE-2026-93485, so sites reachable by untrusted users should be updated or mitigated immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-93485",
        "https://www.cve.org/CVERecord?id=CVE-2026-93485",
        "https://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
        "https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/"
      ],
      "published": "2026-09-30T07:28:35Z",
      "updated": "2026-09-30T07:28:35Z"
    },
    {
      "id": "CVE-2026-89055",
      "url": "https://labs.diras.sa/cve/cve-2026-89055/",
      "title": "Customer Reviews for WooCommerce authorization bypass deletes media",
      "vendor": "ivole",
      "product": "Customer Reviews for WooCommerce",
      "cwe": "CWE-862",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
      },
      "epss": 0.00385,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "5.x",
          "affected": "5.120.0 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so immediately mitigate exposure to public review-form links and harden access to the Media Library while awaiting a vendor fix.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-89055",
        "https://www.cve.org/CVERecord?id=CVE-2026-89055",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/b7bbeeea-3888-42a6-8d14-f5c39f5dcb70?source=cve",
        "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-reviews.php#L1871",
        "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reminders/class-cr-local-forms-ajax.php#L57",
        "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-endpoint.php#L318",
        "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-endpoint.php#L467",
        "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-reviews.php#L129",
        "https://plugins.trac.wordpress.org/changeset?reponame=&old=3694303%40customer-reviews-woocommerce&new=3694303%40customer-reviews-woocommerce"
      ],
      "published": "2026-09-30T07:28:23Z",
      "updated": "2026-09-30T07:28:23Z"
    },
    {
      "id": "CVE-2026-64703",
      "url": "https://labs.diras.sa/cve/cve-2026-64703/",
      "title": "MacOS use-after-free lets an app cause denial-of-service",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00569,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Apply Apple’s published updates for Sonoma 14.8.8, Sequoia 15.7.8 and Tahoe 26.6 promptly — patched builds are available and remove the vulnerability.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64703",
        "https://www.cve.org/CVERecord?id=CVE-2026-64703",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072"
      ],
      "published": "2026-09-29T17:57:13Z",
      "updated": "2026-09-29T17:57:13Z"
    },
    {
      "id": "CVE-2026-64695",
      "url": "https://labs.diras.sa/cve/cve-2026-64695/",
      "title": "IOS and iPadOS kernel memory corruption over network",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00729,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "High urgency — the bug can be reached over the network without credentials, so prioritize installing the vendor updates (for example iOS/iPadOS 18.7.10) on exposed devices immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64695",
        "https://www.cve.org/CVERecord?id=CVE-2026-64695",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:56:46Z",
      "updated": "2026-09-29T17:56:46Z"
    },
    {
      "id": "CVE-2026-64697",
      "url": "https://labs.diras.sa/cve/cve-2026-64697/",
      "title": "MacOS kernel memory corruption remote code execution",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00585,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: apply vendor updates immediately — the flaw allows unauthenticated remote kernel memory corruption and Apple published fixes for 14.8.8, 15.7.8 and 26.6. If you cannot update, restrict network exposure to macOS hosts and increase monitoring.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64697",
        "https://www.cve.org/CVERecord?id=CVE-2026-64697",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072"
      ],
      "published": "2026-09-29T17:56:28Z",
      "updated": "2026-09-29T17:56:28Z"
    },
    {
      "id": "CVE-2026-64704",
      "url": "https://labs.diras.sa/cve/cve-2026-64704/",
      "title": "MacOS type confusion pre-auth remote code execution",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-843",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00585,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: this is a remote, no-login-needed vulnerability with a critical CVSS rating; apply the vendor updates named below immediately to exposed systems.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64704",
        "https://www.cve.org/CVERecord?id=CVE-2026-64704",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072"
      ],
      "published": "2026-09-29T17:56:17Z",
      "updated": "2026-09-29T17:56:17Z"
    },
    {
      "id": "CVE-2026-64702",
      "url": "https://labs.diras.sa/cve/cve-2026-64702/",
      "title": "MacOS sandbox escape lets an app break out of its sandbox",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00541,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgently install the vendor fixes: this is a critical (CVSS 9.8) sandbox-escape bug that lets an app escalate beyond its sandbox; apply the listed macOS updates immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64702",
        "https://www.cve.org/CVERecord?id=CVE-2026-64702",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072"
      ],
      "published": "2026-09-29T17:56:04Z",
      "updated": "2026-09-29T17:56:04Z"
    },
    {
      "id": "CVE-2026-64700",
      "url": "https://labs.diras.sa/cve/cve-2026-64700/",
      "title": "IOS and iPadOS use-after-free may let an app terminate the system",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00661,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: install the vendor fixes because Apple has released patched builds for each affected branch (for example iOS/iPadOS 18.7.10 and 26.6). Applying those updates closes the reported use-after-free memory bug.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64700",
        "https://www.cve.org/CVERecord?id=CVE-2026-64700",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:55:53Z",
      "updated": "2026-09-29T17:55:53Z"
    },
    {
      "id": "CVE-2026-64694",
      "url": "https://labs.diras.sa/cve/cve-2026-64694/",
      "title": "MacOS integer overflow leads to remote code execution potential",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-190",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00585,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw is remotely reachable without authentication (CVSS AV:N/PR:N/UI:N) and vendor fixes are available for the affected branches; apply the updates immediately to exposed systems.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64694",
        "https://www.cve.org/CVERecord?id=CVE-2026-64694",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072"
      ],
      "published": "2026-09-29T17:55:40Z",
      "updated": "2026-09-29T17:55:40Z"
    },
    {
      "id": "CVE-2026-64698",
      "url": "https://labs.diras.sa/cve/cve-2026-64698/",
      "title": "MacOS kernel memory bug lets local apps crash or read kernel memory",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00585,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: this is a critical kernel memory flaw — apply the vendor updates for affected macOS releases immediately to remove the attack surface.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64698",
        "https://www.cve.org/CVERecord?id=CVE-2026-64698",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072"
      ],
      "published": "2026-09-29T17:55:28Z",
      "updated": "2026-09-29T17:55:28Z"
    },
    {
      "id": "CVE-2026-64720",
      "url": "https://labs.diras.sa/cve/cve-2026-64720/",
      "title": "IOS and iPadOS race condition lets remote attacker crash system",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-362",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00467,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: the flaw requires no authentication or user interaction and is fixed in 26.6; apply the vendor updates promptly to remove remote crash risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64720",
        "https://www.cve.org/CVERecord?id=CVE-2026-64720",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069"
      ],
      "published": "2026-09-29T17:55:05Z",
      "updated": "2026-09-29T17:55:05Z"
    },
    {
      "id": "CVE-2026-64727",
      "url": "https://labs.diras.sa/cve/cve-2026-64727/",
      "title": "MacOS type confusion in kernel memory handling allows an app to crash system",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-843",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00499,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Treat this as high priority: the bug requires no privileges to trigger and is fixed in macOS 26.6 and tvOS 26.6, so apply vendor updates promptly.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64727",
        "https://www.cve.org/CVERecord?id=CVE-2026-64727",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128069"
      ],
      "published": "2026-09-29T17:54:56Z",
      "updated": "2026-09-29T17:54:56Z"
    },
    {
      "id": "CVE-2026-64726",
      "url": "https://labs.diras.sa/cve/cve-2026-64726/",
      "title": "IOS and iPadOS memory corruption allows remote code execution",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0065,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth, network-exploitable memory corruption that can lead to remote code execution; apply Apple's available updates immediately to affected devices.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64726",
        "https://www.cve.org/CVERecord?id=CVE-2026-64726",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:54:43Z",
      "updated": "2026-09-29T17:54:43Z"
    },
    {
      "id": "CVE-2026-64729",
      "url": "https://labs.diras.sa/cve/cve-2026-64729/",
      "title": "IOS and iPadOS use-after-free lets an app cause system termination",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00588,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: this is rated critical (CVSS 9.8) and Apple released fixes in 26.6 for all affected branches — apply the 26.6 updates promptly to remove the vulnerability.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64729",
        "https://www.cve.org/CVERecord?id=CVE-2026-64729",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070"
      ],
      "published": "2026-09-29T17:54:33Z",
      "updated": "2026-09-29T17:54:33Z"
    },
    {
      "id": "CVE-2026-64733",
      "url": "https://labs.diras.sa/cve/cve-2026-64733/",
      "title": "IOS and iPadOS app fingerprinting information disclosure",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00605,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: this is rated critical with network, no-auth, no-UI attack vectors (CVSS 9.8), so prioritize deploying the vendor fix 26.6 immediately for internet-facing and high-risk devices.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64733",
        "https://www.cve.org/CVERecord?id=CVE-2026-64733",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070"
      ],
      "published": "2026-09-29T17:54:19Z",
      "updated": "2026-09-29T17:54:19Z"
    },
    {
      "id": "CVE-2026-64738",
      "url": "https://labs.diras.sa/cve/cve-2026-64738/",
      "title": "IOS and iPadOS sandbox escape allows app to break out of sandbox",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0056,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Treat this as high priority: Apple published fixes for the affected releases and devices should be updated to the listed fixed versions immediately to remove the sandbox escape vector.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64738",
        "https://www.cve.org/CVERecord?id=CVE-2026-64738",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:54:09Z",
      "updated": "2026-09-29T17:54:09Z"
    },
    {
      "id": "CVE-2026-64731",
      "url": "https://labs.diras.sa/cve/cve-2026-64731/",
      "title": "MacOS path handling sandbox escape",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00611,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: install the vendor updates because Apple fixed this sandbox escape in 15.7.8 and 26.6; an app running locally can exploit the flaw to break out of its sandbox. Prioritise patching desktops that allow third-party app installation.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64731",
        "https://www.cve.org/CVERecord?id=CVE-2026-64731",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071"
      ],
      "published": "2026-09-29T17:53:51Z",
      "updated": "2026-09-29T17:53:51Z"
    },
    {
      "id": "CVE-2026-64746",
      "url": "https://labs.diras.sa/cve/cve-2026-64746/",
      "title": "IOS and iPadOS authorization bypass lets apps add contacts",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-862",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0056,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent — Apple shipped fixes (18.7.10 and 26.6) because an installed app can modify contacts without consent; update devices running affected releases immediately or block installation of untrusted apps until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64746",
        "https://www.cve.org/CVERecord?id=CVE-2026-64746",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:53:35Z",
      "updated": "2026-09-29T17:53:35Z"
    },
    {
      "id": "CVE-2026-64751",
      "url": "https://labs.diras.sa/cve/cve-2026-64751/",
      "title": "IOS and iPadOS use-after-free remote code execution",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00588,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent — apply Apple’s 26.6 updates immediately because the flaw permits remote code execution without authentication or user interaction, allowing attackers to reach kernel memory from network access.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64751",
        "https://www.cve.org/CVERecord?id=CVE-2026-64751",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070"
      ],
      "published": "2026-09-29T17:53:24Z",
      "updated": "2026-09-29T17:53:24Z"
    },
    {
      "id": "CVE-2026-64767",
      "url": "https://labs.diras.sa/cve/cve-2026-64767/",
      "title": "MacOS buffer overflow pre-auth remote code execution",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-120",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0078,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent — this flaw allows remote, unauthenticated code execution or kernel corruption (no login needed), so prioritize patching systems exposed to untrusted networks and apply vendor updates immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64767",
        "https://www.cve.org/CVERecord?id=CVE-2026-64767",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072"
      ],
      "published": "2026-09-29T17:53:13Z",
      "updated": "2026-09-29T17:53:13Z"
    },
    {
      "id": "CVE-2026-64762",
      "url": "https://labs.diras.sa/cve/cve-2026-64762/",
      "title": "IOS and iPadOS out-of-bounds read may cause system termination",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00605,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: install the vendor fixes as soon as possible — Apple released updates that fix the bug in iOS/iPadOS 18.7.10 and macOS 14.8.8, 15.7.8, and 26.6. The strongest fact: vendor-supplied fixes are available for the listed branches.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64762",
        "https://www.cve.org/CVERecord?id=CVE-2026-64762",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:53:02Z",
      "updated": "2026-09-29T17:53:02Z"
    },
    {
      "id": "CVE-2026-64774",
      "url": "https://labs.diras.sa/cve/cve-2026-64774/",
      "title": "IOS and iPadOS integer overflow leads to remote heap corruption",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-190",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00801,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Treat this as high priority and apply Apple’s updates now: fixed builds are available for iOS/iPadOS 18.7.10 and 26.6 and for several macOS, tvOS and visionOS releases; patch internet-facing and high-value devices first.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64774",
        "https://www.cve.org/CVERecord?id=CVE-2026-64774",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:52:49Z",
      "updated": "2026-09-29T17:52:49Z"
    },
    {
      "id": "CVE-2026-64775",
      "url": "https://labs.diras.sa/cve/cve-2026-64775/",
      "title": "IOS and iPadOS memory initialization flaw allows remote code execution",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-665",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00665,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: this is exploitable without authentication or user interaction, so apply vendor updates immediately to eliminate remote code execution risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64775",
        "https://www.cve.org/CVERecord?id=CVE-2026-64775",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072"
      ],
      "published": "2026-09-29T17:52:31Z",
      "updated": "2026-09-29T17:52:31Z"
    },
    {
      "id": "CVE-2026-64770",
      "url": "https://labs.diras.sa/cve/cve-2026-64770/",
      "title": "IOS and iPadOS out-of-bounds write may allow remote impact",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00801,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Treat this as high priority: the vulnerability scores 9.8 and is reachable remotely without privileges or user interaction, so apply the vendor fixes promptly to internet-exposed devices.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64770",
        "https://www.cve.org/CVERecord?id=CVE-2026-64770",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:52:21Z",
      "updated": "2026-09-29T17:52:21Z"
    },
    {
      "id": "CVE-2026-64772",
      "url": "https://labs.diras.sa/cve/cve-2026-64772/",
      "title": "IOS and iPadOS out-of-bounds write remote code execution",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00783,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: exploitability is higher because the flaw requires no privileges or user interaction (PR:N, UI:N). Apply the vendor updates immediately to remove exposed attack surface.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64772",
        "https://www.cve.org/CVERecord?id=CVE-2026-64772",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:52:09Z",
      "updated": "2026-09-29T17:52:09Z"
    },
    {
      "id": "CVE-2026-64769",
      "url": "https://labs.diras.sa/cve/cve-2026-64769/",
      "title": "IOS and iPadOS out-of-bounds write allows remote code execution",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00801,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent — this is a network-accessible, unauthenticated vulnerability that can result in remote code execution; apply the vendor fixes immediately to exposed devices (no login or user action required).",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64769",
        "https://www.cve.org/CVERecord?id=CVE-2026-64769",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:51:57Z",
      "updated": "2026-09-29T17:51:57Z"
    },
    {
      "id": "CVE-2026-64771",
      "url": "https://labs.diras.sa/cve/cve-2026-64771/",
      "title": "IOS and iPadOS buffer overflow allows remote code execution",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00847,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Patch immediately: the flaw is remotely exploitable without authentication or user interaction, and vendor fixes are available for the affected branches.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64771",
        "https://www.cve.org/CVERecord?id=CVE-2026-64771",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:51:45Z",
      "updated": "2026-09-29T17:51:45Z"
    },
    {
      "id": "CVE-2026-12940",
      "url": "https://labs.diras.sa/cve/cve-2026-12940/",
      "title": "Langflow OSS environment-variable RCE in MCP stdio launcher",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00943,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.10.1",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize reducing internet exposure and applying vendor guidance or mitigations immediately to vulnerable Langflow OSS instances.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-12940",
        "https://www.cve.org/CVERecord?id=CVE-2026-12940",
        "https://www.ibm.com/support/pages/node/7279995"
      ],
      "published": "2026-09-29T17:51:32Z",
      "updated": "2026-09-29T17:51:32Z"
    },
    {
      "id": "CVE-2026-68771",
      "url": "https://labs.diras.sa/cve/cve-2026-68771/",
      "title": "ComfyUI unsafe deserialization pre-auth remote code execution",
      "vendor": "Comfy-Org",
      "product": "ComfyUI",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01148,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "0.x",
          "affected": "0.23.0 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so treat this as high priority and apply the vendor's remediation or block the vulnerable upload/processing flow immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-68771",
        "https://www.cve.org/CVERecord?id=CVE-2026-68771",
        "https://github.com/Comfy-Org/ComfyUI/pull/14543",
        "https://github.com/Comfy-Org/ComfyUI",
        "https://github.com/Comfy-Org/ComfyUI/commit/94ee49b1612824366a8631ea069b2a1fa5c73720",
        "https://www.vulncheck.com/advisories/comfyui-unauthenticated-rce-via-loadtrainingdataset-pickle-deserialization"
      ],
      "published": "2026-09-29T17:51:15Z",
      "updated": "2026-09-29T17:51:15Z"
    },
    {
      "id": "CVE-2026-8457",
      "url": "https://labs.diras.sa/cve/cve-2026-8457/",
      "title": "WooCommerce - Social Login authentication bypass lets attackers assume accounts",
      "vendor": "WPWeb",
      "product": "WooCommerce - Social Login",
      "cwe": "CWE-289",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00704,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.8.7 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is critical because the flaw lets unauthenticated actors obtain administrator sessions; immediately remove or disable the Apple social-login provider or the plugin until a vendor fix is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-8457",
        "https://www.cve.org/CVERecord?id=CVE-2026-8457",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/53e83037-2cc5-4dc9-b55d-03829df12a65?source=cve",
        "https://codecanyon.net/item/social-login-wordpress-woocommerce-plugin/8495883"
      ],
      "published": "2026-09-29T17:51:01Z",
      "updated": "2026-09-29T17:51:01Z"
    },
    {
      "id": "CVE-2026-0163",
      "url": "https://labs.diras.sa/cve/cve-2026-0163/",
      "title": "Android kernel use-after-free lets remote attackers escalate privileges",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00382,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "Android",
          "affected": "Android kernel",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists while no patch is available, so prioritize reducing exposure of Android devices, applying any vendor mitigations, and increasing detection for kernel compromise.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-0163",
        "https://www.cve.org/CVERecord?id=CVE-2026-0163",
        "https://source.android.com/docs/security/bulletin/pixel/2026/2026-08-01"
      ],
      "published": "2026-09-29T17:50:44Z",
      "updated": "2026-09-29T17:50:44Z"
    },
    {
      "id": "CVE-2026-20272",
      "url": "https://labs.diras.sa/cve/cve-2026-20272/",
      "title": "Cisco IOS XE improper neutralization (CWE-74) pre-auth remote code execution",
      "vendor": "Cisco",
      "product": "Cisco IOS XE Software",
      "cwe": "CWE-74",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00573,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "17.x",
          "affected": "17.2.1a",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16.12.1y",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16.12.3s",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16.7.1b",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16.6.2",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16.6.5",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16.12.1w",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16.9.1d",
          "fixed": null
        },
        {
          "branch": "17.x",
          "affected": "17.3.1",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16.9.4c",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — this is a remote, no-authentication code-execution flaw, meaning internet-exposed Cisco IOS XE devices are high priority to isolate or mitigate immediately. Prioritize removing external exposure and preparing to apply vendor fixes as soon as they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20272",
        "https://www.cve.org/CVERecord?id=CVE-2026-20272",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ"
      ],
      "published": "2026-09-29T17:50:31Z",
      "updated": "2026-09-29T17:50:31Z"
    },
    {
      "id": "CVE-2026-9205",
      "url": "https://labs.diras.sa/cve/cve-2026-9205/",
      "title": "Langflow OSS weak key derivation allows remote secret compromise",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-338",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00417,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.10.3",
          "fixed": null
        }
      ],
      "dirasTake": "High urgency: the weakness lets remote, unauthenticated attackers attack cryptographic keys (no login required), so immediately restrict external exposure and follow vendor guidance for updates or mitigations.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-9205",
        "https://www.cve.org/CVERecord?id=CVE-2026-9205",
        "https://www.ibm.com/support/pages/node/7282648"
      ],
      "published": "2026-09-29T17:50:19Z",
      "updated": "2026-09-29T17:50:19Z"
    },
    {
      "id": "CVE-2026-28005",
      "url": "https://labs.diras.sa/cve/cve-2026-28005/",
      "title": "Kadence WooCommerce Email Designer unauthenticated privilege escalation",
      "vendor": "Nexcess",
      "product": "Kadence WooCommerce Email Designer",
      "cwe": "CWE-862",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00483,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.5.19 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated privilege-escalation (no login required) that can lead to full compromise of affected sites, so isolate internet-facing installs and prioritize mitigation until a vendor update is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-28005",
        "https://www.cve.org/CVERecord?id=CVE-2026-28005",
        "https://patchstack.com/database/wordpress/plugin/kadence-woocommerce-email-designer/vulnerability/wordpress-kadence-woocommerce-email-designer-plugin-1-5-19-privilege-escalation-vulnerability?_s_id=cve"
      ],
      "published": "2026-09-29T17:50:04Z",
      "updated": "2026-09-29T17:50:04Z"
    },
    {
      "id": "CVE-2026-56793",
      "url": "https://labs.diras.sa/cve/cve-2026-56793/",
      "title": "OpenManage Server Administrator improper authentication remote access",
      "vendor": "Dell",
      "product": "OpenManage Server Administrator Managed Node (Patch) for Windows",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00532,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "OpenManage Server Administrator Managed Node (Patch) for Windows 11.x",
          "affected": "before 11.1.0.2",
          "fixed": "11.1.0.2"
        },
        {
          "branch": "Dell OpenManage Server Administrator Managed Node for RHEL 8.10 11.x",
          "affected": "before 11.1.0.2",
          "fixed": "11.1.0.2"
        },
        {
          "branch": "Dell OpenManage Server Administrator Managed Node for RHEL 9.4 11.x",
          "affected": "before 11.1.0.2",
          "fixed": "11.1.0.2"
        },
        {
          "branch": "Dell OpenManage Server Administrator Managed Node for SLES 15 11.x",
          "affected": "before 11.1.0.2",
          "fixed": "11.1.0.2"
        }
      ],
      "dirasTake": "Urgent: this is an unauthenticated remote-access vulnerability and Dell issued a fixed release (11.1.0.2); prioritize installing the update or isolating the service from untrusted networks immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-56793",
        "https://www.cve.org/CVERecord?id=CVE-2026-56793",
        "https://www.dell.com/support/kbdoc/en-us/000494958/dsa-2026-326-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilities"
      ],
      "published": "2026-09-29T17:49:53Z",
      "updated": "2026-09-29T17:49:53Z"
    },
    {
      "id": "CVE-2026-34265",
      "url": "https://labs.diras.sa/cve/cve-2026-34265/",
      "title": "SAP NetWeaver and ABAP Platform DIAG parsing memory corruption vulnerability",
      "vendor": "SAP",
      "product": "SAP NetWeaver and ABAP Platform",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00642,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "SAP NetWeaver and ABAP Platform",
          "affected": "KRNL64NUC 7.22",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.22EXT",
          "fixed": null
        },
        {
          "branch": "SAP NetWeaver and ABAP Platform",
          "affected": "KRNL64UC 7.22",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.22EXT2",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.22EXT3",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.53",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.54",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.77",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.89",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.93",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a high-impact, pre-auth network flaw with no vendor fixes reported; prioritize isolating and reducing exposure of affected NetWeaver/ABAP instances until a patch is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-34265",
        "https://www.cve.org/CVERecord?id=CVE-2026-34265",
        "https://me.sap.com/notes/3714806",
        "https://url.sap/sapsecuritypatchday"
      ],
      "published": "2026-09-29T17:49:41Z",
      "updated": "2026-09-29T17:49:41Z"
    },
    {
      "id": "CVE-2026-62815",
      "url": "https://labs.diras.sa/cve/cve-2026-62815/",
      "title": "Windows 11 use-after-free in Microsoft QUIC allows remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9168",
          "fixed": "10.0.26100.9168"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9168",
          "fixed": "10.0.26200.9168"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2704",
          "fixed": "10.0.28000.2704"
        },
        {
          "branch": "Windows Server 2022 10.x",
          "affected": "10.0.20348.0 – before 10.0.20348.5499",
          "fixed": "10.0.20348.5499"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33296",
          "fixed": "10.0.26100.33296"
        },
        {
          "branch": "Windows Server 2025 (Server Core installation) 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33296",
          "fixed": "10.0.26100.33296"
        }
      ],
      "dirasTake": "Patch urgently: this is a remotely exploitable, pre-auth code execution bug and Microsoft has issued fixed builds for all affected branches; prioritize deployment on internet-facing Windows 11 and Server hosts.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62815",
        "https://www.cve.org/CVERecord?id=CVE-2026-62815",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815"
      ],
      "published": "2026-09-29T17:49:31Z",
      "updated": "2026-09-29T17:49:31Z"
    },
    {
      "id": "CVE-2026-62878",
      "url": "https://labs.diras.sa/cve/cve-2026-62878/",
      "title": "Windows Server DNS stack buffer overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-121",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23338",
          "fixed": "6.3.9600.23338"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23338",
          "fixed": "6.3.9600.23338"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows Server 2022 10.x",
          "affected": "10.0.20348.0 – before 10.0.20348.5499",
          "fixed": "10.0.20348.5499"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33296",
          "fixed": "10.0.26100.33296"
        }
      ],
      "dirasTake": "Urgent—public exploit code exists for an unauthenticated remote code execution flaw in Windows DNS, so prioritize installing the vendor fixes or isolating DNS servers from untrusted networks immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62878",
        "https://www.cve.org/CVERecord?id=CVE-2026-62878",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878"
      ],
      "published": "2026-09-29T17:49:21Z",
      "updated": "2026-09-29T17:49:21Z"
    },
    {
      "id": "CVE-2026-62893",
      "url": "https://labs.diras.sa/cve/cve-2026-62893/",
      "title": "Windows Server use-after-free in Windows Deployment Services allows remote code execution",
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23338",
          "fixed": "6.3.9600.23338"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23338",
          "fixed": "6.3.9600.23338"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows Server 2022 10.x",
          "affected": "10.0.20348.0 – before 10.0.20348.5499",
          "fixed": "10.0.20348.5499"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33296",
          "fixed": "10.0.26100.33296"
        }
      ],
      "dirasTake": "Urgent: this is pre-auth remote code execution with network access required and a CVSS 9.8 rating, so prioritize installing the vendor updates that include the listed fixed builds or else restrict network exposure immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62893",
        "https://www.cve.org/CVERecord?id=CVE-2026-62893",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62893"
      ],
      "published": "2026-09-29T17:49:09Z",
      "updated": "2026-09-29T17:49:09Z"
    },
    {
      "id": "CVE-2026-65768",
      "url": "https://labs.diras.sa/cve/cve-2026-65768/",
      "title": "Microsoft Teams for Android path traversal pre-auth remote code execution",
      "vendor": "Microsoft",
      "product": "Microsoft Teams for Android",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00939,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – before 1.0.0.2026133602",
          "fixed": "1.0.0.2026133602"
        }
      ],
      "dirasTake": "Urgent: apply the vendor update to 1.0.0.2026133602 immediately because this vulnerability permits remote code execution without authentication. If you cannot update quickly, restrict network exposure of the app and increase monitoring for suspicious activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65768",
        "https://www.cve.org/CVERecord?id=CVE-2026-65768",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768"
      ],
      "published": "2026-09-29T17:48:57Z",
      "updated": "2026-09-29T17:48:57Z"
    },
    {
      "id": "CVE-2026-65791",
      "url": "https://labs.diras.sa/cve/cve-2026-65791/",
      "title": "Windows iSCSI Target heap buffer overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23338",
          "fixed": "6.3.9600.23338"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23338",
          "fixed": "6.3.9600.23338"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw allows remote code execution without authentication, so prioritize installing the vendor fixes or otherwise blocking access to the iSCSI Target Service from untrusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65791",
        "https://www.cve.org/CVERecord?id=CVE-2026-65791",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65791"
      ],
      "published": "2026-09-29T17:48:45Z",
      "updated": "2026-09-29T17:48:45Z"
    },
    {
      "id": "CVE-2026-26035",
      "url": "https://labs.diras.sa/cve/cve-2026-26035/",
      "title": "FortiWeb improper authentication allows unauthenticated administrative login",
      "vendor": "Fortinet",
      "product": "FortiWeb",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0075,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "8.x",
          "affected": "8.0.0 – 8.0.2",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.6.0 – 7.6.6",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.4.0 – 7.4.11",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0 – 7.2.12",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – 7.0.12",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because the issue lets unauthenticated actors access management interfaces without credentials, exposing full device control. Immediately limit exposure of FortiWeb management ports and follow vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-26035",
        "https://www.cve.org/CVERecord?id=CVE-2026-26035",
        "https://fortiguard.fortinet.com/psirt/FG-IR-26-158"
      ],
      "published": "2026-09-29T17:48:33Z",
      "updated": "2026-09-29T17:48:33Z"
    },
    {
      "id": "CVE-2026-19001",
      "url": "https://labs.diras.sa/cve/cve-2026-19001/",
      "title": "MongoDB BI Connector ODBC Driver buffer overflow in metadata functions",
      "vendor": "MongoDB",
      "product": "BI Connector ODBC Driver",
      "cwe": "CWE-190",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00539,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – before 1.4.9",
          "fixed": "1.4.9"
        }
      ],
      "dirasTake": "Urgent: this is exploitable without authentication or user interaction (CVSS vector shows AV:N/PR:N/UI:N); prioritize updating to 1.4.9 or apply mitigations immediately for exposed services.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-19001",
        "https://www.cve.org/CVERecord?id=CVE-2026-19001",
        "https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9"
      ],
      "published": "2026-09-29T17:48:22Z",
      "updated": "2026-09-29T17:48:22Z"
    },
    {
      "id": "CVE-2026-75003",
      "url": "https://labs.diras.sa/cve/cve-2026-75003/",
      "title": "Roundcube Webmail SVG url() bypass lets crafted images leak data",
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-669",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00578,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.6.0 – before 1.6.18",
          "fixed": "1.6.18"
        },
        {
          "branch": "1.x",
          "affected": "1.7.0 – before 1.7.3",
          "fixed": "1.7.3"
        }
      ],
      "dirasTake": "Urgent: this is a high-impact vulnerability that lets crafted SVGs evade image-blocking, so prioritize upgrading to the fixed releases or temporarily block SVG rendering from untrusted sources.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-75003",
        "https://www.cve.org/CVERecord?id=CVE-2026-75003",
        "https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3",
        "https://github.com/roundcube/roundcubemail/releases/tag/1.6.18",
        "https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b",
        "https://github.com/roundcube/roundcubemail/releases/tag/1.7.3",
        "https://github.com/roundcube/roundcubemail/commit/440277c32e6d84f3d116153af1cc8454361a8a56"
      ],
      "published": "2026-09-29T17:44:52Z",
      "updated": "2026-09-29T17:44:52Z"
    },
    {
      "id": "CVE-2026-74936",
      "url": "https://labs.diras.sa/cve/cve-2026-74936/",
      "title": "Firefox use-after-free in WebAssembly remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00592,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [],
      "dirasTake": "Urgent: public exploit code is available, so prioritize temporary mitigations and monitoring until an official fix is applied.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74936",
        "https://www.cve.org/CVERecord?id=CVE-2026-74936",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2052688",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-76/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-79/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:44:31Z",
      "updated": "2026-09-29T17:44:31Z"
    },
    {
      "id": "CVE-2026-74943",
      "url": "https://labs.diras.sa/cve/cve-2026-74943/",
      "title": "Firefox use-after-free in ImageLib allows remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00606,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [],
      "dirasTake": "Urgent: public exploit code is available and the flaw allows remote code execution with no user interaction, so prioritize containment and patching when Mozilla issues fixes.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74943",
        "https://www.cve.org/CVERecord?id=CVE-2026-74943",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2057308",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-75/",
        "https://www.mozilla.org/security/advisories/mfsa2026-76/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-79/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:44:17Z",
      "updated": "2026-09-29T17:44:17Z"
    },
    {
      "id": "CVE-2026-74940",
      "url": "https://labs.diras.sa/cve/cve-2026-74940/",
      "title": "Firefox use-after-free in Graphics: Text allows remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00606,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: treat as high priority because the vulnerability allows remote code execution with no authentication or user interaction, according to the CVSS vector. Restrict exposure of Firefox instances and prepare to apply vendor fixes as soon as they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74940",
        "https://www.cve.org/CVERecord?id=CVE-2026-74940",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2054842",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-75/",
        "https://www.mozilla.org/security/advisories/mfsa2026-76/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-79/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:44:05Z",
      "updated": "2026-09-29T17:44:05Z"
    },
    {
      "id": "CVE-2026-74944",
      "url": "https://labs.diras.sa/cve/cve-2026-74944/",
      "title": "Firefox use-after-free in DOM remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00592,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: this is a remotely triggerable, high-impact use-after-free with a CVSS 9.8 rating and no public exploit reported or vendor patch available yet; reduce exposure of internet-facing Firefox instances and prepare to apply vendor updates immediately when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74944",
        "https://www.cve.org/CVERecord?id=CVE-2026-74944",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2057778",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-76/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-79/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:43:52Z",
      "updated": "2026-09-29T17:43:52Z"
    },
    {
      "id": "CVE-2026-74964",
      "url": "https://labs.diras.sa/cve/cve-2026-74964/",
      "title": "Firefox integer overflow leads to remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-190",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00684,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as high priority: the bug allows unauthenticated remote code execution over the network and no patch is recorded in the supplied facts, so reduce exposure until vendor fixes are applied.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74964",
        "https://www.cve.org/CVERecord?id=CVE-2026-74964",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2053327",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-76/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-79/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:43:40Z",
      "updated": "2026-09-29T17:43:40Z"
    },
    {
      "id": "CVE-2026-74979",
      "url": "https://labs.diras.sa/cve/cve-2026-74979/",
      "title": "Firefox mitigation-bypass in Add-ons Manager allows pre-auth full compromise",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00525,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "High urgency: this flaw requires no authentication or user interaction, so exposed Firefox installations should be treated as high risk until vendor updates are applied.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74979",
        "https://www.cve.org/CVERecord?id=CVE-2026-74979",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2045676",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:43:27Z",
      "updated": "2026-09-29T17:43:27Z"
    },
    {
      "id": "CVE-2026-74987",
      "url": "https://labs.diras.sa/cve/cve-2026-74987/",
      "title": "Firefox memory-corruption remote attack",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00715,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "High priority — the flaw is a remote, pre-auth memory-corruption bug (no user interaction) so restrict network exposure of browsers and apply the vendor updates referenced in Mozilla's advisory immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74987",
        "https://www.cve.org/CVERecord?id=CVE-2026-74987",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1500946%2C1788109%2C2045379%2C2045380%2C2049339%2C2049393%2C2053580%2C2054662%2C2054665%2C2054673%2C2054785%2C2058645",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048797%2C2050536%2C2053272%2C2053579%2C2057115%2C2057116%2C2057130%2C2057991%2C2057995%2C2058002%2C2058008%2C2058032%2C2058102%2C2058667",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2059424",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-76/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-79/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:43:17Z",
      "updated": "2026-09-29T17:43:17Z"
    },
    {
      "id": "CVE-2026-74990",
      "url": "https://labs.diras.sa/cve/cve-2026-74990/",
      "title": "Firefox remote memory-corruption bug leads to remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00715,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Act urgently: this is a critical, remote code execution flaw with no public patch reported in the provided facts, so inventory exposed Firefox installs and reduce their attack surface immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74990",
        "https://www.cve.org/CVERecord?id=CVE-2026-74990",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045762%2C2052401%2C2058208",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045774%2C2048490%2C2050864%2C2053159%2C2053260%2C2053261%2C2053582%2C2053599%2C2053607%2C2053608%2C2053853%2C2054626%2C2054627%2C2054635%2C2054677%2C2054740%2C2054832%2C2056792%2C2057098%2C2057100%2C2057101%2C2057103%2C2057117%2C2057118%2C2058048%2C2058049%2C2058622%2C2058623%2C2058665%2C2058666%2C2059121%2C2059164%2C2059188",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-75/",
        "https://www.mozilla.org/security/advisories/mfsa2026-76/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-79/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:42:43Z",
      "updated": "2026-09-29T17:42:43Z"
    },
    {
      "id": "CVE-2026-74988",
      "url": "https://labs.diras.sa/cve/cve-2026-74988/",
      "title": "Firefox pre-auth remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00609,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as high priority: the CVSS score is critical (9.8) and no vendor patch is listed in the provided data, so limit exposure and prepare to update as soon as Mozilla publishes fixes.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74988",
        "https://www.cve.org/CVERecord?id=CVE-2026-74988",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2018164%2C2045404%2C2045507%2C2045711%2C2052403%2C2053174%2C2054643%2C2054667%2C2054671%2C2054674%2C2054687%2C2054717%2C2054761%2C2054787%2C2055676%2C2056779%2C2056781%2C2058629%2C2059019%2C2059138",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045796%2C2046734%2C2051424%2C2054721%2C2057994%2C2058094%2C2058611%2C2058615%2C2058616%2C2061315",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053153%2C2053262%2C2054763%2C2059198%2C2059224",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:42:30Z",
      "updated": "2026-09-29T17:42:30Z"
    },
    {
      "id": "CVE-2026-74989",
      "url": "https://labs.diras.sa/cve/cve-2026-74989/",
      "title": "Firefox memory-corruption remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0057,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as urgent: the flaw is rated critical (CVSS 9.8) and no patch is listed in the provided facts, so immediately apply mitigations and prepare to deploy vendor updates when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74989",
        "https://www.cve.org/CVERecord?id=CVE-2026-74989",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022257%2C2027351%2C2027380%2C2029289",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2027388%2C2029750%2C2029794%2C2043298%2C2045126%2C2049810%2C2051741",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/"
      ],
      "published": "2026-09-29T17:42:17Z",
      "updated": "2026-09-29T17:42:17Z"
    },
    {
      "id": "CVE-2026-74985",
      "url": "https://labs.diras.sa/cve/cve-2026-74985/",
      "title": "Firefox Enterprise Policies privilege escalation vulnerability",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00527,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as urgent: the issue is rated critical (CVSS 9.8) and no patch is recorded in the supplied facts, so immediately reduce exposure and follow vendor guidance when published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74985",
        "https://www.cve.org/CVERecord?id=CVE-2026-74985",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2059825",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T17:41:57Z",
      "updated": "2026-09-29T17:41:57Z"
    },
    {
      "id": "CVE-2026-73373",
      "url": "https://labs.diras.sa/cve/cve-2026-73373/",
      "title": "Joomla! CMS unrestricted SHTML upload allows remote code execution",
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00649,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Joomla! CMS 1.x",
          "affected": "1.0.0-5.4.6",
          "fixed": null
        },
        {
          "branch": "Joomla! CMS 6.x",
          "affected": "6.0.0-6.1.2",
          "fixed": null
        },
        {
          "branch": "Joomla! Framework Filesystem package 1.x",
          "affected": "1.0.0-3.3.0",
          "fixed": null
        },
        {
          "branch": "Joomla! Framework Filesystem package 4.x",
          "affected": "4.0.0-4.2.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat internet-facing Joomla! sites as high risk because unrestricted SHTML uploads can allow remote code execution without credentials; prioritize mitigation where sites accept file uploads or serve SHTML. Restrict upload endpoints and disable server-side SHTML processing until a vendor fix is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-73373",
        "https://www.cve.org/CVERecord?id=CVE-2026-73373",
        "https://www.joomla.org/",
        "https://developer.joomla.org/security-centre/1077-20260810-core-unrestricted-uploads-of-shtml-files.html"
      ],
      "published": "2026-09-29T17:41:45Z",
      "updated": "2026-09-29T17:41:45Z"
    },
    {
      "id": "CVE-2026-66682",
      "url": "https://labs.diras.sa/cve/cve-2026-66682/",
      "title": "Abandoned Cart Pro for WooCommerce unauthenticated privilege escalation",
      "vendor": "Tyche Softwares",
      "product": "Abandoned Cart Pro for WooCommerce",
      "cwe": "CWE-266",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00483,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "10.x",
          "affected": "10.4.0 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a high-impact pre-auth privilege escalation that requires no login, so treat internet-facing sites running the plugin as high priority to protect until a vendor fix is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-66682",
        "https://www.cve.org/CVERecord?id=CVE-2026-66682",
        "https://patchstack.com/database/wordpress/plugin/woocommerce-abandon-cart-pro/vulnerability/wordpress-abandoned-cart-pro-for-woocommerce-plugin-10-4-0-privilege-escalation-vulnerability-2?_s_id=cve"
      ],
      "published": "2026-09-29T17:39:44Z",
      "updated": "2026-09-29T17:39:44Z"
    },
    {
      "id": "CVE-2026-77070",
      "url": "https://labs.diras.sa/cve/cve-2026-77070/",
      "title": "N8n MongoDB node NoSQL injection lets attackers disclose or delete data",
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-943",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00511,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "before 1.123.69",
          "fixed": "1.123.69"
        },
        {
          "branch": "2.x",
          "affected": "2.34.0 – before 2.34.1",
          "fixed": "2.34.1"
        },
        {
          "branch": "2.x",
          "affected": "2.0.0 – before 2.33.4",
          "fixed": "2.33.4"
        }
      ],
      "dirasTake": "Urgent: this is a critical injection that can leak or delete large amounts of data; apply the vendor patches now or otherwise isolate MongoDB-related workflows until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77070",
        "https://www.cve.org/CVERecord?id=CVE-2026-77070",
        "https://github.com/n8n-io/n8n/security/advisories/GHSA-953p-jm2c-8h5j",
        "https://www.vulncheck.com/advisories/n8n-before-nosql-injection-via-mongodb-node"
      ],
      "published": "2026-09-29T17:39:34Z",
      "updated": "2026-09-29T17:39:34Z"
    },
    {
      "id": "CVE-2026-62834",
      "url": "https://labs.diras.sa/cve/cve-2026-62834/",
      "title": "Azure Data Factory improper signature verification allows privilege elevation",
      "vendor": "Microsoft",
      "product": "Azure Data Factory",
      "cwe": "CWE-347",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00529,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure Data Factory",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this vulnerability requires no credentials or user interaction, so exposed Azure Data Factory endpoints should be treated as high risk and remediated promptly.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62834",
        "https://www.cve.org/CVERecord?id=CVE-2026-62834",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62834"
      ],
      "published": "2026-09-29T17:38:46Z",
      "updated": "2026-09-29T17:38:46Z"
    },
    {
      "id": "CVE-2026-32558",
      "url": "https://labs.diras.sa/cve/cve-2026-32558/",
      "title": "Affiliate Pro unauthenticated privilege escalation",
      "vendor": "RedefiningTheWeb",
      "product": "Affiliate Pro - Affiliate Program for WooCommerce & WordPress",
      "cwe": "CWE-266",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00483,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "8.x",
          "affected": "8.9.1 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this vulnerability allows privilege elevation without any login on internet-facing WordPress sites; prioritize restricting exposure and applying vendor guidance when available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-32558",
        "https://www.cve.org/CVERecord?id=CVE-2026-32558",
        "https://patchstack.com/database/wordpress/plugin/wp-wc-affiliate-program/vulnerability/wordpress-affiliate-pro-affiliate-program-for-woocommerce-wordpress-plugin-8-9-1-privilege-escalation-vulnerability?_s_id=cve"
      ],
      "published": "2026-09-29T17:38:35Z",
      "updated": "2026-09-29T17:38:35Z"
    },
    {
      "id": "CVE-2026-63073",
      "url": "https://labs.diras.sa/cve/cve-2026-63073/",
      "title": "OpenSSL CMP format-string denial of service",
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-134",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01159,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "4.x",
          "affected": "4.0.0 – before 4.0.2",
          "fixed": "4.0.2"
        },
        {
          "branch": "3.x",
          "affected": "3.6.0 – before 3.6.4",
          "fixed": "3.6.4"
        },
        {
          "branch": "3.x",
          "affected": "3.5.0 – before 3.5.8",
          "fixed": "3.5.8"
        },
        {
          "branch": "3.x",
          "affected": "3.4.0 – before 3.4.7",
          "fixed": "3.4.7"
        }
      ],
      "dirasTake": "Urgent: apply vendor updates or mitigations since an attacker controlling or intercepting a CMP endpoint can trigger a crash without authentication.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-63073",
        "https://www.cve.org/CVERecord?id=CVE-2026-63073",
        "https://openssl-library.org/news/secadv/20260825.txt",
        "https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21",
        "https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29",
        "https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca",
        "https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4"
      ],
      "published": "2026-09-29T17:38:18Z",
      "updated": "2026-09-29T17:38:18Z"
    },
    {
      "id": "CVE-2026-79090",
      "url": "https://labs.diras.sa/cve/cve-2026-79090/",
      "title": "Chrome improper privilege management lets remote attacker bypass access",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00419,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.65 – before 152.0.7977.65",
          "fixed": "152.0.7977.65"
        }
      ],
      "dirasTake": "Urgent: update Chrome to 152.0.7977.65 immediately — the flaw lets an attacker bypass access controls if a user loads a crafted page, so treat exposed or user-facing browsers as high priority.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-79090",
        "https://www.cve.org/CVERecord?id=CVE-2026-79090",
        "https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html",
        "https://issues.chromium.org/issues/517673944"
      ],
      "published": "2026-09-29T17:38:06Z",
      "updated": "2026-09-29T17:38:06Z"
    },
    {
      "id": "CVE-2026-79152",
      "url": "https://labs.diras.sa/cve/cve-2026-79152/",
      "title": "Chrome CustomTabs authorization bypass via co-installed app",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00321,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.65 – before 152.0.7977.65",
          "fixed": "152.0.7977.65"
        }
      ],
      "dirasTake": "Urgently update Chrome on Android to 152.0.7977.65 because a vendor fix is available; this prevents local apps from exploiting the incorrect authorization in CustomTabs.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-79152",
        "https://www.cve.org/CVERecord?id=CVE-2026-79152",
        "https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html",
        "https://issues.chromium.org/issues/533083384"
      ],
      "published": "2026-09-29T17:37:55Z",
      "updated": "2026-09-29T17:37:55Z"
    },
    {
      "id": "CVE-2026-65637",
      "url": "https://labs.diras.sa/cve/cve-2026-65637/",
      "title": "Apache Tomcat improper input validation allows remote code execution",
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00738,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "11.x",
          "affected": "11.0.20 – 11.0.24",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.1.53 – 10.1.57",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.0.115 – 9.0.120",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent — the flaw enables remote, unauthenticated code execution against exposed Tomcat services and no fixed versions are listed in the supplied data; immediately reduce exposure and watch for vendor patches.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65637",
        "https://www.cve.org/CVERecord?id=CVE-2026-65637",
        "https://lists.apache.org/thread/djog953z1ohsyt25bdvhfzbmsy22vgcj"
      ],
      "published": "2026-09-29T17:37:16Z",
      "updated": "2026-09-29T17:37:16Z"
    },
    {
      "id": "CVE-2026-16639",
      "url": "https://labs.diras.sa/cve/cve-2026-16639/",
      "title": "Internationalization Single Sign-On authentication bypass",
      "vendor": "Drupal",
      "product": "Internationalization Single Sign-On",
      "cwe": "CWE-288",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00366,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "before 1.8.0",
          "fixed": "1.8.0"
        }
      ],
      "dirasTake": "Treat this as high urgency: the flaw permits bypass without any login and a vendor fix (1.8.0) is available, so prioritize upgrades or immediate exposure restrictions.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-16639",
        "https://www.cve.org/CVERecord?id=CVE-2026-16639",
        "https://www.drupal.org/sa-contrib-2026-081"
      ],
      "published": "2026-09-29T17:36:58Z",
      "updated": "2026-09-29T17:36:58Z"
    },
    {
      "id": "CVE-2026-16641",
      "url": "https://labs.diras.sa/cve/cve-2026-16641/",
      "title": "Commerce Elavon input validation flaw allows unauthenticated remote compromise",
      "vendor": "Drupal",
      "product": "Commerce Elavon",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0029,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Commerce Elavon",
          "affected": "*.*",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is an unauthenticated, remotely reachable vulnerability affecting all Commerce Elavon releases, so immediately limit exposure and prepare to apply vendor guidance once a fix is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-16641",
        "https://www.cve.org/CVERecord?id=CVE-2026-16641",
        "https://www.drupal.org/sa-contrib-2026-084"
      ],
      "published": "2026-09-29T17:36:42Z",
      "updated": "2026-09-29T17:36:42Z"
    },
    {
      "id": "CVE-2026-47890",
      "url": "https://labs.diras.sa/cve/cve-2026-47890/",
      "title": "Spring Framework SSE stream corruption",
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-93",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00564,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.0.0 – 7.0.8",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.2.0 – 6.2.19",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority: the vulnerability has a critical CVSS 9.8 rating and no fix is currently listed for affected Spring Framework branches. If your applications use SSE with view fragments, reduce exposure and prepare to patch as soon as vendor fixes are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-47890",
        "https://www.cve.org/CVERecord?id=CVE-2026-47890",
        "https://spring.io/security/cve-2026-47890"
      ],
      "published": "2026-09-29T17:35:35Z",
      "updated": "2026-09-29T17:35:35Z"
    },
    {
      "id": "CVE-2026-47891",
      "url": "https://labs.diras.sa/cve/cve-2026-47891/",
      "title": "Spring Framework Aalto XML maxInMemorySize bypass",
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-770",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00522,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.0.0 – 7.0.8",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.2.0 – 6.2.19",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.1.0 – 6.1.28",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.0.0 – 6.0.30",
          "fixed": null
        },
        {
          "branch": "5.x",
          "affected": "5.3.0 – 5.3.49",
          "fixed": null
        },
        {
          "branch": "5.x",
          "affected": "5.2.25.RELEASE and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this allows unauthenticated XML input to drive excessive memory use; immediately restrict access to XML-parsing endpoints and apply request limits while awaiting vendor remediation.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-47891",
        "https://www.cve.org/CVERecord?id=CVE-2026-47891",
        "https://spring.io/security/cve-2026-47891"
      ],
      "published": "2026-09-29T17:35:18Z",
      "updated": "2026-09-29T17:35:18Z"
    },
    {
      "id": "CVE-2026-59313",
      "url": "https://labs.diras.sa/cve/cve-2026-59313/",
      "title": "Spring Framework stream corruption in SSE",
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-93",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00564,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.0.0 – 7.0.8",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.2.0 – 6.2.19",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.1.0 – 6.1.28",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.0.0 – 6.0.30",
          "fixed": null
        },
        {
          "branch": "5.x",
          "affected": "5.3.0 – 5.3.49",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this flaw can be triggered without authentication or user interaction, so internet-facing SSE endpoints should be treated as high priority to protect and mitigate immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-59313",
        "https://www.cve.org/CVERecord?id=CVE-2026-59313",
        "https://spring.io/security/cve-2026-59313"
      ],
      "published": "2026-09-29T17:34:03Z",
      "updated": "2026-09-29T17:34:03Z"
    },
    {
      "id": "CVE-2026-19286",
      "url": "https://labs.diras.sa/cve/cve-2026-19286/",
      "title": "Langflow OSS A2A endpoint remote code execution",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00799,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.11.1",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this pre-auth RCE, so immediately remove or restrict external access to the A2A endpoint and apply the vendor remediation as soon as possible.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-19286",
        "https://www.cve.org/CVERecord?id=CVE-2026-19286",
        "https://www.ibm.com/support/pages/node/7284733"
      ],
      "published": "2026-09-29T17:33:21Z",
      "updated": "2026-09-29T17:33:21Z"
    },
    {
      "id": "CVE-2026-84129",
      "url": "https://labs.diras.sa/cve/cve-2026-84129/",
      "title": "Firefox site-isolation navigation vulnerability allows remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00291,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "High priority: this is a remote, pre-auth code-execution issue (CVSS 9.8) and no patch is listed in the provided data, so immediately limit exposure and follow Mozilla mitigation guidance when available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84129",
        "https://www.cve.org/CVERecord?id=CVE-2026-84129",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2055028",
        "https://www.mozilla.org/security/advisories/mfsa2026-82/",
        "https://www.mozilla.org/security/advisories/mfsa2026-85/",
        "https://www.mozilla.org/security/advisories/mfsa2026-86/",
        "https://www.mozilla.org/security/advisories/mfsa2026-88/"
      ],
      "published": "2026-09-29T17:32:40Z",
      "updated": "2026-09-29T17:32:40Z"
    },
    {
      "id": "CVE-2026-84135",
      "url": "https://labs.diras.sa/cve/cve-2026-84135/",
      "title": "Firefox remote code execution via input-validation flaw",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00449,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: this is a critical, pre-auth remote code execution with no patch listed in the facts; immediately reduce exposure for internet-facing Firefox installs and prepare to apply vendor updates as soon as they are published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84135",
        "https://www.cve.org/CVERecord?id=CVE-2026-84135",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2046661",
        "https://www.mozilla.org/security/advisories/mfsa2026-82/"
      ],
      "published": "2026-09-29T17:32:13Z",
      "updated": "2026-09-29T17:32:13Z"
    },
    {
      "id": "CVE-2026-84134",
      "url": "https://labs.diras.sa/cve/cve-2026-84134/",
      "title": "Firefox information disclosure unauthenticated (CWE-200)",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0057,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as high urgency: the vulnerability scores 9.8 and the supplied facts show no available patch, so reduce exposure and prepare to apply vendor fixes as soon as they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84134",
        "https://www.cve.org/CVERecord?id=CVE-2026-84134",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2044882",
        "https://www.mozilla.org/security/advisories/mfsa2026-82/",
        "https://www.mozilla.org/security/advisories/mfsa2026-85/",
        "https://www.mozilla.org/security/advisories/mfsa2026-86/",
        "https://www.mozilla.org/security/advisories/mfsa2026-88/"
      ],
      "published": "2026-09-29T17:32:00Z",
      "updated": "2026-09-29T17:32:00Z"
    },
    {
      "id": "CVE-2026-84133",
      "url": "https://labs.diras.sa/cve/cve-2026-84133/",
      "title": "Firefox site isolation bypass in DOM Push Subscriptions component",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00291,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as urgent: the flaw affects a browser component and the CVSS score is 9.8, and there is no patch available in the provided facts — prioritize exposure reduction and monitoring immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84133",
        "https://www.cve.org/CVERecord?id=CVE-2026-84133",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2032388",
        "https://www.mozilla.org/security/advisories/mfsa2026-82/",
        "https://www.mozilla.org/security/advisories/mfsa2026-85/",
        "https://www.mozilla.org/security/advisories/mfsa2026-86/",
        "https://www.mozilla.org/security/advisories/mfsa2026-88/"
      ],
      "published": "2026-09-29T17:31:48Z",
      "updated": "2026-09-29T17:31:48Z"
    },
    {
      "id": "CVE-2026-84142",
      "url": "https://labs.diras.sa/cve/cve-2026-84142/",
      "title": "Firefox memory corruption pre-auth remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00561,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: this is a remotely triggerable, no-authentication memory-corruption bug (CVSS 9.8) that can lead to full compromise; prioritize reducing exposure and applying vendor updates as soon as they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84142",
        "https://www.cve.org/CVERecord?id=CVE-2026-84142",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029421%2C2040889%2C2045313%2C2045435%2C2053578%2C2058621%2C2058626",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048796%2C2053150%2C2057356",
        "https://www.mozilla.org/security/advisories/mfsa2026-82/",
        "https://www.mozilla.org/security/advisories/mfsa2026-86/"
      ],
      "published": "2026-09-29T17:31:35Z",
      "updated": "2026-09-29T17:31:35Z"
    },
    {
      "id": "CVE-2026-84140",
      "url": "https://labs.diras.sa/cve/cve-2026-84140/",
      "title": "Firefox site isolation navigation pre-auth remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00286,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: this is a remotely reachable RCE that requires no authentication, and vendor fixes are recorded for Firefox 155 and ESR 153.2; prioritize reducing exposure and applying vendor updates when available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84140",
        "https://www.cve.org/CVERecord?id=CVE-2026-84140",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2063780",
        "https://www.mozilla.org/security/advisories/mfsa2026-82/",
        "https://www.mozilla.org/security/advisories/mfsa2026-85/",
        "https://www.mozilla.org/security/advisories/mfsa2026-86/",
        "https://www.mozilla.org/security/advisories/mfsa2026-88/"
      ],
      "published": "2026-09-29T17:31:20Z",
      "updated": "2026-09-29T17:31:20Z"
    },
    {
      "id": "CVE-2026-84141",
      "url": "https://labs.diras.sa/cve/cve-2026-84141/",
      "title": "Firefox integer overflow in ImageLib component",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-190",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0063,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: this is a critical (CVSS 9.8) remote flaw with no vendor patch currently available, so prioritize reducing exposure of Firefox clients and preparing to apply Mozilla updates as soon as they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84141",
        "https://www.cve.org/CVERecord?id=CVE-2026-84141",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2063994",
        "https://www.mozilla.org/security/advisories/mfsa2026-82/",
        "https://www.mozilla.org/security/advisories/mfsa2026-85/",
        "https://www.mozilla.org/security/advisories/mfsa2026-86/",
        "https://www.mozilla.org/security/advisories/mfsa2026-88/"
      ],
      "published": "2026-09-29T17:31:03Z",
      "updated": "2026-09-29T17:31:03Z"
    },
    {
      "id": "CVE-2026-84143",
      "url": "https://labs.diras.sa/cve/cve-2026-84143/",
      "title": "Firefox memory-corruption remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00378,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as high urgency because the flaw allows unauthenticated remote code execution over the network with no user interaction required, and memory-corruption issues are frequently exploitable.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84143",
        "https://www.cve.org/CVERecord?id=CVE-2026-84143",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048793%2C2054645%2C2057114%2C2059109%2C2061287",
        "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054631%2C2054657%2C2055007%2C2055681%2C2057107%2C2058087%2C2058088%2C2058090%2C2058095%2C2058101%2C2059183%2C2059185%2C2061301%2C2061325",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2057108",
        "https://www.mozilla.org/security/advisories/mfsa2026-82/",
        "https://www.mozilla.org/security/advisories/mfsa2026-84/",
        "https://www.mozilla.org/security/advisories/mfsa2026-85/",
        "https://www.mozilla.org/security/advisories/mfsa2026-86/",
        "https://www.mozilla.org/security/advisories/mfsa2026-87/",
        "https://www.mozilla.org/security/advisories/mfsa2026-88/"
      ],
      "published": "2026-09-29T17:30:43Z",
      "updated": "2026-09-29T17:30:43Z"
    },
    {
      "id": "CVE-2026-84325",
      "url": "https://labs.diras.sa/cve/cve-2026-84325/",
      "title": "Chrome DataTransfer input validation bypass allows system-access bypass",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00402,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.75 – before 152.0.7977.75",
          "fixed": "152.0.7977.75"
        }
      ],
      "dirasTake": "High urgency: this is a critical (CVSS 9.8) remote input‑validation flaw with a vendor fix available; update Chrome to 152.0.7977.75 as soon as possible.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84325",
        "https://www.cve.org/CVERecord?id=CVE-2026-84325",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html",
        "https://issues.chromium.org/issues/553117928"
      ],
      "published": "2026-09-29T17:30:28Z",
      "updated": "2026-09-29T17:30:28Z"
    },
    {
      "id": "CVE-2026-20274",
      "url": "https://labs.diras.sa/cve/cve-2026-20274/",
      "title": "Cisco IOS XR Software improper resource control vulnerability",
      "vendor": "Cisco",
      "product": "Cisco IOS XR Software",
      "cwe": "CWE-664",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00731,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "6.x",
          "affected": "6.5.29",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.5.26",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.5.25",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.5.28",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.5.90",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.1.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.90",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.7.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because the vulnerability allows remote, unauthenticated network access and carries a CVSS 9.8 rating; act now to reduce exposure and monitor devices while Cisco publishes fixes or guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20274",
        "https://www.cve.org/CVERecord?id=CVE-2026-20274",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM"
      ],
      "published": "2026-09-29T17:30:16Z",
      "updated": "2026-09-29T17:30:16Z"
    },
    {
      "id": "CVE-2026-20279",
      "url": "https://labs.diras.sa/cve/cve-2026-20279/",
      "title": "Cisco IOS XR Software improper access control pre-auth remote code execution",
      "vendor": "Cisco",
      "product": "Cisco IOS XR Software",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00301,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "6.x",
          "affected": "6.5.29",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.5.26",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.5.25",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.5.28",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.5.90",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.1.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.90",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.7.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high urgency: the flaw allows unauthenticated remote code execution over the network, so immediately limit device exposure and prepare to apply vendor fixes when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20279",
        "https://www.cve.org/CVERecord?id=CVE-2026-20279",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM"
      ],
      "published": "2026-09-29T17:29:56Z",
      "updated": "2026-09-29T17:29:56Z"
    },
    {
      "id": "CVE-2026-84238",
      "url": "https://labs.diras.sa/cve/cve-2026-84238/",
      "title": "YITH Request a Quote for WooCommerce Premium unauthenticated broken access control",
      "vendor": "YITH",
      "product": "YITH Request a Quote for WooCommerce Premium",
      "cwe": "CWE-862",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00483,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "4.x",
          "affected": "before 4.46.0",
          "fixed": "4.46.0"
        }
      ],
      "dirasTake": "Urgent: this is a remotely reachable, unauthenticated access-control bypass with a 9.8 CVSS score; prioritize updating because the vendor released a fixed 4.46.0 build.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84238",
        "https://www.cve.org/CVERecord?id=CVE-2026-84238",
        "https://patchstack.com/database/wordpress/plugin/yith-woocommerce-request-a-quote-premium/vulnerability/wordpress-yith-request-a-quote-for-woocommerce-premium-plugin-4-46-0-broken-access-control-vulnerability?_s_id=cve"
      ],
      "published": "2026-09-29T17:29:39Z",
      "updated": "2026-09-29T17:29:39Z"
    },
    {
      "id": "CVE-2026-58240",
      "url": "https://labs.diras.sa/cve/cve-2026-58240/",
      "title": "SAP NetWeaver Message Server component registration bypass allows unauthorized actions",
      "vendor": "SAP",
      "product": "SAP NetWeaver (Message Server)",
      "cwe": "CWE-308",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00528,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "SAP NetWeaver (Message Server)",
          "affected": "KERNEL 9.16",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.18",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.19",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.20",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a network-accessible, unauthenticated flaw with a high-severity impact (CVSS 9.8), so restrict exposure of Message Server interfaces immediately and prioritize vendor fixes when available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-58240",
        "https://www.cve.org/CVERecord?id=CVE-2026-58240",
        "https://me.sap.com/notes/3759472",
        "https://url.sap/sapsecuritypatchday"
      ],
      "published": "2026-09-29T17:29:27Z",
      "updated": "2026-09-29T17:29:27Z"
    },
    {
      "id": "CVE-2026-68839",
      "url": "https://labs.diras.sa/cve/cve-2026-68839/",
      "title": "Windows USB Mass Storage heap overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01022,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent — this is a network-accessible, unauthenticated remote code execution vulnerability with a CVSS 9.8 and vendor fixes available; prioritize applying the provided fixed builds or block exposure of affected systems until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-68839",
        "https://www.cve.org/CVERecord?id=CVE-2026-68839",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68839"
      ],
      "published": "2026-09-29T17:29:15Z",
      "updated": "2026-09-29T17:29:15Z"
    },
    {
      "id": "CVE-2026-69276",
      "url": "https://labs.diras.sa/cve/cve-2026-69276/",
      "title": "Windows UxTheme integer underflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00996,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent — this is an unauthenticated remote code execution bug in a network-reachable Windows component; apply Microsoft’s updates to the fixed builds immediately or otherwise isolate vulnerable hosts from untrusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69276",
        "https://www.cve.org/CVERecord?id=CVE-2026-69276",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69276"
      ],
      "published": "2026-09-29T17:29:02Z",
      "updated": "2026-09-29T17:29:02Z"
    },
    {
      "id": "CVE-2026-69408",
      "url": "https://labs.diras.sa/cve/cve-2026-69408/",
      "title": "Windows 10 Version 1607 integer overflow in Media Foundation allows remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a network-accessible, no-auth remote code execution with critical impact and vendor fixes released; prioritize applying the supplied security updates to affected builds immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69408",
        "https://www.cve.org/CVERecord?id=CVE-2026-69408",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69408"
      ],
      "published": "2026-09-29T17:28:38Z",
      "updated": "2026-09-29T17:28:38Z"
    },
    {
      "id": "CVE-2026-69431",
      "url": "https://labs.diras.sa/cve/cve-2026-69431/",
      "title": "Windows Telnet Client heap-based buffer overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00996,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated code execution bug (CVSS 9.8) that can be triggered over the network, so prioritize installing the vendor fixes for the listed builds or otherwise block Telnet exposure.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69431",
        "https://www.cve.org/CVERecord?id=CVE-2026-69431",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69431"
      ],
      "published": "2026-09-29T17:28:22Z",
      "updated": "2026-09-29T17:28:22Z"
    },
    {
      "id": "CVE-2026-69463",
      "url": "https://labs.diras.sa/cve/cve-2026-69463/",
      "title": "Windows NTFS heap overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a network-facing, no-authentication remote code execution flaw (CVSS 9.8) — prioritize applying the vendor fixes for the listed builds and block unnecessary NTFS network exposure.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69463",
        "https://www.cve.org/CVERecord?id=CVE-2026-69463",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69463"
      ],
      "published": "2026-09-29T17:28:07Z",
      "updated": "2026-09-29T17:28:07Z"
    },
    {
      "id": "CVE-2026-69491",
      "url": "https://labs.diras.sa/cve/cve-2026-69491/",
      "title": "Windows 10 Version 1607 heap buffer overflow in DirectMusic allows remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: treat this as high priority to patch because the flaw allows unauthenticated remote code execution over the network (CVSS 9.8). Apply the vendor fixes immediately to exposed systems.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69491",
        "https://www.cve.org/CVERecord?id=CVE-2026-69491",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69491"
      ],
      "published": "2026-09-29T17:27:51Z",
      "updated": "2026-09-29T17:27:51Z"
    },
    {
      "id": "CVE-2026-69493",
      "url": "https://labs.diras.sa/cve/cve-2026-69493/",
      "title": "Windows 10 Event Logging out-of-bounds remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Treat this as high priority: the bug allows unauthenticated remote code execution over the network, so apply Microsoft's fixed builds or mitigations promptly to internet-exposed and critical hosts.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69493",
        "https://www.cve.org/CVERecord?id=CVE-2026-69493",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69493"
      ],
      "published": "2026-09-29T17:27:40Z",
      "updated": "2026-09-29T17:27:40Z"
    },
    {
      "id": "CVE-2026-69496",
      "url": "https://labs.diras.sa/cve/cve-2026-69496/",
      "title": "Windows Compressed Folder heap overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is high-severity, remotely triggerable code execution with no authentication required, so prioritize patching to the fixed builds Microsoft published immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69496",
        "https://www.cve.org/CVERecord?id=CVE-2026-69496",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69496"
      ],
      "published": "2026-09-29T17:27:26Z",
      "updated": "2026-09-29T17:27:26Z"
    },
    {
      "id": "CVE-2026-69525",
      "url": "https://labs.diras.sa/cve/cve-2026-69525/",
      "title": "Windows Remote Desktop Services use-after-free remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a critical, pre-auth RDP code execution bug with public fixes available; prioritize installing the vendor updates that move systems to the fixed builds listed below or otherwise block/unexpose RDP from untrusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69525",
        "https://www.cve.org/CVERecord?id=CVE-2026-69525",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69525"
      ],
      "published": "2026-09-29T17:27:09Z",
      "updated": "2026-09-29T17:27:09Z"
    },
    {
      "id": "CVE-2026-69579",
      "url": "https://labs.diras.sa/cve/cve-2026-69579/",
      "title": "Windows Message Queuing use-after-free remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgently prioritize patching because this is an unauthenticated, network-accessible remote code execution (CVSS 9.8) that lets attackers run code without a login. Apply the supplied fixed builds to exposed systems immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69579",
        "https://www.cve.org/CVERecord?id=CVE-2026-69579",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69579"
      ],
      "published": "2026-09-29T17:26:56Z",
      "updated": "2026-09-29T17:26:56Z"
    },
    {
      "id": "CVE-2026-69586",
      "url": "https://labs.diras.sa/cve/cve-2026-69586/",
      "title": "Windows 10 Version 1607 integer overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        }
      ],
      "dirasTake": "Patch urgently: this is an unauthenticated remote code execution vulnerability that can be reached over the network, so apply the vendor updates for the fixed builds immediately or block exposure to untrusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69586",
        "https://www.cve.org/CVERecord?id=CVE-2026-69586",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69586"
      ],
      "published": "2026-09-29T17:26:41Z",
      "updated": "2026-09-29T17:26:41Z"
    },
    {
      "id": "CVE-2026-69590",
      "url": "https://labs.diras.sa/cve/cve-2026-69590/",
      "title": "Windows 10 Version 1607 RRAS remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a remotely exploitable, pre-auth RCE with a critical 9.8 CVSS and vendor fixes available — prioritize installing the listed updates or isolating RRAS from untrusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69590",
        "https://www.cve.org/CVERecord?id=CVE-2026-69590",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69590"
      ],
      "published": "2026-09-29T17:26:28Z",
      "updated": "2026-09-29T17:26:28Z"
    },
    {
      "id": "CVE-2026-69595",
      "url": "https://labs.diras.sa/cve/cve-2026-69595/",
      "title": "Windows Server use-after-free in Services for NFS ONCRPC XDR remote code execution",
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2022 10.x",
          "affected": "10.0.20348.0 – before 10.0.20348.5622",
          "fixed": "10.0.20348.5622"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33438",
          "fixed": "10.0.26100.33438"
        }
      ],
      "dirasTake": "Urgent: this is an unauthenticated remote code execution vulnerability that can be reached over the network, so prioritize patching systems exposed to untrusted networks or internet-facing NFS services.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69595",
        "https://www.cve.org/CVERecord?id=CVE-2026-69595",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69595"
      ],
      "published": "2026-09-29T17:26:12Z",
      "updated": "2026-09-29T17:26:12Z"
    },
    {
      "id": "CVE-2026-69715",
      "url": "https://labs.diras.sa/cve/cve-2026-69715/",
      "title": "Windows DirectShow out-of-bounds read remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth, network-triggered remote code execution (CVSS 9.8) that requires no login or user action, so prioritize applying the provided security updates for the fixed builds.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69715",
        "https://www.cve.org/CVERecord?id=CVE-2026-69715",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69715"
      ],
      "published": "2026-09-29T17:26:00Z",
      "updated": "2026-09-29T17:26:00Z"
    },
    {
      "id": "CVE-2026-69730",
      "url": "https://labs.diras.sa/cve/cve-2026-69730/",
      "title": "Windows 10 Version 1607 DNS use-after-free remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth remote code execution vulnerability that allows unauthenticated code execution over the network, so prioritize installing the vendor fixes immediately to prevent remote compromise.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69730",
        "https://www.cve.org/CVERecord?id=CVE-2026-69730",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69730"
      ],
      "published": "2026-09-29T17:25:47Z",
      "updated": "2026-09-29T17:25:47Z"
    },
    {
      "id": "CVE-2026-69768",
      "url": "https://labs.diras.sa/cve/cve-2026-69768/",
      "title": "Windows 10 Version 1607 heap buffer overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this flaw allows remote code execution without authentication, so prioritize installing the vendor fixes for the affected builds immediately to eliminate remote attack paths.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69768",
        "https://www.cve.org/CVERecord?id=CVE-2026-69768",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69768"
      ],
      "published": "2026-09-29T17:25:34Z",
      "updated": "2026-09-29T17:25:34Z"
    },
    {
      "id": "CVE-2026-69769",
      "url": "https://labs.diras.sa/cve/cve-2026-69769/",
      "title": "Windows HTTP Print Provider heap overflow lets remote attackers run code",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent — this is a remote, unauthenticated code-execution flaw (no login or user click required); prioritize applying the vendor fixes listed for your build immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69769",
        "https://www.cve.org/CVERecord?id=CVE-2026-69769",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69769"
      ],
      "published": "2026-09-29T17:25:17Z",
      "updated": "2026-09-29T17:25:17Z"
    },
    {
      "id": "CVE-2026-69819",
      "url": "https://labs.diras.sa/cve/cve-2026-69819/",
      "title": "Windows 10 Version 1607 out-of-bounds write RPC Runtime remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a network-reachable, unauthenticated remote code execution (no login required), so prioritise installing vendor updates or blocking RPC exposure from untrusted networks immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69819",
        "https://www.cve.org/CVERecord?id=CVE-2026-69819",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69819"
      ],
      "published": "2026-09-29T17:25:04Z",
      "updated": "2026-09-29T17:25:04Z"
    },
    {
      "id": "CVE-2026-69829",
      "url": "https://labs.diras.sa/cve/cve-2026-69829/",
      "title": "Windows Shell heap overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated code execution bug with a high-severity rating; prioritize installing the Microsoft fixes for the listed builds because no authentication or user interaction is required to trigger it.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69829",
        "https://www.cve.org/CVERecord?id=CVE-2026-69829",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69829"
      ],
      "published": "2026-09-29T17:24:42Z",
      "updated": "2026-09-29T17:24:42Z"
    },
    {
      "id": "CVE-2026-69824",
      "url": "https://labs.diras.sa/cve/cve-2026-69824/",
      "title": "Windows 10 Version 1607 integer underflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is unauthenticated remote code execution against an internet-reachable component, so prioritize installing the vendor fixes listed for each affected build or otherwise block access to the vulnerable service.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69824",
        "https://www.cve.org/CVERecord?id=CVE-2026-69824",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69824"
      ],
      "published": "2026-09-29T17:24:30Z",
      "updated": "2026-09-29T17:24:30Z"
    },
    {
      "id": "CVE-2026-69845",
      "url": "https://labs.diras.sa/cve/cve-2026-69845/",
      "title": "Windows DHCP Server heap buffer overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01022,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        }
      ],
      "dirasTake": "Urgent: this vulnerability allows remote code execution without authentication, so prioritize patching to the fixed builds listed by Microsoft; if immediate patching is impractical, restrict network access to DHCP services and monitor for suspicious activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69845",
        "https://www.cve.org/CVERecord?id=CVE-2026-69845",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69845"
      ],
      "published": "2026-09-29T17:24:15Z",
      "updated": "2026-09-29T17:24:15Z"
    },
    {
      "id": "CVE-2026-69910",
      "url": "https://labs.diras.sa/cve/cve-2026-69910/",
      "title": "Windows 10 Version 1607 stack-based buffer overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        }
      ],
      "dirasTake": "Urgent: this flaw permits remote code execution without authentication, so prioritize patching or isolation because an unauthenticated network attacker can reach vulnerable systems.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69910",
        "https://www.cve.org/CVERecord?id=CVE-2026-69910",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69910"
      ],
      "published": "2026-09-29T17:24:02Z",
      "updated": "2026-09-29T17:24:02Z"
    },
    {
      "id": "CVE-2026-70296",
      "url": "https://labs.diras.sa/cve/cve-2026-70296/",
      "title": "Windows 10 Version 1607 out-of-bounds write in Windows Imaging Component",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent — this is an unauthenticated, remotely reachable code-execution flaw in a common Windows component; apply Microsoft’s fixes for the affected builds immediately and limit network exposure of vulnerable hosts.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-70296",
        "https://www.cve.org/CVERecord?id=CVE-2026-70296",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70296"
      ],
      "published": "2026-09-29T17:23:48Z",
      "updated": "2026-09-29T17:23:48Z"
    },
    {
      "id": "CVE-2026-72950",
      "url": "https://labs.diras.sa/cve/cve-2026-72950/",
      "title": "Windows Routing and Remote Access Service remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00923,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: treat this as a high-priority patching task because the vulnerability allows unauthenticated remote code execution over the network. Apply the vendor fixes for affected builds immediately or block RRAS exposure at network perimeters.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-72950",
        "https://www.cve.org/CVERecord?id=CVE-2026-72950",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72950"
      ],
      "published": "2026-09-29T17:23:33Z",
      "updated": "2026-09-29T17:23:33Z"
    },
    {
      "id": "CVE-2026-72979",
      "url": "https://labs.diras.sa/cve/cve-2026-72979/",
      "title": "Windows 10 Version 1607 DHCP Server use-after-free remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        }
      ],
      "dirasTake": "Apply vendor updates immediately: this is a network-accessible, unauthenticated remote code execution flaw and a fixed build is published for each affected branch. Treat systems exposed to untrusted networks as highest priority.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-72979",
        "https://www.cve.org/CVERecord?id=CVE-2026-72979",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72979"
      ],
      "published": "2026-09-29T17:23:19Z",
      "updated": "2026-09-29T17:23:19Z"
    },
    {
      "id": "CVE-2026-72982",
      "url": "https://labs.diras.sa/cve/cve-2026-72982/",
      "title": "Windows 10 Version 1607 Netlogon stack-based buffer overflow remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a critical remote code execution bug that requires no authentication and can be reached over the network, so prioritize installing the provided builds that contain the fixes.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-72982",
        "https://www.cve.org/CVERecord?id=CVE-2026-72982",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72982"
      ],
      "published": "2026-09-29T17:23:01Z",
      "updated": "2026-09-29T17:23:01Z"
    },
    {
      "id": "CVE-2026-72983",
      "url": "https://labs.diras.sa/cve/cve-2026-72983/",
      "title": "Windows Internet Connection Sharing use-after-free remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: this is a network unauthenticated remote code execution — an attacker only needs network access (no login), so prioritize deploying the provided fixes or otherwise isolating ICS-exposed hosts.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-72983",
        "https://www.cve.org/CVERecord?id=CVE-2026-72983",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72983"
      ],
      "published": "2026-09-29T17:22:46Z",
      "updated": "2026-09-29T17:22:46Z"
    },
    {
      "id": "CVE-2026-73009",
      "url": "https://labs.diras.sa/cve/cve-2026-73009/",
      "title": "Windows Secure Socket Tunneling Protocol use-after-free remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: patch exposed SSTP endpoints immediately because this vulnerability permits unauthenticated remote code execution over the network. Apply vendor updates or block SSTP exposure until systems are updated.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-73009",
        "https://www.cve.org/CVERecord?id=CVE-2026-73009",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73009"
      ],
      "published": "2026-09-29T17:22:32Z",
      "updated": "2026-09-29T17:22:32Z"
    },
    {
      "id": "CVE-2026-73010",
      "url": "https://labs.diras.sa/cve/cve-2026-73010/",
      "title": "Windows 10 Version 1809 use-after-free remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2022 10.x",
          "affected": "10.0.20348.0 – before 10.0.20348.5622",
          "fixed": "10.0.20348.5622"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33438",
          "fixed": "10.0.26100.33438"
        },
        {
          "branch": "Windows Server 2025 (Server Core installation) 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33438",
          "fixed": "10.0.26100.33438"
        }
      ],
      "dirasTake": "Urgent — this is a pre-auth remote code execution vulnerability and Microsoft published fixes; prioritize installing the listed fixed builds for affected Windows 10 and Server branches or otherwise block network exposure to vulnerable hosts.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-73010",
        "https://www.cve.org/CVERecord?id=CVE-2026-73010",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73010"
      ],
      "published": "2026-09-29T17:22:18Z",
      "updated": "2026-09-29T17:22:18Z"
    },
    {
      "id": "CVE-2026-73025",
      "url": "https://labs.diras.sa/cve/cve-2026-73025/",
      "title": "Windows iSCSI weak authentication network bypass",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-1390",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00901,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        }
      ],
      "dirasTake": "Urgent: treat this as a high-priority patching task because the flaw lets an unauthenticated remote attacker bypass iSCSI authentication; fixed builds are available for all affected branches. Apply the fixes or block iSCSI exposure immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-73025",
        "https://www.cve.org/CVERecord?id=CVE-2026-73025",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73025"
      ],
      "published": "2026-09-29T17:22:07Z",
      "updated": "2026-09-29T17:22:07Z"
    },
    {
      "id": "CVE-2026-77493",
      "url": "https://labs.diras.sa/cve/cve-2026-77493/",
      "title": "Windows 10 Version 1607 double-free in Graphics Component allows remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Patch urgently: the flaw allows remote code execution without authentication, so prioritize updates for exposed hosts and apply Microsoft's fixed builds immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77493",
        "https://www.cve.org/CVERecord?id=CVE-2026-77493",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77493"
      ],
      "published": "2026-09-29T17:21:53Z",
      "updated": "2026-09-29T17:21:53Z"
    },
    {
      "id": "CVE-2026-78445",
      "url": "https://labs.diras.sa/cve/cve-2026-78445/",
      "title": "Windows Server Services for NFS use-after-free remote code execution",
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows Server 2022 10.x",
          "affected": "10.0.20348.0 – before 10.0.20348.5622",
          "fixed": "10.0.20348.5622"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33438",
          "fixed": "10.0.26100.33438"
        }
      ],
      "dirasTake": "Urgent: deploy Microsoft's updates immediately because this is a remote, unauthenticated code-execution flaw that allows attackers to run code over the network. Prioritise internet-facing or NFS-exposed servers first.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-78445",
        "https://www.cve.org/CVERecord?id=CVE-2026-78445",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78445"
      ],
      "published": "2026-09-29T17:21:36Z",
      "updated": "2026-09-29T17:21:36Z"
    },
    {
      "id": "CVE-2026-28606",
      "url": "https://labs.diras.sa/cve/cve-2026-28606/",
      "title": "Android pairing bypass lets remote attacker escalate privileges",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00386,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "17.x",
          "affected": "17",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16-qpr2",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15",
          "fixed": null
        }
      ],
      "dirasTake": "Fix urgently: this flaw allows escalation without user interaction and carries a critical CVSS 9.8 rating. Prioritize mitigations for internet- or Bluetooth-exposed devices until Google issues a patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-28606",
        "https://www.cve.org/CVERecord?id=CVE-2026-28606",
        "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
      ],
      "published": "2026-09-29T17:21:22Z",
      "updated": "2026-09-29T17:21:22Z"
    },
    {
      "id": "CVE-2026-49921",
      "url": "https://labs.diras.sa/cve/cve-2026-49921/",
      "title": "Android heap buffer overflow remote code execution",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00386,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "17.x",
          "affected": "17",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16-qpr2",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14",
          "fixed": null
        }
      ],
      "dirasTake": "Act urgently: this is a critical, remote code execution bug that requires no user interaction, so prioritize mitigations and prepare to deploy vendor patches when available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-49921",
        "https://www.cve.org/CVERecord?id=CVE-2026-49921",
        "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
      ],
      "published": "2026-09-29T17:21:10Z",
      "updated": "2026-09-29T17:21:10Z"
    },
    {
      "id": "CVE-2026-58822",
      "url": "https://labs.diras.sa/cve/cve-2026-58822/",
      "title": "Android ftsmooth improper casting remote code execution",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-704",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00382,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "17.x",
          "affected": "17",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16-qpr2",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority because the flaw allows unauthenticated, no-user-interaction remote code execution; prioritize reducing network exposure of Android devices and apply vendor mitigation guidance as it becomes available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-58822",
        "https://www.cve.org/CVERecord?id=CVE-2026-58822",
        "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
      ],
      "published": "2026-09-29T17:20:58Z",
      "updated": "2026-09-29T17:20:58Z"
    },
    {
      "id": "CVE-2026-87534",
      "url": "https://labs.diras.sa/cve/cve-2026-87534/",
      "title": "Chrome WebView missing authorization allows bypass via crafted network traffic",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00292,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "153.x",
          "affected": "153.0.8010.36 – before 153.0.8010.36",
          "fixed": "153.0.8010.36"
        }
      ],
      "dirasTake": "Urgent: upgrade affected Chrome WebView instances because the flaw permits bypassing authorization without authentication, letting remote attackers act after a crafted network interaction.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-87534",
        "https://www.cve.org/CVERecord?id=CVE-2026-87534",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html",
        "https://issues.chromium.org/issues/513134173"
      ],
      "published": "2026-09-29T17:20:42Z",
      "updated": "2026-09-29T17:20:42Z"
    },
    {
      "id": "CVE-2026-87544",
      "url": "https://labs.diras.sa/cve/cve-2026-87544/",
      "title": "Chrome incorrect authorization allows access to privileged Extensions page",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00335,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "153.x",
          "affected": "153.0.8010.36 – before 153.0.8010.36",
          "fixed": "153.0.8010.36"
        }
      ],
      "dirasTake": "Apply the vendor patch immediately: Google released 153.0.8010.36 to fix this authorization bypass. Treat as high priority because a browser update is available that directly remediates the issue.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-87544",
        "https://www.cve.org/CVERecord?id=CVE-2026-87544",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html",
        "https://issues.chromium.org/issues/542355360"
      ],
      "published": "2026-09-29T17:20:30Z",
      "updated": "2026-09-29T17:20:30Z"
    },
    {
      "id": "CVE-2026-87595",
      "url": "https://labs.diras.sa/cve/cve-2026-87595/",
      "title": "Chrome server-side request forgery in Mobile via crafted HTML",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-918",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00419,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "153.x",
          "affected": "153.0.8010.36 – before 153.0.8010.36",
          "fixed": "153.0.8010.36"
        }
      ],
      "dirasTake": "Urgently update affected Chrome Mobile installs to 153.0.8010.36 because a remote SSRF can be triggered via a crafted page without prior authentication and a vendor fix is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-87595",
        "https://www.cve.org/CVERecord?id=CVE-2026-87595",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html",
        "https://issues.chromium.org/issues/513726466"
      ],
      "published": "2026-09-29T17:20:18Z",
      "updated": "2026-09-29T17:20:18Z"
    },
    {
      "id": "CVE-2026-85025",
      "url": "https://labs.diras.sa/cve/cve-2026-85025/",
      "title": "Langflow OSS unauthenticated code execution via public MCP endpoints",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00614,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.11.5",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority: an attacker needs no account to reach exposed MCP endpoints, so immediately remove or restrict any publicly shared project endpoints and follow IBM’s remediation guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85025",
        "https://www.cve.org/CVERecord?id=CVE-2026-85025",
        "https://www.ibm.com/support/pages/node/7286666"
      ],
      "published": "2026-09-29T17:20:03Z",
      "updated": "2026-09-29T17:20:03Z"
    },
    {
      "id": "CVE-2026-79724",
      "url": "https://labs.diras.sa/cve/cve-2026-79724/",
      "title": "Langflow OSS command injection allows remote OS command execution",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00673,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.11.5",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated command injection with critical impact (CVSS 9.8); prioritize isolating internet-facing Langflow OSS instances and apply vendor fixes or mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-79724",
        "https://www.cve.org/CVERecord?id=CVE-2026-79724",
        "https://www.ibm.com/support/pages/node/7286666"
      ],
      "published": "2026-09-29T17:19:52Z",
      "updated": "2026-09-29T17:19:52Z"
    },
    {
      "id": "CVE-2026-81204",
      "url": "https://labs.diras.sa/cve/cve-2026-81204/",
      "title": "Langflow OSS code injection during graph construction allows remote code execution",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0086,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.11.5",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated code execution flaw with critical impact and easy network access (CVSS 9.8). Prioritize reducing exposure of internet-facing Langflow OSS instances and applying vendor guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-81204",
        "https://www.cve.org/CVERecord?id=CVE-2026-81204",
        "https://www.ibm.com/support/pages/node/7286666"
      ],
      "published": "2026-09-29T17:19:30Z",
      "updated": "2026-09-29T17:19:30Z"
    },
    {
      "id": "CVE-2026-65414",
      "url": "https://labs.diras.sa/cve/cve-2026-65414/",
      "title": "IOS and iPadOS out-of-bounds write remote code execution",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01078,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "iOS and iPadOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "macOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "tvOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "visionOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "watchOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgent: apply vendor updates promptly because this flaw requires no privileges or user interaction (CVSS shows PR:N and UI:N), making exposed devices high risk until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65414",
        "https://www.cve.org/CVERecord?id=CVE-2026-65414",
        "https://support.apple.com/en-us/149034",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149036",
        "https://support.apple.com/en-us/149037",
        "https://support.apple.com/en-us/149038",
        "https://support.apple.com/en-us/149041",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-29T17:19:18Z",
      "updated": "2026-09-29T17:19:18Z"
    },
    {
      "id": "CVE-2026-84520",
      "url": "https://labs.diras.sa/cve/cve-2026-84520/",
      "title": "MacOS kernel buffer overflow lets local attacker corrupt kernel memory",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-120",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00445,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgent: install the macOS Golden Gate 27 update because the flaw permits local corruption of kernel memory, which can result in system crashes or privilege escalation. If you cannot patch immediately, restrict who can run code locally and increase endpoint monitoring for crashes and suspicious kernel activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84520",
        "https://www.cve.org/CVERecord?id=CVE-2026-84520",
        "https://support.apple.com/en-us/149035"
      ],
      "published": "2026-09-29T17:19:06Z",
      "updated": "2026-09-29T17:19:06Z"
    },
    {
      "id": "CVE-2026-84561",
      "url": "https://labs.diras.sa/cve/cve-2026-84561/",
      "title": "IOS and iPadOS double free lets remote code execution / kernel corruption",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-415",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0068,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "iOS and iPadOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "macOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "tvOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "visionOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "watchOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw is exploitable over the network without authentication or user interaction (CVSS AV:N/PR:N/UI:N), and vendor patches are already available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84561",
        "https://www.cve.org/CVERecord?id=CVE-2026-84561",
        "https://support.apple.com/en-us/149034",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149036",
        "https://support.apple.com/en-us/149037",
        "https://support.apple.com/en-us/149038",
        "https://support.apple.com/en-us/149041",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-29T17:18:55Z",
      "updated": "2026-09-29T17:18:55Z"
    },
    {
      "id": "CVE-2026-84609",
      "url": "https://labs.diras.sa/cve/cve-2026-84609/",
      "title": "IOS and iPadOS permissions bug lets an app modify protected system files",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-120",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00665,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "macOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "tvOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "visionOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "watchOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgently install the vendor updates: Apple published fixes in iOS/iPadOS 27 and macOS 15.8/26.7 and corresponding 27 releases—apply them to remove the ability for apps to modify protected files.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84609",
        "https://www.cve.org/CVERecord?id=CVE-2026-84609",
        "https://support.apple.com/en-us/149034",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149036",
        "https://support.apple.com/en-us/149037",
        "https://support.apple.com/en-us/149038",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-29T17:18:42Z",
      "updated": "2026-09-29T17:18:42Z"
    },
    {
      "id": "CVE-2026-92036",
      "url": "https://labs.diras.sa/cve/cve-2026-92036/",
      "title": "Firefox memory-safety flaw in HTTP networking allows remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00587,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as urgent: the flaw allows unauthenticated remote code execution over the network and the vendor has not published a patch in the provided facts.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92036",
        "https://www.cve.org/CVERecord?id=CVE-2026-92036",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2068416",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/"
      ],
      "published": "2026-09-29T17:18:28Z",
      "updated": "2026-09-29T17:18:28Z"
    },
    {
      "id": "CVE-2026-92037",
      "url": "https://labs.diras.sa/cve/cve-2026-92037/",
      "title": "Firefox DOM animation boundary bug allows pre-auth remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00587,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: this is a high-risk remote code execution bug because it can be triggered remotely with no authentication or user interaction, enabling full compromise of the browser process if exploited.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92037",
        "https://www.cve.org/CVERecord?id=CVE-2026-92037",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2068460",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/"
      ],
      "published": "2026-09-29T17:18:10Z",
      "updated": "2026-09-29T17:18:10Z"
    },
    {
      "id": "CVE-2026-92061",
      "url": "https://labs.diras.sa/cve/cve-2026-92061/",
      "title": "Firefox process sandboxing buffer overflow remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00587,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: this is a high-impact, no-authentication remote code execution bug (CVSS 9.8) — prioritize mitigation because the flaw lets attackers gain code execution without user interaction.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92061",
        "https://www.cve.org/CVERecord?id=CVE-2026-92061",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2041758",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/"
      ],
      "published": "2026-09-29T17:17:53Z",
      "updated": "2026-09-29T17:17:53Z"
    },
    {
      "id": "CVE-2026-92066",
      "url": "https://labs.diras.sa/cve/cve-2026-92066/",
      "title": "Firefox sandbox escape leading to remote code execution",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00587,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as urgent: the flaw requires no privileges or user interaction (pre-auth), enabling remote attackers to escape the browser sandbox. If you cannot patch immediately, restrict exposure and monitor affected hosts closely.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-92066",
        "https://www.cve.org/CVERecord?id=CVE-2026-92066",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2058093",
        "https://www.mozilla.org/security/advisories/mfsa2026-90/",
        "https://www.mozilla.org/security/advisories/mfsa2026-94/"
      ],
      "published": "2026-09-29T17:17:37Z",
      "updated": "2026-09-29T17:17:37Z"
    },
    {
      "id": "CVE-2026-55366",
      "url": "https://labs.diras.sa/cve/cve-2026-55366/",
      "title": "Android kernel IMS authentication bypass remote privilege escalation",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0046,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Android",
          "affected": "Android kernel",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high urgency: the IMS flaw allows authentication bypass with no user interaction, meaning an unauthenticated remote attacker could attempt privilege escalation against affected Android kernel deployments.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-55366",
        "https://www.cve.org/CVERecord?id=CVE-2026-55366",
        "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
      ],
      "published": "2026-09-29T17:17:24Z",
      "updated": "2026-09-29T17:17:24Z"
    },
    {
      "id": "CVE-2026-56960",
      "url": "https://labs.diras.sa/cve/cve-2026-56960/",
      "title": "Android kernel use-after-free remote privilege escalation",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00401,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "Android",
          "affected": "Android kernel",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: the flaw requires no authentication or user interaction, enabling remote escalation from network access to kernel privileges; prioritize exposure reduction and monitoring until a vendor fix is available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-56960",
        "https://www.cve.org/CVERecord?id=CVE-2026-56960",
        "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
      ],
      "published": "2026-09-29T17:17:12Z",
      "updated": "2026-09-29T17:17:12Z"
    },
    {
      "id": "CVE-2026-69399",
      "url": "https://labs.diras.sa/cve/cve-2026-69399/",
      "title": "Azure ARC elevation of privilege via network",
      "vendor": "Microsoft",
      "product": "Azure ARC",
      "cwe": "CWE-441",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00484,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure ARC",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: the issue allows privilege elevation over the network with no authentication required and carries a critical CVSS 9.8 rating, so prioritize mitigations and vendor updates for internet-facing Azure ARC instances.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69399",
        "https://www.cve.org/CVERecord?id=CVE-2026-69399",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69399"
      ],
      "published": "2026-09-29T17:15:38Z",
      "updated": "2026-09-29T17:15:38Z"
    },
    {
      "id": "CVE-2026-70009",
      "url": "https://labs.diras.sa/cve/cve-2026-70009/",
      "title": "Azure ARC path traversal privilege elevation",
      "vendor": "Microsoft",
      "product": "Azure ARC",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00534,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure ARC",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw requires no authentication and has a critical CVSS 9.8 rating, so immediately limit network exposure and prioritize vendor remediation guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-70009",
        "https://www.cve.org/CVERecord?id=CVE-2026-70009",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70009"
      ],
      "published": "2026-09-29T17:15:19Z",
      "updated": "2026-09-29T17:15:19Z"
    },
    {
      "id": "CVE-2026-70200",
      "url": "https://labs.diras.sa/cve/cve-2026-70200/",
      "title": "Azure Logic Apps path traversal allows remote privilege escalation",
      "vendor": "Microsoft",
      "product": "Azure Logic Apps",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.006,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure Logic Apps",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is remotely exploitable without authentication, so prioritize mitigations that remove internet exposure and apply Microsoft’s fixes or guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-70200",
        "https://www.cve.org/CVERecord?id=CVE-2026-70200",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70200"
      ],
      "published": "2026-09-29T17:15:06Z",
      "updated": "2026-09-29T17:15:06Z"
    },
    {
      "id": "CVE-2026-85889",
      "url": "https://labs.diras.sa/cve/cve-2026-85889/",
      "title": "Azure AI Foundry missing authentication privilege elevation",
      "vendor": "Microsoft",
      "product": "Azure AI Foundry",
      "cwe": "CWE-306",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00671,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure AI Foundry",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this flaw allows unauthenticated access to privileged functions, so restrict network exposure now and apply the vendor's update or guidance immediately when available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85889",
        "https://www.cve.org/CVERecord?id=CVE-2026-85889",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889"
      ],
      "published": "2026-09-29T17:14:47Z",
      "updated": "2026-09-29T17:14:47Z"
    },
    {
      "id": "CVE-2026-93762",
      "url": "https://labs.diras.sa/cve/cve-2026-93762/",
      "title": "Mongoid unsafe reflection data disclosure and deletion",
      "vendor": "MongoDB",
      "product": "Mongoid",
      "cwe": "CWE-470",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00573,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "9.x",
          "affected": "9.1.0",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.0.0 – 9.0.11",
          "fixed": null
        },
        {
          "branch": "8.x",
          "affected": "8.1.0 – 8.1.12",
          "fixed": null
        },
        {
          "branch": "8.x",
          "affected": "8.0.0 – 8.0.12",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.6.0 – 7.6.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.5.0 – 7.5.4",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: an unauthenticated flaw with no fixed releases listed can expose and delete data; immediately restrict external access and sanitize any user-controlled field names in queries until vendor fixes are available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-93762",
        "https://www.cve.org/CVERecord?id=CVE-2026-93762",
        "https://jira.mongodb.org/browse/MONGOID-5973"
      ],
      "published": "2026-09-29T17:14:34Z",
      "updated": "2026-09-29T17:14:34Z"
    },
    {
      "id": "CVE-2026-93643",
      "url": "https://labs.diras.sa/cve/cve-2026-93643/",
      "title": "Zimbra Collaboration Suite path-traversal pre-auth remote code execution",
      "vendor": "Zimbra",
      "product": "Zimbra Collaboration Suite (ZCS)",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0096,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "10.x",
          "affected": "before 10.1.21",
          "fixed": "10.1.21"
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth RCE requiring no login; install the 10.1.21 update promptly or block public Briefcase and OnlyOffice document editing exposure while you patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-93643",
        "https://www.cve.org/CVERecord?id=CVE-2026-93643",
        "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories"
      ],
      "published": "2026-09-29T17:13:16Z",
      "updated": "2026-09-29T17:13:16Z"
    },
    {
      "id": "CVE-2026-18143",
      "url": "https://labs.diras.sa/cve/cve-2026-18143/",
      "title": "Request a Quote for WooCommerce arbitrary file upload via popup handler",
      "vendor": "Addify",
      "product": "Request a Quote for WooCommerce",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00413,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.9.2 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority: public exploit code exists, so any internet-facing site using the plugin's public multi-page popup should be mitigated or disabled immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-18143",
        "https://www.cve.org/CVERecord?id=CVE-2026-18143",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/3417ec27-6abf-45c7-945f-6ef456ba1187?source=cve",
        "https://woocommerce.com/products/request-a-quote-plugin-for-woocommerce/"
      ],
      "published": "2026-09-29T17:12:57Z",
      "updated": "2026-09-29T17:12:57Z"
    },
    {
      "id": "CVE-2026-88775",
      "url": "https://labs.diras.sa/cve/cve-2026-88775/",
      "title": "Citrix ADC memory overflow allows unauthenticated remote code execution",
      "vendor": "Citrix",
      "product": "ADC",
      "cwe": "CWE-120",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00384,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        },
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37 FIPS",
          "fixed": "14.1-73.37 FIPS"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1.37.279 FIPS and NDcPP",
          "fixed": "13.1.37.279 FIPS and NDcPP"
        },
        {
          "branch": "Gateway 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "Gateway 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because the flaw is remotely reachable without authentication (no login required). Apply vendor fixes promptly or restrict network exposure to management interfaces.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-88775",
        "https://www.cve.org/CVERecord?id=CVE-2026-88775",
        "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
      ],
      "published": "2026-09-29T17:12:35Z",
      "updated": "2026-09-29T17:12:35Z"
    },
    {
      "id": "CVE-2026-88777",
      "url": "https://labs.diras.sa/cve/cve-2026-88777/",
      "title": "Citrix ADC memory overflow allows unauthenticated network denial of service",
      "vendor": "Citrix",
      "product": "ADC",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00384,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        },
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37 FIPS",
          "fixed": "14.1-73.37 FIPS"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1.37.279 FIPS and NDcPP",
          "fixed": "13.1.37.279 FIPS and NDcPP"
        },
        {
          "branch": "Gateway 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "Gateway 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        }
      ],
      "dirasTake": "Urgent: apply vendor fixes immediately because this is remotely reachable without authentication and Citrix has published fixed firmware versions.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-88777",
        "https://www.cve.org/CVERecord?id=CVE-2026-88777",
        "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
      ],
      "published": "2026-09-29T17:12:20Z",
      "updated": "2026-09-29T17:12:20Z"
    },
    {
      "id": "CVE-2026-88776",
      "url": "https://labs.diras.sa/cve/cve-2026-88776/",
      "title": "Citrix ADC memory overflow can cause service disruption",
      "vendor": "Citrix",
      "product": "ADC",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00384,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        },
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37 FIPS",
          "fixed": "14.1-73.37 FIPS"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1.37.279 FIPS and NDcPP",
          "fixed": "13.1.37.279 FIPS and NDcPP"
        },
        {
          "branch": "Gateway 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "Gateway 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        }
      ],
      "dirasTake": "Urgent: this can be reached over the network without credentials, so prioritize applying the vendor fixes listed for your ADC/Gateway branch or immediately restrict exposure and monitor for anomalies.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-88776",
        "https://www.cve.org/CVERecord?id=CVE-2026-88776",
        "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
      ],
      "published": "2026-09-29T17:12:04Z",
      "updated": "2026-09-29T17:12:04Z"
    },
    {
      "id": "CVE-2026-57983",
      "url": "https://labs.diras.sa/cve/cve-2026-57983/",
      "title": "Microsoft Edge security feature bypass over network (pre-auth authorization bypass)",
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-285",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00648,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "150.x",
          "affected": "1.0.0.0 – before 150.0.4078.48",
          "fixed": "150.0.4078.48"
        }
      ],
      "dirasTake": "Urgent: this is a critical, network-accessible bypass that requires no authentication; update Microsoft Edge to build 150.0.4078.48 immediately where possible.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-57983",
        "https://www.cve.org/CVERecord?id=CVE-2026-57983",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57983"
      ],
      "published": "2026-09-29T17:11:51Z",
      "updated": "2026-09-29T17:11:51Z"
    },
    {
      "id": "CVE-2026-62643",
      "url": "https://labs.diras.sa/cve/cve-2026-62643/",
      "title": "Roundcube Webmail CSS sanitization SSRF and information disclosure",
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-918",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.0044,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.6.0 – before 1.6.17",
          "fixed": "1.6.17"
        },
        {
          "branch": "1.x",
          "affected": "1.7.0 – before 1.7.2",
          "fixed": "1.7.2"
        }
      ],
      "dirasTake": "Urgent — this is a critical, unauthenticated vulnerability (CVSS 10.0) that can trigger SSRF or data disclosure from Roundcube installations; apply the vendor fixes 1.6.17 or 1.7.2 immediately or block HTML message rendering until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62643",
        "https://www.cve.org/CVERecord?id=CVE-2026-62643",
        "https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2",
        "https://github.com/roundcube/roundcubemail/releases/tag/1.7.2",
        "https://github.com/roundcube/roundcubemail/commit/6d69e094d55d3a9a84dfb36edf6ca985311f0c1c",
        "https://github.com/roundcube/roundcubemail/releases/tag/1.6.17",
        "https://github.com/roundcube/roundcubemail/commit/294c7da6e7284166f040cef8607b677d459e0786"
      ],
      "published": "2026-09-29T17:11:39Z",
      "updated": "2026-09-29T17:11:39Z"
    },
    {
      "id": "CVE-2026-54433",
      "url": "https://labs.diras.sa/cve/cve-2026-54433/",
      "title": "Roundcube Webmail stored XSS zero-click via crafted email",
      "vendor": "Roundcube",
      "product": "Webmail",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00311,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.6.0 – before 1.6.17",
          "fixed": "1.6.17"
        },
        {
          "branch": "1.x",
          "affected": "1.7.0 – before 1.7.2",
          "fixed": "1.7.2"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this Roundcube Webmail stored XSS and the attack can run in a victim's authenticated session via message preview, so prioritize upgrading or applying mitigations now.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-54433",
        "https://www.cve.org/CVERecord?id=CVE-2026-54433",
        "https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2"
      ],
      "published": "2026-09-29T17:11:27Z",
      "updated": "2026-09-29T17:11:27Z"
    },
    {
      "id": "CVE-2026-54159",
      "url": "https://labs.diras.sa/cve/cve-2026-54159/",
      "title": "Ps_facetedsearch arbitrary file write leading to remote code execution",
      "vendor": "PrestaShop",
      "product": "ps_facetedsearch",
      "cwe": "CWE-74",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.0075,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "ps_facetedsearch",
          "affected": ">= 3.0.0, < 4.0.4",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — the flaw permits remote code execution without any login, so prioritize containment and patching actions immediately where ps_facetedsearch is exposed to untrusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-54159",
        "https://www.cve.org/CVERecord?id=CVE-2026-54159",
        "https://github.com/PrestaShop/ps_facetedsearch/security/advisories/GHSA-m5f5-28qr-9g9r",
        "https://github.com/PrestaShop/ps_facetedsearch/commit/9ca839fac68a60641d8187a3ff9730ab09af33cb",
        "https://github.com/PrestaShop/ps_facetedsearch/releases/tag/v4.0.4"
      ],
      "published": "2026-09-29T17:10:56Z",
      "updated": "2026-09-29T17:10:56Z"
    },
    {
      "id": "CVE-2026-16367",
      "url": "https://labs.diras.sa/cve/cve-2026-16367/",
      "title": "Firefox sandbox escape in Disability Access APIs (invalid pointer)",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00375,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Urgent: this is a remotely exploitable sandbox escape requiring no authentication or user interaction, making it high priority to isolate exposed Firefox installs and prepare to apply vendor updates as soon as they are published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-16367",
        "https://www.cve.org/CVERecord?id=CVE-2026-16367",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2050627",
        "https://www.mozilla.org/security/advisories/mfsa2026-68/",
        "https://www.mozilla.org/security/advisories/mfsa2026-71/"
      ],
      "published": "2026-09-29T17:10:45Z",
      "updated": "2026-09-29T17:10:45Z"
    },
    {
      "id": "CVE-2026-56163",
      "url": "https://labs.diras.sa/cve/cve-2026-56163/",
      "title": "Azure Kubernetes Service missing authentication allows pre-auth privilege escalation",
      "vendor": "Microsoft",
      "product": "Azure Kubernetes Service",
      "cwe": "CWE-306",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00901,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure Kubernetes Service",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: the issue grants unauthenticated full system impact and carries a CVSS 10.0 base score, so immediately follow vendor guidance and limit network exposure to the service.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-56163",
        "https://www.cve.org/CVERecord?id=CVE-2026-56163",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56163"
      ],
      "published": "2026-09-29T17:10:29Z",
      "updated": "2026-09-29T17:10:29Z"
    },
    {
      "id": "CVE-2026-65880",
      "url": "https://labs.diras.sa/cve/cve-2026-65880/",
      "title": "Balbooa Forms for Joomla unauthenticated remote code execution",
      "vendor": "balbooa.com",
      "product": "Balbooa Forms component for Joomla",
      "cwe": "CWE-94",
      "cvss": {
        "version": "4.0",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": 0.00772,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0-2.4.2.1",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw allows remote code execution without any login, so immediately restrict public access to affected endpoints and follow vendor guidance as soon as updates or mitigations are published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65880",
        "https://www.cve.org/CVERecord?id=CVE-2026-65880",
        "https://www.balbooa.com/joomla-forms"
      ],
      "published": "2026-09-29T17:10:09Z",
      "updated": "2026-09-29T17:10:09Z"
    },
    {
      "id": "CVE-2026-66803",
      "url": "https://labs.diras.sa/cve/cve-2026-66803/",
      "title": "Azure Cosmos DB improper access control pre-auth remote code execution",
      "vendor": "Microsoft",
      "product": "Azure Cosmos DB",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00901,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure Cosmos DB",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated code execution with a critical CVSS 10.0 rating—prioritise mitigation now by applying vendor updates or limiting network exposure to Cosmos DB endpoints.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-66803",
        "https://www.cve.org/CVERecord?id=CVE-2026-66803",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803"
      ],
      "published": "2026-09-29T17:09:58Z",
      "updated": "2026-09-29T17:09:58Z"
    },
    {
      "id": "CVE-2026-64633",
      "url": "https://labs.diras.sa/cve/cve-2026-64633/",
      "title": "Veeam ONE unauthenticated remote code execution",
      "vendor": "Veeam",
      "product": "ONE",
      "cwe": "CWE-94",
      "cvss": {
        "version": "4.0",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": 0.00604,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "13.x",
          "affected": "13.0.2 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so prioritize mitigation immediately; use network restrictions and isolate Veeam ONE agent hosts while waiting for vendor fixes.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64633",
        "https://www.cve.org/CVERecord?id=CVE-2026-64633",
        "https://www.veeam.com/kb4892"
      ],
      "published": "2026-09-29T17:09:45Z",
      "updated": "2026-09-29T17:09:45Z"
    },
    {
      "id": "CVE-2026-56162",
      "url": "https://labs.diras.sa/cve/cve-2026-56162/",
      "title": "Azure SQL Database improper authentication privilege elevation",
      "vendor": "Microsoft",
      "product": "Azure SQL Database",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00901,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure SQL Database",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated privilege-escalation against an internet-facing managed database and has a maximum CVSS score, so prioritize applying Microsoft's guidance or patches and block unnecessary network access immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-56162",
        "https://www.cve.org/CVERecord?id=CVE-2026-56162",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56162"
      ],
      "published": "2026-09-29T17:09:21Z",
      "updated": "2026-09-29T17:09:21Z"
    },
    {
      "id": "CVE-2026-62836",
      "url": "https://labs.diras.sa/cve/cve-2026-62836/",
      "title": "Azure SQL Managed Instance privilege elevation via communication channel flaw",
      "vendor": "Microsoft",
      "product": "Azure SQL Managed Instance",
      "cwe": "CWE-923",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00648,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure SQL Managed Instance",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a network-accessible, no-authentication privilege escalation with a CVSS 10.0 rating; prioritize reducing exposure of Azure SQL Managed Instance endpoints and apply Microsoft guidance or patches as soon as they are available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62836",
        "https://www.cve.org/CVERecord?id=CVE-2026-62836",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62836"
      ],
      "published": "2026-09-29T17:09:09Z",
      "updated": "2026-09-29T17:09:09Z"
    },
    {
      "id": "CVE-2026-65667",
      "url": "https://labs.diras.sa/cve/cve-2026-65667/",
      "title": "Microsoft Teams missing authorization privilege elevation",
      "vendor": "Microsoft",
      "product": "Microsoft Teams",
      "cwe": "CWE-862",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00798,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft Teams",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this flaw requires no authentication, so exposed Teams services are at high risk; prioritize applying vendor updates or mitigations immediately because an unauthenticated attacker can trigger privilege elevation.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65667",
        "https://www.cve.org/CVERecord?id=CVE-2026-65667",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65667"
      ],
      "published": "2026-09-29T17:08:58Z",
      "updated": "2026-09-29T17:08:58Z"
    },
    {
      "id": "CVE-2026-75874",
      "url": "https://labs.diras.sa/cve/cve-2026-75874/",
      "title": "Firefox sandbox escape in Remote Settings Client",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00455,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [],
      "dirasTake": "Treat this as urgent: the flaw can be triggered remotely with no authentication or user interaction, so reduce exposure of affected clients and apply vendor guidance as soon as fixes are published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-75874",
        "https://www.cve.org/CVERecord?id=CVE-2026-75874",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2039972",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-83/",
        "https://www.mozilla.org/security/advisories/mfsa2026-84/",
        "https://www.mozilla.org/security/advisories/mfsa2026-85/",
        "https://www.mozilla.org/security/advisories/mfsa2026-87/",
        "https://www.mozilla.org/security/advisories/mfsa2026-88/"
      ],
      "published": "2026-09-29T17:08:47Z",
      "updated": "2026-09-29T17:08:47Z"
    },
    {
      "id": "CVE-2026-65770",
      "url": "https://labs.diras.sa/cve/cve-2026-65770/",
      "title": "Azure Managed Instance for Apache Cassandra argument injection allows remote code execution",
      "vendor": "Microsoft",
      "product": "Azure Managed Instance for Apache Cassandra",
      "cwe": "CWE-88",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.01053,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure Managed Instance for Apache Cassandra",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this vulnerability permits unauthenticated remote code execution (CVSS 10.0) so reduce internet exposure immediately and prioritize applying the vendor's updates or mitigations when they are published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65770",
        "https://www.cve.org/CVERecord?id=CVE-2026-65770",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65770"
      ],
      "published": "2026-09-29T17:08:33Z",
      "updated": "2026-09-29T17:08:33Z"
    },
    {
      "id": "CVE-2026-65816",
      "url": "https://labs.diras.sa/cve/cve-2026-65816/",
      "title": "Azure Web Apps incorrect name resolution lets unauthenticated actor elevate privileges",
      "vendor": "Microsoft",
      "product": "Azure Web Apps",
      "cwe": "CWE-706",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00974,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure Web Apps",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, unauthenticated elevation-of-privilege flaw with maximum severity and no user interaction required, so prioritize mitigation for internet-facing Azure Web Apps immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65816",
        "https://www.cve.org/CVERecord?id=CVE-2026-65816",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65816"
      ],
      "published": "2026-09-29T17:08:24Z",
      "updated": "2026-09-29T17:08:24Z"
    },
    {
      "id": "CVE-2026-69555",
      "url": "https://labs.diras.sa/cve/cve-2026-69555/",
      "title": "Azure ARC incorrect authorization lets remote attacker escalate privileges",
      "vendor": "Microsoft",
      "product": "Azure ARC",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00798,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure ARC",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, pre-auth vulnerability (no login needed) that yields full compromise potential, so immediately reduce network exposure and follow Microsoft guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69555",
        "https://www.cve.org/CVERecord?id=CVE-2026-69555",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69555"
      ],
      "published": "2026-09-29T17:08:13Z",
      "updated": "2026-09-29T17:08:13Z"
    },
    {
      "id": "CVE-2026-69502",
      "url": "https://labs.diras.sa/cve/cve-2026-69502/",
      "title": "Azure SQL Database server-side request forgery privilege elevation",
      "vendor": "Microsoft",
      "product": "Azure SQL Database",
      "cwe": "CWE-918",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00798,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure SQL Database",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: the flaw permits unauthenticated remote privilege elevation (no login needed) and carries a maximum CVSS score, so immediately follow vendor guidance and reduce exposure of Azure SQL Database instances.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69502",
        "https://www.cve.org/CVERecord?id=CVE-2026-69502",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69502"
      ],
      "published": "2026-09-29T17:08:03Z",
      "updated": "2026-09-29T17:08:03Z"
    },
    {
      "id": "CVE-2026-70352",
      "url": "https://labs.diras.sa/cve/cve-2026-70352/",
      "title": "Azure AI Language Authoring missing authentication allows privilege elevation",
      "vendor": "Microsoft",
      "product": "Azure AI Language Authoring",
      "cwe": "CWE-306",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00921,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure AI Language Authoring",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — this flaw requires no authentication and enables remote privilege elevation, so treat it as high priority; apply Microsoft’s updates or mitigations immediately and restrict network exposure to the service.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-70352",
        "https://www.cve.org/CVERecord?id=CVE-2026-70352",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70352"
      ],
      "published": "2026-09-29T17:07:52Z",
      "updated": "2026-09-29T17:07:52Z"
    },
    {
      "id": "CVE-2026-65381",
      "url": "https://labs.diras.sa/cve/cve-2026-65381/",
      "title": "MacOS entitlement validation sandbox escape",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-862",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00354,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgently install Apple’s updates: the vendor published fixes for the affected branches (15.8, 26.7, 27), so patching is the fastest way to remove the risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65381",
        "https://www.cve.org/CVERecord?id=CVE-2026-65381",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-29T17:07:39Z",
      "updated": "2026-09-29T17:07:39Z"
    },
    {
      "id": "CVE-2026-69865",
      "url": "https://labs.diras.sa/cve/cve-2026-69865/",
      "title": "Azure Container Registry authorization bypass via user-controlled key",
      "vendor": "Microsoft",
      "product": "Azure Container Registry",
      "cwe": "CWE-639",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00815,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure Container Registry",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a remote, pre-auth vulnerability with maximum severity (CVSS 10.0) so prioritize mitigation now; immediately limit registry exposure and prepare to apply vendor fixes when they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69865",
        "https://www.cve.org/CVERecord?id=CVE-2026-69865",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69865"
      ],
      "published": "2026-09-29T17:06:37Z",
      "updated": "2026-09-29T17:06:37Z"
    },
    {
      "id": "CVE-2026-62874",
      "url": "https://labs.diras.sa/cve/cve-2026-62874/",
      "title": "Azure Billing insufficient data authenticity privilege escalation",
      "vendor": "Microsoft",
      "product": "Azure Billing",
      "cwe": "CWE-345",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
      },
      "epss": 0.00428,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "Azure Billing",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: the vulnerability allows remote, unauthenticated privilege elevation (CVSS 10.0) so prioritize applying Microsoft’s remediation guidance and reduce network exposure to Azure Billing immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62874",
        "https://www.cve.org/CVERecord?id=CVE-2026-62874",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62874"
      ],
      "published": "2026-09-29T17:06:24Z",
      "updated": "2026-09-29T17:06:24Z"
    },
    {
      "id": "CVE-2026-88773",
      "url": "https://labs.diras.sa/cve/cve-2026-88773/",
      "title": "Citrix ADC HTTP request/response smuggling allows pre-auth breach",
      "vendor": "Citrix",
      "product": "ADC",
      "cwe": "CWE-444",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00361,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        },
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37 FIPS",
          "fixed": "14.1-73.37 FIPS"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1-37.279 and NDcPP",
          "fixed": "13.1-37.279 and NDcPP"
        },
        {
          "branch": "Gateway 14.x",
          "affected": "before 14.1-73.37 FIPS",
          "fixed": "14.1-73.37 FIPS"
        },
        {
          "branch": "Gateway 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth, remotely reachable parsing bug in an internet-facing product and fixed builds are available (see vendor fixed releases), so prioritize patching exposed ADC/Gateway appliances or otherwise block access immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-88773",
        "https://www.cve.org/CVERecord?id=CVE-2026-88773",
        "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
      ],
      "published": "2026-09-29T17:06:11Z",
      "updated": "2026-09-29T17:06:11Z"
    },
    {
      "id": "CVE-2026-6837",
      "url": "https://labs.diras.sa/cve/cve-2026-6837/",
      "title": "Zyxel WAX650S firmware command injection post-auth (administrator)",
      "vendor": "Zyxel",
      "product": "WAX650S firmware",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01521,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "WAX650S firmware",
          "affected": "<= 7.10(ABRM.4)C0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this post-auth command injection, so prioritize remediation for internet-facing or widely accessible WAX650S devices. Restrict management access immediately and follow vendor guidance while a patch is awaited.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-6837",
        "https://www.cve.org/CVERecord?id=CVE-2026-6837",
        "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026"
      ],
      "published": "2026-09-29T17:05:59Z",
      "updated": "2026-09-29T17:05:59Z"
    },
    {
      "id": "CVE-2026-69414",
      "url": "https://labs.diras.sa/cve/cve-2026-69414/",
      "title": "Microsoft Malware Protection Engine elevation of privilege",
      "vendor": "Microsoft",
      "product": "Microsoft Malware Protection Engine",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00327,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.1.0.0 – before 1.1.26080.3",
          "fixed": "1.1.26080.3"
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so prioritize updating to the fixed build 1.1.26080.3 or apply vendor guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69414",
        "https://www.cve.org/CVERecord?id=CVE-2026-69414",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414"
      ],
      "published": "2026-09-29T17:05:48Z",
      "updated": "2026-09-29T17:05:48Z"
    },
    {
      "id": "CVE-2026-54998",
      "url": "https://labs.diras.sa/cve/cve-2026-54998/",
      "title": "Microsoft Exchange Online authorization bypass lets authorized users escalate privileges",
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Online",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00778,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft Exchange Online",
          "affected": "-",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for CVE-2026-54998, which raises immediate risk to internet-exposed Exchange Online tenants and warrants rapid mitigation or patching per vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-54998",
        "https://www.cve.org/CVERecord?id=CVE-2026-54998",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54998"
      ],
      "published": "2026-09-29T17:05:30Z",
      "updated": "2026-09-29T17:05:30Z"
    },
    {
      "id": "CVE-2026-47301",
      "url": "https://labs.diras.sa/cve/cve-2026-47301/",
      "title": "Microsoft Configuration Manager privilege escalation over network",
      "vendor": "Microsoft",
      "product": "Microsoft Configuration Manager",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00778,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft Configuration Manager 5.x",
          "affected": "1.0.0 – before 5.0.9135.1031",
          "fixed": "5.0.9135.1031"
        },
        {
          "branch": "Microsoft Configuration Manager 2509 5.x",
          "affected": "1.0.0 – before 5.0.9141.1030",
          "fixed": "5.0.9141.1030"
        },
        {
          "branch": "Microsoft Configuration Manager 2603 5.x",
          "affected": "1.0.0 – before 5.0.9146.1021",
          "fixed": "5.0.9146.1021"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize updating to the vendor fixed builds listed for your branch; restrict access to Configuration Manager while you patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-47301",
        "https://www.cve.org/CVERecord?id=CVE-2026-47301",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47301"
      ],
      "published": "2026-09-29T17:05:19Z",
      "updated": "2026-09-29T17:05:19Z"
    },
    {
      "id": "CVE-2026-20200",
      "url": "https://labs.diras.sa/cve/cve-2026-20200/",
      "title": "Cisco Unified Computing System (Standalone) authenticated remote code execution",
      "vendor": "Cisco",
      "product": "Cisco Unified Computing System (Standalone)",
      "cwe": "CWE-141",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00734,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "4.x",
          "affected": "4.3(1.230097)",
          "fixed": null
        },
        {
          "branch": "4.x",
          "affected": "4.3(1.230124)",
          "fixed": null
        },
        {
          "branch": "4.x",
          "affected": "4.3(1.230138)",
          "fixed": null
        },
        {
          "branch": "4.x",
          "affected": "4.3(2.230207)",
          "fixed": null
        },
        {
          "branch": "4.x",
          "affected": "4.3(2.230270)",
          "fixed": null
        },
        {
          "branch": "4.x",
          "affected": "4.3(2.240002)",
          "fixed": null
        },
        {
          "branch": "4.x",
          "affected": "4.3(3.240022)",
          "fixed": null
        },
        {
          "branch": "4.x",
          "affected": "4.3(3.240043)",
          "fixed": null
        },
        {
          "branch": "4.x",
          "affected": "4.3(4.240142)",
          "fixed": null
        },
        {
          "branch": "4.x",
          "affected": "4.3(4.240152)",
          "fixed": null
        }
      ],
      "dirasTake": "Act urgently: public exploit code exists for this flaw, so immediately restrict network access to the web management interface and follow vendor guidance to mitigate exposure.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20200",
        "https://www.cve.org/CVERecord?id=CVE-2026-20200",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU"
      ],
      "published": "2026-09-29T17:05:06Z",
      "updated": "2026-09-29T17:05:06Z"
    },
    {
      "id": "CVE-2026-28326",
      "url": "https://labs.diras.sa/cve/cve-2026-28326/",
      "title": "Access Rights Manager unauthenticated remote code execution",
      "vendor": "SolarWinds",
      "product": "Access Rights Manager",
      "cwe": "CWE-321",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00694,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "2026.x",
          "affected": "2026.2 and all previous versions",
          "fixed": null
        }
      ],
      "dirasTake": "Act urgently: public exploit code exists for this flaw, so reduce exposure immediately and implement vendor guidance or network restrictions where possible.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-28326",
        "https://www.cve.org/CVERecord?id=CVE-2026-28326",
        "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326",
        "https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/arm_2026-2-1_release_notes.htm",
        "https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm"
      ],
      "published": "2026-09-29T17:04:53Z",
      "updated": "2026-09-29T17:04:53Z"
    },
    {
      "id": "CVE-2026-58480",
      "url": "https://labs.diras.sa/cve/cve-2026-58480/",
      "title": "Blocksy Companion unauthenticated arbitrary file upload leads to remote code execution",
      "vendor": "Creative Themes",
      "product": "Blocksy Companion",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.03572,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.1.46 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this unauthenticated RCE, so reduce exposure immediately by disabling the Advanced Reviews upload functionality or removing the plugin until a vendor patch is applied.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-58480",
        "https://www.cve.org/CVERecord?id=CVE-2026-58480",
        "https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blocksy-companion/blocksy-companion-2146-unauthenticated-arbitrary-file-upload-via-blc-review-images-parameter",
        "https://patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability/wordpress-blocksy-companion-plugin-2-1-46-unauthenticated-arbitrary-file-upload-vulnerability",
        "https://wordpress.org/plugins/blocksy-companion/",
        "https://www.vulncheck.com/advisories/blocksy-companion-pro-unauthenticated-file-upload-via-save-attachments"
      ],
      "published": "2026-09-29T17:04:19Z",
      "updated": "2026-09-29T17:04:19Z"
    },
    {
      "id": "CVE-2026-15158",
      "url": "https://labs.diras.sa/cve/cve-2026-15158/",
      "title": "Blocksy Companion arbitrary file upload leading to remote code execution",
      "vendor": "creativethemeshq",
      "product": "Blocksy Companion",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01067,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.1.46 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "High urgency: this allows unauthenticated uploads that can lead to RCE when the paid plugin plus two extensions are enabled — disable or remove those extensions until the vendor issues a patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-15158",
        "https://www.cve.org/CVERecord?id=CVE-2026-15158",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/2df449b4-3f3b-4afc-b391-8d8d11710c07?source=cve",
        "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.46/framework/premium/extensions/woocommerce-extra/features/advanced-reviews/feature.php#L811",
        "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.46/framework/premium/extensions/custom-fonts/extension.php#L137"
      ],
      "published": "2026-09-29T17:04:10Z",
      "updated": "2026-09-29T17:04:10Z"
    },
    {
      "id": "CVE-2026-73532",
      "url": "https://labs.diras.sa/cve/cve-2026-73532/",
      "title": "Fluent Forms Pro embedded malicious code in tampered 6.2.7 build",
      "vendor": "WPManageNinja",
      "product": "Fluent Forms Pro",
      "cwe": "CWE-506",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00671,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "6.x",
          "affected": "6.2.7",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat sites running Fluent Forms Pro 6.2.7 as potentially compromised because the tampered build included a backdoor and persistent artifacts that survived plugin removal. Immediately isolate affected hosts and follow containment and remediation steps.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-73532",
        "https://www.cve.org/CVERecord?id=CVE-2026-73532",
        "https://wpmanageninja.com/security-incident-on-31-july-2026/",
        "https://wordpress.org/plugins/fluentform/",
        "https://patchstack.com/database/wordpress/plugin/fluentformpro/vulnerability/wordpress-fluent-forms-pro-add-on-pack-plugin-6-2-7-6-2-7-remote-code-execution-vulnerability",
        "https://www.vulncheck.com/advisories/fluent-forms-pro-embedded-malicious-code-via-tampered-plugin-build"
      ],
      "published": "2026-09-29T17:03:45Z",
      "updated": "2026-09-29T17:03:45Z"
    },
    {
      "id": "CVE-2026-19598",
      "url": "https://labs.diras.sa/cve/cve-2026-19598/",
      "title": "Pods – Custom Content Types and Fields privilege escalation via auth bypass",
      "vendor": "sc0ttkclark",
      "product": "Pods – Custom Content Types and Fields",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.03521,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.8 – 2.8.23.3",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.9 – 2.9.19.3",
          "fixed": null
        },
        {
          "branch": "3.x",
          "affected": "3.0 – 3.0.10.3",
          "fixed": null
        },
        {
          "branch": "3.x",
          "affected": "3.1 – 3.1.4.1",
          "fixed": null
        },
        {
          "branch": "3.x",
          "affected": "3.2 – 3.2.8.2",
          "fixed": null
        },
        {
          "branch": "3.x",
          "affected": "3.3 – 3.3.9",
          "fixed": null
        }
      ],
      "dirasTake": "Fix urgently: public exploit code exists and the flaw allows unauthenticated full administrator takeover, so treat internet-facing WordPress sites with this plugin as high risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-19598",
        "https://www.cve.org/CVERecord?id=CVE-2026-19598",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/3628032a-3121-45a7-8a78-cfcd8ba6af2f?source=cve",
        "https://plugins.trac.wordpress.org/browser/pods/tags/3.3.9/includes/general.php#L400"
      ],
      "published": "2026-09-29T17:03:34Z",
      "updated": "2026-09-29T17:03:34Z"
    },
    {
      "id": "CVE-2026-15748",
      "url": "https://labs.diras.sa/cve/cve-2026-15748/",
      "title": "Forminator Forms arbitrary file upload allows remote code execution",
      "vendor": "wpmudev",
      "product": "Forminator Forms – Contact Form, Payment Form & Custom Form Builder",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.06138,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.56.1 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists and no fix is yet available for affected versions, so sites using the plugin should assume high risk and take immediate mitigations.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-15748",
        "https://www.cve.org/CVERecord?id=CVE-2026-15748",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/263ac05d-f1ca-46e3-a43e-3b45eb8066d4?source=cve",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/fields/upload.php#L552",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/modules/custom-forms/front/front-action.php#L2767",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/modules/custom-forms/front/front-action.php#L738",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/helpers/helper-fields.php#L3425",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/abstracts/abstract-class-field.php#L2308",
        "https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/admin/classes/class-admin-ajax.php#L1196"
      ],
      "published": "2026-09-29T17:03:23Z",
      "updated": "2026-09-29T17:03:23Z"
    },
    {
      "id": "CVE-2026-78006",
      "url": "https://labs.diras.sa/cve/cve-2026-78006/",
      "title": "The Events Calendar pre-auth remote code execution via widget unserialize",
      "vendor": "stellarwp",
      "product": "The Events Calendar",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0147,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "6.x",
          "affected": "6.17.4 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists and no fixed release is recorded, so prioritize mitigating internet-facing sites running The Events Calendar. Immediately reduce exposure and apply the vendor's guidance where available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-78006",
        "https://www.cve.org/CVERecord?id=CVE-2026-78006",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/a0c67346-534a-4b67-a904-fa148703707a?source=cve",
        "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L213",
        "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L295",
        "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L255",
        "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Collections/Lazy_Post_Collection.php#L82",
        "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Collection_Trait.php#L247",
        "https://plugins.trac.wordpress.org/changeset?reponame=&old=3690576%40the-events-calendar&new=3690576%40the-events-calendar"
      ],
      "published": "2026-09-29T17:02:48Z",
      "updated": "2026-09-29T17:02:48Z"
    },
    {
      "id": "CVE-2026-78159",
      "url": "https://labs.diras.sa/cve/cve-2026-78159/",
      "title": "The Events Calendar remote code execution via widget parsing",
      "vendor": "stellarwp",
      "product": "The Events Calendar",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01394,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "6.x",
          "affected": "6.17.3 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: unauthenticated RCE with public exploit code available — immediately reduce exposure by disabling or restricting the comment/widget attack surface and monitor for exploit activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-78159",
        "https://www.cve.org/CVERecord?id=CVE-2026-78159",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c?source=cve",
        "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Element_Classes.php#L211",
        "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/views/v2/components/messages.php#L30",
        "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L279",
        "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L214",
        "https://plugins.trac.wordpress.org/changeset?reponame=&old=3667866%40the-events-calendar&new=3667866%40the-events-calendar",
        "https://plugins.trac.wordpress.org/changeset?reponame=&old=3667867%40the-events-calendar&new=3667867%40the-events-calendar"
      ],
      "published": "2026-09-29T17:02:36Z",
      "updated": "2026-09-29T17:02:36Z"
    },
    {
      "id": "CVE-2026-54107",
      "url": "https://labs.diras.sa/cve/cve-2026-54107/",
      "title": "Windows 10 Version 1607 race condition lets local users elevate privileges",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "cvss": {
        "version": "3.1",
        "score": 7,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00214,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7548",
          "fixed": "10.0.19044.7548"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7548",
          "fixed": "10.0.19045.7548"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.8875",
          "fixed": "10.0.26100.8875"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.8875",
          "fixed": "10.0.26200.8875"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2525",
          "fixed": "10.0.28000.2525"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23291",
          "fixed": "6.3.9600.23291"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this Win32K race condition, so prioritize installing the vendor updates that move affected builds to the fixed builds listed by Microsoft.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-54107",
        "https://www.cve.org/CVERecord?id=CVE-2026-54107",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54107"
      ],
      "published": "2026-09-29T17:02:19Z",
      "updated": "2026-09-29T17:02:19Z"
    },
    {
      "id": "CVE-2026-43813",
      "url": "https://labs.diras.sa/cve/cve-2026-43813/",
      "title": "IOS and iPadOS code signing bypass allows malicious apps to run",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 7.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00167,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgently update devices: public exploit code is available, so apply the 26.6 updates promptly to reduce risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-43813",
        "https://www.cve.org/CVERecord?id=CVE-2026-43813",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070"
      ],
      "published": "2026-09-29T17:02:09Z",
      "updated": "2026-09-29T17:02:09Z"
    },
    {
      "id": "CVE-2026-64725",
      "url": "https://labs.diras.sa/cve/cve-2026-64725/",
      "title": "IOS and iPadOS out-of-bounds write can let a local app crash the device",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 7.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
      },
      "epss": 0.00164,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so apply Apple’s security updates immediately for affected platforms or otherwise restrict untrusted app installs and monitor device stability.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64725",
        "https://www.cve.org/CVERecord?id=CVE-2026-64725",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T17:01:57Z",
      "updated": "2026-09-29T17:01:57Z"
    },
    {
      "id": "CVE-2026-19650",
      "url": "https://labs.diras.sa/cve/cve-2026-19650/",
      "title": "GitLab GraphQL GET-request mutation execution vulnerability",
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-352",
      "cvss": {
        "version": "3.1",
        "score": 7.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
      },
      "epss": 0.00615,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "18.x",
          "affected": "18.2 – before 18.11.11",
          "fixed": "18.11.11"
        },
        {
          "branch": "19.x",
          "affected": "19.0 – before 19.0.8",
          "fixed": "19.0.8"
        },
        {
          "branch": "19.x",
          "affected": "19.1 – before 19.1.6",
          "fixed": "19.1.6"
        },
        {
          "branch": "19.x",
          "affected": "19.2 – before 19.2.4",
          "fixed": "19.2.4"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize updating externally reachable GitLab instances to the listed fixed releases or block access to GraphQL endpoints until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-19650",
        "https://www.cve.org/CVERecord?id=CVE-2026-19650",
        "https://gitlab.com/gitlab-org/gitlab/-/work_items/612617",
        "https://hackerone.com/reports/3903669",
        "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/"
      ],
      "published": "2026-09-29T17:01:46Z",
      "updated": "2026-09-29T17:01:46Z"
    },
    {
      "id": "CVE-2026-69451",
      "url": "https://labs.diras.sa/cve/cve-2026-69451/",
      "title": "Windows 10 Version 1607 use-after-free in WMI allows privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 7.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0057,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize patching exposed systems; this is especially critical for internet-accessible hosts because an authenticated network attacker can gain elevated privileges.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69451",
        "https://www.cve.org/CVERecord?id=CVE-2026-69451",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69451"
      ],
      "published": "2026-09-29T17:01:31Z",
      "updated": "2026-09-29T17:01:31Z"
    },
    {
      "id": "CVE-2026-19760",
      "url": "https://labs.diras.sa/cve/cve-2026-19760/",
      "title": "WP Fastest Cache – Stored XSS via Host header in Combine JS",
      "vendor": "emrevona",
      "product": "WP Fastest Cache – WordPress Cache Plugin",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00404,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.5.0 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "High priority — this can be triggered without authentication when Polylang and Combine JS are enabled; disable Combine JS or deactivate Polylang on public sites until the vendor issues a patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-19760",
        "https://www.cve.org/CVERecord?id=CVE-2026-19760",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/69a22238-88e8-4ff5-8e2b-8c58a04ff154?source=cve",
        "https://plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.5.0/inc/js-utilities.php#L274",
        "https://plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.5.0/inc/js-utilities.php#L257",
        "https://plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.5.0/wpFastestCache.php#L507",
        "https://plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.4.9/inc/js-utilities.php#L274",
        "https://plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.4.9/inc/js-utilities.php#L257",
        "https://plugins.trac.wordpress.org/browser/wp-fastest-cache/tags/1.4.9/wpFastestCache.php#L507"
      ],
      "published": "2026-09-29T17:00:49Z",
      "updated": "2026-09-29T17:00:49Z"
    },
    {
      "id": "CVE-2026-18978",
      "url": "https://labs.diras.sa/cve/cve-2026-18978/",
      "title": "LiteSpeed Cache stored cross-site scripting via comments",
      "vendor": "litespeedtech",
      "product": "LiteSpeed Cache",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00368,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.8.1 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: there is no vendor patch available and the flaw enables stored XSS that executes in site visitors' browsers, increasing the risk to users and site sessions.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-18978",
        "https://www.cve.org/CVERecord?id=CVE-2026-18978",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/0b045f3d-8412-4e35-b369-2b485639274d?source=cve",
        "https://plugins.trac.wordpress.org/browser/litespeed-cache/trunk/src/media.cls.php#L1405",
        "https://plugins.trac.wordpress.org/browser/litespeed-cache/trunk/src/media.cls.php#L1358",
        "https://plugins.trac.wordpress.org/browser/litespeed-cache/trunk/src/media.cls.php#L1317",
        "https://plugins.trac.wordpress.org/browser/litespeed-cache/trunk/src/media.cls.php#L777",
        "https://plugins.trac.wordpress.org/changeset/3635849/litespeed-cache/trunk/src/media.cls.php",
        "https://plugins.trac.wordpress.org/changeset?old_path=%2Flitespeed-cache/tags/7.8.1&new_path=%2Flitespeed-cache/tags/7.9"
      ],
      "published": "2026-09-29T17:00:32Z",
      "updated": "2026-09-29T17:00:32Z"
    },
    {
      "id": "CVE-2026-83561",
      "url": "https://labs.diras.sa/cve/cve-2026-83561/",
      "title": "Complianz GDPR/CCPA Cookie Consent Banner stored cross-site scripting via comments",
      "vendor": "complianz",
      "product": "Complianz GDPR/CCPA Cookie Consent Banner",
      "cwe": "CWE-79",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
      },
      "epss": 0.00508,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.5.4 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: no vendor patch is available and the issue allows persistent XSS in visitors’ browsers; immediately disable the affected cookie/script blocker options and enforce strict comment moderation until an update is published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-83561",
        "https://www.cve.org/CVERecord?id=CVE-2026-83561",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/c53da813-0376-4c61-bfe0-fd8a2c946937?source=cve",
        "https://plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/integrations/plugins/elementor.php#L213",
        "https://plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/integrations/plugins/elementor.php#L206",
        "https://plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/integrations/plugins/elementor.php#L188",
        "https://plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/class-cookie-blocker.php#L828",
        "https://plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/class-cookie-blocker.php#L458",
        "https://plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/functions.php#L1232",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3686656%40complianz-gdpr%2Ftags%2F7.5.5&old=3674116%40complianz-gdpr%2Ftags%2F7.5.4",
        "https://plugins.trac.wordpress.org/changeset/3686618/complianz-gdpr/trunk/integrations/plugins/elementor.php",
        "https://plugins.trac.wordpress.org/changeset?reponame=&new=3686656%40complianz-gdpr%2Ftrunk&old=3674116%40complianz-gdpr%2Ftrunk"
      ],
      "published": "2026-09-29T17:00:19Z",
      "updated": "2026-09-29T17:00:19Z"
    },
    {
      "id": "CVE-2026-78906",
      "url": "https://labs.diras.sa/cve/cve-2026-78906/",
      "title": "Chrome ANGLE race condition remote code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00289,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.65 – before 152.0.7977.65",
          "fixed": "152.0.7977.65"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this Chrome ANGLE bug, so update to 152.0.7977.65 immediately and restrict exposure until systems are patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-78906",
        "https://www.cve.org/CVERecord?id=CVE-2026-78906",
        "https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html",
        "https://issues.chromium.org/issues/513923164"
      ],
      "published": "2026-09-29T16:59:56Z",
      "updated": "2026-09-29T16:59:56Z"
    },
    {
      "id": "CVE-2026-85045",
      "url": "https://labs.diras.sa/cve/cve-2026-85045/",
      "title": "Chrome V8 race condition allows remote code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-367",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00289,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.82 – before 152.0.7977.82",
          "fixed": "152.0.7977.82"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this Chrome V8 race condition, so update to the fixed Chrome 152.0.7977.82 immediately or block access to vulnerable builds until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85045",
        "https://www.cve.org/CVERecord?id=CVE-2026-85045",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html",
        "https://issues.chromium.org/issues/547819997"
      ],
      "published": "2026-09-29T16:59:46Z",
      "updated": "2026-09-29T16:59:46Z"
    },
    {
      "id": "CVE-2015-5287",
      "url": "https://labs.diras.sa/cve/cve-2015-5287/",
      "title": "Automatic Bug Reporting Tool symlink local privilege escalation",
      "vendor": "Red Hat",
      "product": "Automatic Bug Reporting Tool",
      "cwe": "CWE-59",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.04962,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-26",
        "dueDate": "2026-09-09"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [],
      "dirasTake": "Urgent: CISA placed this issue on the KEV catalog with a mandated remediation schedule and working exploit code is public, so prioritize mitigation for exposed ABRT installs immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2015-5287",
        "https://www.cve.org/CVERecord?id=CVE-2015-5287",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5287",
        "http://rhn.redhat.com/errata/RHSA-2015-2505.html",
        "https://www.exploit-db.com/exploits/38832/",
        "http://www.openwall.com/lists/oss-security/2015/12/01/1",
        "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html",
        "https://bugzilla.redhat.com/show_bug.cgi?id=1266837",
        "http://www.securityfocus.com/bid/78137",
        "https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e",
        "http://packetstormsecurity.com/files/154592/ABRT-sosreport-Privilege-Escalation.html"
      ],
      "published": "2026-09-29T16:59:35Z",
      "updated": "2026-09-29T16:59:35Z"
    },
    {
      "id": "CVE-2026-46680",
      "url": "https://labs.diras.sa/cve/cve-2026-46680/",
      "title": "Containerd runAsNonRoot bypass via large numeric User value",
      "vendor": "containerd",
      "product": "containerd",
      "cwe": "CWE-269",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00163,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "containerd",
          "affected": "< 1.7.32",
          "fixed": null
        },
        {
          "branch": "containerd",
          "affected": ">= 2.0.4, < 2.0.9",
          "fixed": null
        },
        {
          "branch": "containerd",
          "affected": ">= 2.0.10, < 2.2.4",
          "fixed": null
        },
        {
          "branch": "containerd",
          "affected": ">= 2.2.5, < 2.3.1",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent—public exploit code exists for this runAsNonRoot bypass, so treat exposed containerd hosts and image registries as high priority for mitigation and containment.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-46680",
        "https://www.cve.org/CVERecord?id=CVE-2026-46680",
        "https://github.com/containerd/containerd/security/advisories/GHSA-fqw6-gf59-qr4w"
      ],
      "published": "2026-09-29T16:58:41Z",
      "updated": "2026-09-29T16:58:41Z"
    },
    {
      "id": "CVE-2026-53362",
      "url": "https://labs.diras.sa/cve/cve-2026-53362/",
      "title": "Linux Kernel IPv6 frag handling local privilege escalation",
      "vendor": "Linux",
      "product": "Kernel",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00709,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-27",
        "dueDate": "2026-08-30"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "14200.x",
          "affected": "773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 14200d435af9a9eeb444f529fc2f689a236b7962",
          "fixed": "14200d435af9a9eeb444f529fc2f689a236b7962"
        },
        {
          "branch": "65.x",
          "affected": "773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 65fb14cbebb0cd0eff903a22d33537ddc8b95769",
          "fixed": "65fb14cbebb0cd0eff903a22d33537ddc8b95769"
        },
        {
          "branch": "46.x",
          "affected": "773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 46f201f8b4c39633a1fa3dc12459f506d470993d",
          "fixed": "46f201f8b4c39633a1fa3dc12459f506d470993d"
        },
        {
          "branch": "6374.x",
          "affected": "773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 6374fb9edf72c67a118a2c214a0dddd04c921e0a",
          "fixed": "6374fb9edf72c67a118a2c214a0dddd04c921e0a"
        },
        {
          "branch": "Linux",
          "affected": "773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before e9eacf19281ea2498b36291b56c9606118c2d74e",
          "fixed": "e9eacf19281ea2498b36291b56c9606118c2d74e"
        },
        {
          "branch": "736.x",
          "affected": "773ba4fe9104a64a54d1c00f0fb6ffb95def2b03 – before 736b380e28d0480c7bc3e022f1950f31fe53a7c5",
          "fixed": "736b380e28d0480c7bc3e022f1950f31fe53a7c5"
        },
        {
          "branch": "6.x",
          "affected": "6.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA placed CVE-2026-53362 on the Known Exploited Vulnerabilities catalog with a remediation deadline of 2026-08-30; apply available fixes or vendor mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-53362",
        "https://www.cve.org/CVERecord?id=CVE-2026-53362",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53362",
        "https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962",
        "https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769",
        "https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d",
        "https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a",
        "https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e",
        "https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5"
      ],
      "published": "2026-09-29T16:58:15Z",
      "updated": "2026-09-29T16:58:15Z"
    },
    {
      "id": "CVE-2026-49176",
      "url": "https://labs.diras.sa/cve/cve-2026-49176/",
      "title": "Windows 10/Server privilege escalation in WalletService (local)",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-269",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00328,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7548",
          "fixed": "10.0.19044.7548"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7548",
          "fixed": "10.0.19045.7548"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.8875",
          "fixed": "10.0.26100.8875"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.8875",
          "fixed": "10.0.26200.8875"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2525",
          "fixed": "10.0.28000.2525"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize updates. Microsoft published fixed builds for each affected branch; apply them or block local access where possible.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-49176",
        "https://www.cve.org/CVERecord?id=CVE-2026-49176",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49176"
      ],
      "published": "2026-09-29T16:57:49Z",
      "updated": "2026-09-29T16:57:49Z"
    },
    {
      "id": "CVE-2026-54992",
      "url": "https://labs.diras.sa/cve/cve-2026-54992/",
      "title": "Windows 10 Version 1607 heap-based buffer overflow local code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00337,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7548",
          "fixed": "10.0.19044.7548"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7548",
          "fixed": "10.0.19045.7548"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.8875",
          "fixed": "10.0.26100.8875"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.8875",
          "fixed": "10.0.26200.8875"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2525",
          "fixed": "10.0.28000.2525"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23291",
          "fixed": "6.3.9600.23291"
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so prioritize installing the provided fixes for the listed Windows 10, Windows 11 and Server builds or otherwise restrict local access immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-54992",
        "https://www.cve.org/CVERecord?id=CVE-2026-54992",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54992"
      ],
      "published": "2026-09-29T16:57:35Z",
      "updated": "2026-09-29T16:57:35Z"
    },
    {
      "id": "CVE-2026-58635",
      "url": "https://labs.diras.sa/cve/cve-2026-58635/",
      "title": "Windows 10 Version 1809 Narrator Braille command injection local privilege elevation",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-77",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00322,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7548",
          "fixed": "10.0.19044.7548"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7548",
          "fixed": "10.0.19045.7548"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.8875",
          "fixed": "10.0.26100.8875"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.8875",
          "fixed": "10.0.26200.8875"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2525",
          "fixed": "10.0.28000.2525"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows Server 2022 10.x",
          "affected": "10.0.20348.0 – before 10.0.20348.5386",
          "fixed": "10.0.20348.5386"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33158",
          "fixed": "10.0.26100.33158"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize updates; the strongest immediate mitigation is to install Microsoft’s fixed builds or restrict local account access until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-58635",
        "https://www.cve.org/CVERecord?id=CVE-2026-58635",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58635"
      ],
      "published": "2026-09-29T16:57:22Z",
      "updated": "2026-09-29T16:57:22Z"
    },
    {
      "id": "CVE-2026-50343",
      "url": "https://labs.diras.sa/cve/cve-2026-50343/",
      "title": "Windows Install Service local privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-269",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00298,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7548",
          "fixed": "10.0.19044.7548"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7548",
          "fixed": "10.0.19045.7548"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.8875",
          "fixed": "10.0.26100.8875"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.8875",
          "fixed": "10.0.26200.8875"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2525",
          "fixed": "10.0.28000.2525"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows Server 2022 10.x",
          "affected": "10.0.20348.0 – before 10.0.20348.5386",
          "fixed": "10.0.20348.5386"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33158",
          "fixed": "10.0.26100.33158"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize patching systems with any affected Windows 10, Windows 11, or Windows Server branch; the availability of exploit code makes updates and immediate mitigations critical.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-50343",
        "https://www.cve.org/CVERecord?id=CVE-2026-50343",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50343"
      ],
      "published": "2026-09-29T16:56:58Z",
      "updated": "2026-09-29T16:56:58Z"
    },
    {
      "id": "CVE-2026-50402",
      "url": "https://labs.diras.sa/cve/cve-2026-50402/",
      "title": "Windows NTFS numeric conversion local privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-681",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00333,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7548",
          "fixed": "10.0.19044.7548"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7548",
          "fixed": "10.0.19045.7548"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.8875",
          "fixed": "10.0.26100.8875"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.8875",
          "fixed": "10.0.26200.8875"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2525",
          "fixed": "10.0.28000.2525"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23291",
          "fixed": "6.3.9600.23291"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize patching systems; apply the vendor fixes or block untrusted local accounts immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-50402",
        "https://www.cve.org/CVERecord?id=CVE-2026-50402",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50402"
      ],
      "published": "2026-09-29T16:56:37Z",
      "updated": "2026-09-29T16:56:37Z"
    },
    {
      "id": "CVE-2026-28912",
      "url": "https://labs.diras.sa/cve/cve-2026-28912/",
      "title": "MacOS local privilege escalation via logic issue",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00173,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.7",
          "fixed": "14.8.7"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so update systems promptly; Apple published fixes for the affected branches. Prioritise patching hosts where untrusted local users have access.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-28912",
        "https://www.cve.org/CVERecord?id=CVE-2026-28912",
        "https://support.apple.com/en-us/127117",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071"
      ],
      "published": "2026-09-29T16:56:25Z",
      "updated": "2026-09-29T16:56:25Z"
    },
    {
      "id": "CVE-2026-39875",
      "url": "https://labs.diras.sa/cve/cve-2026-39875/",
      "title": "MacOS permission flaw local privilege escalation",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-276",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00153,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "High urgency: working exploit code is publicly available, so prioritize updates to the fixed releases (14.8.8, 15.7.8, 26.6) or isolate machines until you can patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-39875",
        "https://www.cve.org/CVERecord?id=CVE-2026-39875",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072"
      ],
      "published": "2026-09-29T16:56:15Z",
      "updated": "2026-09-29T16:56:15Z"
    },
    {
      "id": "CVE-2026-64747",
      "url": "https://labs.diras.sa/cve/cve-2026-64747/",
      "title": "IOS and iPadOS buffer overflow allows kernel code execution",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-120",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00194,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 18.x",
          "affected": "before 18.7.10",
          "fixed": "18.7.10"
        },
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "macOS 14.x",
          "affected": "before 14.8.8",
          "fixed": "14.8.8"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.7.8",
          "fixed": "15.7.8"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "tvOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "visionOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        },
        {
          "branch": "watchOS 26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so update affected Apple platforms immediately to the fixed releases listed by the vendor to prevent local, user‑initiated kernel compromise.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64747",
        "https://www.cve.org/CVERecord?id=CVE-2026-64747",
        "https://support.apple.com/en-us/128066",
        "https://support.apple.com/en-us/128067",
        "https://support.apple.com/en-us/128068",
        "https://support.apple.com/en-us/128069",
        "https://support.apple.com/en-us/128070",
        "https://support.apple.com/en-us/128071",
        "https://support.apple.com/en-us/128072",
        "https://support.apple.com/en-us/148287"
      ],
      "published": "2026-09-29T16:56:04Z",
      "updated": "2026-09-29T16:56:04Z"
    },
    {
      "id": "CVE-2026-14266",
      "url": "https://labs.diras.sa/cve/cve-2026-14266/",
      "title": "7-Zip XZ heap buffer overflow remote code execution",
      "vendor": "7-Zip",
      "product": "7-Zip",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00742,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "26.x",
          "affected": "26.01",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so prioritize mitigation now; treat exposed systems and users who open untrusted archives as high risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-14266",
        "https://www.cve.org/CVERecord?id=CVE-2026-14266",
        "https://www.zerodayinitiative.com/advisories/ZDI-26-444/"
      ],
      "published": "2026-09-29T16:55:51Z",
      "updated": "2026-09-29T16:55:51Z"
    },
    {
      "id": "CVE-2026-54984",
      "url": "https://labs.diras.sa/cve/cve-2026-54984/",
      "title": "Windows 10 Version 1607 heap buffer overflow local code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00466,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7663",
          "fixed": "10.0.19044.7663"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7663",
          "fixed": "10.0.19045.7663"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9168",
          "fixed": "10.0.26100.9168"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9168",
          "fixed": "10.0.26200.9168"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2704",
          "fixed": "10.0.28000.2704"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize installing the vendor fixes for impacted builds or restrict local exposure immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-54984",
        "https://www.cve.org/CVERecord?id=CVE-2026-54984",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54984"
      ],
      "published": "2026-09-29T16:55:41Z",
      "updated": "2026-09-29T16:55:41Z"
    },
    {
      "id": "CVE-2026-62735",
      "url": "https://labs.diras.sa/cve/cve-2026-62735/",
      "title": "Windows HTTP.sys heap buffer overflow local privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00333,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7663",
          "fixed": "10.0.19044.7663"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7663",
          "fixed": "10.0.19045.7663"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9168",
          "fixed": "10.0.26100.9168"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9168",
          "fixed": "10.0.26200.9168"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2704",
          "fixed": "10.0.28000.2704"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        }
      ],
      "dirasTake": "Patch urgently: public exploit code is available, so prioritize applying the vendor updates listed below for affected builds or otherwise restrict and monitor local access to vulnerable hosts.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62735",
        "https://www.cve.org/CVERecord?id=CVE-2026-62735",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62735"
      ],
      "published": "2026-09-29T16:55:25Z",
      "updated": "2026-09-29T16:55:25Z"
    },
    {
      "id": "CVE-2026-62737",
      "url": "https://labs.diras.sa/cve/cve-2026-62737/",
      "title": "Windows 11 untrusted pointer dereference local privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-822",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00333,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9168",
          "fixed": "10.0.26100.9168"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9168",
          "fixed": "10.0.26200.9168"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2704",
          "fixed": "10.0.28000.2704"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33296",
          "fixed": "10.0.26100.33296"
        },
        {
          "branch": "Windows Server 2025 (Server Core installation) 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33296",
          "fixed": "10.0.26100.33296"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize installing the vendor fixes for the listed builds immediately or restrict local account exposure until updates can be applied.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62737",
        "https://www.cve.org/CVERecord?id=CVE-2026-62737",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62737"
      ],
      "published": "2026-09-29T16:55:11Z",
      "updated": "2026-09-29T16:55:11Z"
    },
    {
      "id": "CVE-2026-66804",
      "url": "https://labs.diras.sa/cve/cve-2026-66804/",
      "title": "Windows 10 Version 22H2 cross-device service local privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 22H2",
      "cwe": "CWE-284",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00298,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7663",
          "fixed": "10.0.19045.7663"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9168",
          "fixed": "10.0.26100.9168"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9168",
          "fixed": "10.0.26200.9168"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2704",
          "fixed": "10.0.28000.2704"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so apply the vendor updates immediately; the vulnerability allows privilege elevation by a local authenticated user and fixed builds are published.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-66804",
        "https://www.cve.org/CVERecord?id=CVE-2026-66804",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804"
      ],
      "published": "2026-09-29T16:54:59Z",
      "updated": "2026-09-29T16:54:59Z"
    },
    {
      "id": "CVE-2026-69328",
      "url": "https://labs.diras.sa/cve/cve-2026-69328/",
      "title": "Windows 10 Version 1607 untrusted search path local privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-426",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00457,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        }
      ],
      "dirasTake": "Urgent: apply the vendor fixes immediately because public exploit code exists for this untrusted-search-path privilege escalation. Patch exposed and reachable systems without delay.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-69328",
        "https://www.cve.org/CVERecord?id=CVE-2026-69328",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69328"
      ],
      "published": "2026-09-29T16:54:48Z",
      "updated": "2026-09-29T16:54:48Z"
    },
    {
      "id": "CVE-2026-49881",
      "url": "https://labs.diras.sa/cve/cve-2026-49881/",
      "title": "Android InCallController logic error local privilege escalation",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00101,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "17.x",
          "affected": "17",
          "fixed": null
        }
      ],
      "dirasTake": "Fix this urgently: public exploit code exists and the bug allows local arbitrary code execution without user interaction, so prioritize mitigation for Android 17 devices reachable to untrusted local apps.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-49881",
        "https://www.cve.org/CVERecord?id=CVE-2026-49881",
        "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
      ],
      "published": "2026-09-29T16:54:33Z",
      "updated": "2026-09-29T16:54:33Z"
    },
    {
      "id": "CVE-2026-43783",
      "url": "https://labs.diras.sa/cve/cve-2026-43783/",
      "title": "MacOS race condition lets low-privileged app gain root",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00129,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "26.x",
          "affected": "before 26.6",
          "fixed": "26.6"
        }
      ],
      "dirasTake": "Urgent: install macOS 26.6 immediately because public exploit code exists and the vulnerability allows a local unprivileged app to escalate to root.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-43783",
        "https://www.cve.org/CVERecord?id=CVE-2026-43783",
        "https://support.apple.com/en-us/128067"
      ],
      "published": "2026-09-29T16:54:23Z",
      "updated": "2026-09-29T16:54:23Z"
    },
    {
      "id": "CVE-2026-43786",
      "url": "https://labs.diras.sa/cve/cve-2026-43786/",
      "title": "MacOS entitlement check bypass lets local user gain root privileges",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-280",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00154,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize updates — Apple released fixes in 15.8, 26.7, and 27. Apply patches quickly for any systems with local untrusted users.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-43786",
        "https://www.cve.org/CVERecord?id=CVE-2026-43786",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-29T16:53:58Z",
      "updated": "2026-09-29T16:53:58Z"
    },
    {
      "id": "CVE-2026-84568",
      "url": "https://labs.diras.sa/cve/cve-2026-84568/",
      "title": "MacOS path traversal remote code execution (root)",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00194,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Treat this as urgent: public exploit code exists that targets a vulnerability allowing root code execution, so prioritize installing the vendor fixes for affected macOS branches immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84568",
        "https://www.cve.org/CVERecord?id=CVE-2026-84568",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-29T16:53:47Z",
      "updated": "2026-09-29T16:53:47Z"
    },
    {
      "id": "CVE-2026-87886",
      "url": "https://labs.diras.sa/cve/cve-2026-87886/",
      "title": "Acronis Backup local privilege escalation via insecure permissions",
      "vendor": "Acronis",
      "product": "Backup",
      "cwe": "CWE-276",
      "cvss": {
        "version": "3.0",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00233,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-16",
        "dueDate": "2026-09-19"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "Acronis Backup plugin for cPanel & WHM 1.x",
          "affected": "unspecified – before 1.9.3.1021",
          "fixed": "1.9.3.1021"
        },
        {
          "branch": "Acronis Backup extension for Plesk 1.x",
          "affected": "unspecified – before 1.8.11.638",
          "fixed": "1.8.11.638"
        },
        {
          "branch": "Acronis Backup plugin for DirectAdmin 1.x",
          "affected": "unspecified – before 1.2.3.238",
          "fixed": "1.2.3.238"
        }
      ],
      "dirasTake": "Urgent: this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a rapid remediation requirement, so prioritize updating or mitigating exposed hosts immediately. The decisive fact is CISA’s KEV listing and its short remediation deadline.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-87886",
        "https://www.cve.org/CVERecord?id=CVE-2026-87886",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87886",
        "https://security-advisory.acronis.com/advisories/SEC-10986"
      ],
      "published": "2026-09-29T16:53:36Z",
      "updated": "2026-09-29T16:53:36Z"
    },
    {
      "id": "CVE-2026-62911",
      "url": "https://labs.diras.sa/cve/cve-2026-62911/",
      "title": "Microsoft Exchange Server authentication bypass (capture-replay)",
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-294",
      "cvss": {
        "version": "3.1",
        "score": 8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00694,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft Exchange Server 2016 Cumulative Update 23 15.x",
          "affected": "15.01.0.0 – before 15.01.2507.072",
          "fixed": "15.01.2507.072"
        },
        {
          "branch": "Microsoft Exchange Server 2019 Cumulative Update 14 15.x",
          "affected": "15.02.0.0 – before 15.02.1544.044",
          "fixed": "15.02.1544.044"
        },
        {
          "branch": "Microsoft Exchange Server 2019 Cumulative Update 15 15.x",
          "affected": "15.02.0.0 – before 15.02.1748.049",
          "fixed": "15.02.1748.049"
        },
        {
          "branch": "Microsoft Exchange Server Subscription Edition RTM 15.x",
          "affected": "15.02.0.0 – before 15.02.2562.046",
          "fixed": "15.02.2562.046"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so patch quickly; a working exploit is publicly available and fixes are released for the affected Exchange builds.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-62911",
        "https://www.cve.org/CVERecord?id=CVE-2026-62911",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911"
      ],
      "published": "2026-09-29T16:53:21Z",
      "updated": "2026-09-29T16:53:21Z"
    },
    {
      "id": "CVE-2026-50338",
      "url": "https://labs.diras.sa/cve/cve-2026-50338/",
      "title": "Azure Spring Apps improper authentication privilege escalation",
      "vendor": "Microsoft",
      "product": "Azure Spring Apps",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 8.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00517,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "1.0.0 – before 7.3.0",
          "fixed": "7.3.0"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this vulnerability, so prioritize remediation; upgrade to the fixed release or immediately limit network exposure and monitor for suspicious activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-50338",
        "https://www.cve.org/CVERecord?id=CVE-2026-50338",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50338"
      ],
      "published": "2026-09-29T16:53:08Z",
      "updated": "2026-09-29T16:53:08Z"
    },
    {
      "id": "CVE-2026-53413",
      "url": "https://labs.diras.sa/cve/cve-2026-53413/",
      "title": "Zoom Clients annotator buffer overwrite remote code execution",
      "vendor": "Zoom Communications",
      "product": "Zoom Clients",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 8.3,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00494,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "Zoom Clients",
          "affected": "see references",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this flaw, so prioritize mitigation now; restrict meeting exposure, apply vendor guidance, and prepare to install vendor patches when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-53413",
        "https://www.cve.org/CVERecord?id=CVE-2026-53413",
        "https://www.zoom.com/en/trust/security-bulletin/zsb-26015"
      ],
      "published": "2026-09-29T16:52:54Z",
      "updated": "2026-09-29T16:52:54Z"
    },
    {
      "id": "CVE-2026-85048",
      "url": "https://labs.diras.sa/cve/cve-2026-85048/",
      "title": "Chrome use-after-free in Compositing allows renderer escape and code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 8.3,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00404,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.82 – before 152.0.7977.82",
          "fixed": "152.0.7977.82"
        }
      ],
      "dirasTake": "Apply the vendor update to 152.0.7977.82 immediately: public exploit code exists, so this is high urgency despite any mitigations.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85048",
        "https://www.cve.org/CVERecord?id=CVE-2026-85048",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html",
        "https://issues.chromium.org/issues/540357382"
      ],
      "published": "2026-09-29T16:52:39Z",
      "updated": "2026-09-29T16:52:39Z"
    },
    {
      "id": "CVE-2026-65647",
      "url": "https://labs.diras.sa/cve/cve-2026-65647/",
      "title": "Plesk Migrator symlink flaw allows authenticated users to run code as root",
      "vendor": "WebPros",
      "product": "Plesk Migrator",
      "cwe": "CWE-59",
      "cvss": {
        "version": "4.0",
        "score": 8.7,
        "severity": "high",
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": 0.00743,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Plesk Migrator 2.x",
          "affected": "before 2.36.0",
          "fixed": "2.36.0"
        },
        {
          "branch": "Plesk Site Import 1.x",
          "affected": "before 1.12.1",
          "fixed": "1.12.1"
        }
      ],
      "dirasTake": "Patch urgently: public exploit code exists and vendor updates are available (2.36.0 and 1.12.1), so prioritize upgrading exposed systems immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65647",
        "https://www.cve.org/CVERecord?id=CVE-2026-65647",
        "https://support.plesk.com/hc/en-us/articles/42871001389207-Vulnerability-CVE-2026-65647-in-Plesk-s-Site-Import-and-Migrator-extensions"
      ],
      "published": "2026-09-29T16:52:27Z",
      "updated": "2026-09-29T16:52:27Z"
    },
    {
      "id": "CVE-2025-62593",
      "url": "https://labs.diras.sa/cve/cve-2025-62593/",
      "title": "Ray code injection via browser leading to remote code execution",
      "vendor": "Ray-Project",
      "product": "Ray",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.62459,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-17",
        "dueDate": "2026-08-20"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "ray",
          "affected": "< 2.52.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this CVE is on CISA’s Known Exploited Vulnerabilities list with a near-term federal remediation due date, and public exploit code exists—treat exposed developer instances as high priority for immediate mitigation.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2025-62593",
        "https://www.cve.org/CVERecord?id=CVE-2025-62593",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-62593",
        "https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v",
        "https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09"
      ],
      "published": "2026-09-29T16:52:15Z",
      "updated": "2026-09-29T16:52:15Z"
    },
    {
      "id": "CVE-2026-53266",
      "url": "https://labs.diras.sa/cve/cve-2026-53266/",
      "title": "Linux Kernel ebtables SNAT ARP rewrite out-of-bounds write",
      "vendor": "Linux",
      "product": "Kernel",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00645,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-18",
        "dueDate": "2026-09-21"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Linux",
          "affected": "63137bc5882a1882c553d389fdeeeace86ee1741 – before bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
          "fixed": "bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87"
        },
        {
          "branch": "76280.x",
          "affected": "63137bc5882a1882c553d389fdeeeace86ee1741 – before 76280b78cc9f23bdc6438e10ad6dff148ef8375b",
          "fixed": "76280b78cc9f23bdc6438e10ad6dff148ef8375b"
        },
        {
          "branch": "Linux",
          "affected": "63137bc5882a1882c553d389fdeeeace86ee1741 – before b7e91939ba9be805a62a257fa4e227dffbb88fa0",
          "fixed": "b7e91939ba9be805a62a257fa4e227dffbb88fa0"
        },
        {
          "branch": "Linux",
          "affected": "63137bc5882a1882c553d389fdeeeace86ee1741 – before afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
          "fixed": "afd64b59c3de9bbbdd3759e834fdc55cda716e0b"
        },
        {
          "branch": "153.x",
          "affected": "63137bc5882a1882c553d389fdeeeace86ee1741 – before 153ea96c806aea395daba907a4f88480b6ad5093",
          "fixed": "153ea96c806aea395daba907a4f88480b6ad5093"
        },
        {
          "branch": "Linux",
          "affected": "63137bc5882a1882c553d389fdeeeace86ee1741 – before b18675263db1147c8e1cab625400c13a0d87bd2d",
          "fixed": "b18675263db1147c8e1cab625400c13a0d87bd2d"
        },
        {
          "branch": "Linux",
          "affected": "63137bc5882a1882c553d389fdeeeace86ee1741 – before c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
          "fixed": "c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5"
        },
        {
          "branch": "67.x",
          "affected": "63137bc5882a1882c553d389fdeeeace86ee1741 – before 67ba971ae02514d85818fe0c32549ab4bfa3bf49",
          "fixed": "67ba971ae02514d85818fe0c32549ab4bfa3bf49"
        },
        {
          "branch": "2.x",
          "affected": "2f3839075a5f8dcf116c1abe35b36b018ac62445",
          "fixed": null
        },
        {
          "branch": "51.x",
          "affected": "51ba2945a8ef65ae437c8f9ba05f0343aa82ae5b",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added CVE-2026-53266 to its Known Exploited Vulnerabilities catalog with a short federal remediation deadline, so prioritize installing the kernel fixes or mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-53266",
        "https://www.cve.org/CVERecord?id=CVE-2026-53266",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-53266",
        "https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87",
        "https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b",
        "https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0",
        "https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b",
        "https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093",
        "https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d",
        "https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5",
        "https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49"
      ],
      "published": "2026-09-29T16:52:01Z",
      "updated": "2026-09-29T16:52:01Z"
    },
    {
      "id": "CVE-2026-14431",
      "url": "https://labs.diras.sa/cve/cve-2026-14431/",
      "title": "Chrome V8 type confusion lets remote code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00451,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "150.x",
          "affected": "150.0.7871.46 – before 150.0.7871.46",
          "fixed": "150.0.7871.46"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize updating Chrome to 150.0.7871.46 or later immediately to remove the exposed V8 type confusion.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-14431",
        "https://www.cve.org/CVERecord?id=CVE-2026-14431",
        "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
        "https://issues.chromium.org/issues/523884658"
      ],
      "published": "2026-09-29T16:51:45Z",
      "updated": "2026-09-29T16:51:45Z"
    },
    {
      "id": "CVE-2026-50369",
      "url": "https://labs.diras.sa/cve/cve-2026-50369/",
      "title": "Windows 10 Version 1607 Remote Desktop Services use-after-free elevation of privilege",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00701,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7548",
          "fixed": "10.0.19044.7548"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7548",
          "fixed": "10.0.19045.7548"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.8875",
          "fixed": "10.0.26100.8875"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.8875",
          "fixed": "10.0.26200.8875"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2525",
          "fixed": "10.0.28000.2525"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23291",
          "fixed": "6.3.9600.23291"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this remote elevation-of-privilege bug, so prioritize installing Microsoft's fixes or blocking Remote Desktop exposure immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-50369",
        "https://www.cve.org/CVERecord?id=CVE-2026-50369",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50369"
      ],
      "published": "2026-09-29T16:51:36Z",
      "updated": "2026-09-29T16:51:36Z"
    },
    {
      "id": "CVE-2026-54121",
      "url": "https://labs.diras.sa/cve/cve-2026-54121/",
      "title": "Windows 10 AD CS improper authorization privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-285",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00778,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23291",
          "fixed": "6.3.9600.23291"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23291",
          "fixed": "6.3.9600.23291"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        }
      ],
      "dirasTake": "Treat this as high priority — public exploit code exists for CVE-2026-54121, so install the vendor updates or mitigations immediately to reduce risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-54121",
        "https://www.cve.org/CVERecord?id=CVE-2026-54121",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121"
      ],
      "published": "2026-09-29T16:51:23Z",
      "updated": "2026-09-29T16:51:23Z"
    },
    {
      "id": "CVE-2026-65591",
      "url": "https://labs.diras.sa/cve/cve-2026-65591/",
      "title": "N8n sanitizer bypass authenticated remote code execution",
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-917",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00694,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "before 1.123.64",
          "fixed": "1.123.64"
        },
        {
          "branch": "2.x",
          "affected": "before 2.30.1",
          "fixed": "2.30.1"
        },
        {
          "branch": "2.x",
          "affected": "before 2.29.8",
          "fixed": "2.29.8"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so apply the vendor fixes immediately or isolate instances that allow workflow creation/modification to reduce exposure.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65591",
        "https://www.cve.org/CVERecord?id=CVE-2026-65591",
        "https://github.com/n8n-io/n8n/security/advisories/GHSA-pm35-fqvh-cq5g",
        "https://www.vulncheck.com/advisories/n8n-before-sanitizer-bypass-remote-code-execution"
      ],
      "published": "2026-09-29T16:51:11Z",
      "updated": "2026-09-29T16:51:11Z"
    },
    {
      "id": "CVE-2026-42016",
      "url": "https://labs.diras.sa/cve/cve-2026-42016/",
      "title": "Artifactory incorrect authorization privilege escalation",
      "vendor": "JFrog",
      "product": "Artifactory",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.08643,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-11",
        "dueDate": "2026-09-25"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "before 7.133.11",
          "fixed": "7.133.11"
        }
      ],
      "dirasTake": "Urgent: CISA added this vulnerability to its KEV catalog with a remediation due date, signalling immediate prioritization; apply the vendor fix or mitigations without delay for internet-facing Artifactory instances.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-42016",
        "https://www.cve.org/CVERecord?id=CVE-2026-42016",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016",
        "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
        "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      ],
      "published": "2026-09-29T16:50:54Z",
      "updated": "2026-09-29T16:50:54Z"
    },
    {
      "id": "CVE-2026-17633",
      "url": "https://labs.diras.sa/cve/cve-2026-17633/",
      "title": "Langflow OSS code injection allows authenticated remote code execution",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00676,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.10.3",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this authenticated code-injection flaw, so exposed Langflow OSS instances should be isolated or remediated immediately. Treat internet-facing installations and shared environments as highest priority because an attacker only needs an account and network access.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-17633",
        "https://www.cve.org/CVERecord?id=CVE-2026-17633",
        "https://www.ibm.com/support/pages/node/7282646"
      ],
      "published": "2026-09-29T16:50:41Z",
      "updated": "2026-09-29T16:50:41Z"
    },
    {
      "id": "CVE-2026-49179",
      "url": "https://labs.diras.sa/cve/cve-2026-49179/",
      "title": "Windows Active Directory command injection remote code execution",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-77",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00863,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7663",
          "fixed": "10.0.19044.7663"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7663",
          "fixed": "10.0.19045.7663"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9168",
          "fixed": "10.0.26100.9168"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9168",
          "fixed": "10.0.26200.9168"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2704",
          "fixed": "10.0.28000.2704"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so prioritize patching systems exposed to untrusted networks and apply the listed fixes immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-49179",
        "https://www.cve.org/CVERecord?id=CVE-2026-49179",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49179"
      ],
      "published": "2026-09-29T16:50:31Z",
      "updated": "2026-09-29T16:50:31Z"
    },
    {
      "id": "CVE-2026-65640",
      "url": "https://labs.diras.sa/cve/cve-2026-65640/",
      "title": "WordPress PostScript upload remote code execution via upload_files",
      "vendor": "WordPress",
      "product": "WordPress",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.0",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00796,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "before 7.0.4",
          "fixed": "7.0.4"
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so update immediately to 7.0.4 or apply mitigations; the availability of exploit code makes exposure of sites with upload-capable accounts a high-risk vector.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65640",
        "https://www.cve.org/CVERecord?id=CVE-2026-65640",
        "https://wordpress.org/news/2026/08/wordpress-7-0-4-release/"
      ],
      "published": "2026-09-29T16:50:15Z",
      "updated": "2026-09-29T16:50:15Z"
    },
    {
      "id": "CVE-2026-74939",
      "url": "https://labs.diras.sa/cve/cve-2026-74939/",
      "title": "Firefox DOM navigation privilege escalation vulnerability",
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00454,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [],
      "dirasTake": "Act urgently: public exploit code exists and the flaw requires no prior privileges (CVSS PR:N), so prioritize reducing exposure and monitoring until Mozilla publishes and you deploy a vendor update.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-74939",
        "https://www.cve.org/CVERecord?id=CVE-2026-74939",
        "https://bugzilla.mozilla.org/show_bug.cgi?id=2054416",
        "https://www.mozilla.org/security/advisories/mfsa2026-74/",
        "https://www.mozilla.org/security/advisories/mfsa2026-75/",
        "https://www.mozilla.org/security/advisories/mfsa2026-76/",
        "https://www.mozilla.org/security/advisories/mfsa2026-77/",
        "https://www.mozilla.org/security/advisories/mfsa2026-78/",
        "https://www.mozilla.org/security/advisories/mfsa2026-79/",
        "https://www.mozilla.org/security/advisories/mfsa2026-80/"
      ],
      "published": "2026-09-29T16:50:05Z",
      "updated": "2026-09-29T16:50:05Z"
    },
    {
      "id": "CVE-2026-10053",
      "url": "https://labs.diras.sa/cve/cve-2026-10053/",
      "title": "GitLab package registry path traversal leads to authenticated remote code execution",
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00773,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "19.x",
          "affected": "18.8 – before 19.0.6",
          "fixed": "19.0.6"
        },
        {
          "branch": "19.x",
          "affected": "19.1 – before 19.1.4",
          "fixed": "19.1.4"
        },
        {
          "branch": "19.x",
          "affected": "19.2 – before 19.2.2",
          "fixed": "19.2.2"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize updating exposed GitLab instances to the fixed releases listed by GitLab or immediately restrict access to the package registry and monitor for suspicious activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-10053",
        "https://www.cve.org/CVERecord?id=CVE-2026-10053",
        "https://gitlab.com/gitlab-org/gitlab/-/work_items/601596",
        "https://hackerone.com/reports/3754194"
      ],
      "published": "2026-09-29T16:49:54Z",
      "updated": "2026-09-29T16:49:54Z"
    },
    {
      "id": "CVE-2026-78905",
      "url": "https://labs.diras.sa/cve/cve-2026-78905/",
      "title": "Chrome ANGLE type confusion allows remote code execution from a web page",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00451,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.65 – before 152.0.7977.65",
          "fixed": "152.0.7977.65"
        }
      ],
      "dirasTake": "Urgently update affected Chrome installs because public exploit code exists for this ANGLE type confusion; applying the fixed build 152.0.7977.65 removes the vulnerability.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-78905",
        "https://www.cve.org/CVERecord?id=CVE-2026-78905",
        "https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html",
        "https://issues.chromium.org/issues/517245017"
      ],
      "published": "2026-09-29T16:49:24Z",
      "updated": "2026-09-29T16:49:24Z"
    },
    {
      "id": "CVE-2026-78938",
      "url": "https://labs.diras.sa/cve/cve-2026-78938/",
      "title": "Chrome type confusion in V8 remote code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00451,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.65 – before 152.0.7977.65",
          "fixed": "152.0.7977.65"
        }
      ],
      "dirasTake": "High urgency: public exploit code exists for this Chrome V8 issue, so update immediately to the fixed release 152.0.7977.65 or apply mitigations to limit exposure.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-78938",
        "https://www.cve.org/CVERecord?id=CVE-2026-78938",
        "https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html",
        "https://issues.chromium.org/issues/545767601"
      ],
      "published": "2026-09-29T16:49:15Z",
      "updated": "2026-09-29T16:49:15Z"
    },
    {
      "id": "CVE-2026-79266",
      "url": "https://labs.diras.sa/cve/cve-2026-79266/",
      "title": "Chrome DevTools use-after-free allows extension to execute code",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00382,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.65 – before 152.0.7977.65",
          "fixed": "152.0.7977.65"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this Chrome DevTools use-after-free, so update immediately to the fixed build 152.0.7977.65 and remove or block untrusted extensions until you can patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-79266",
        "https://www.cve.org/CVERecord?id=CVE-2026-79266",
        "https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html",
        "https://issues.chromium.org/issues/537145191"
      ],
      "published": "2026-09-29T16:49:01Z",
      "updated": "2026-09-29T16:49:01Z"
    },
    {
      "id": "CVE-2026-18729",
      "url": "https://labs.diras.sa/cve/cve-2026-18729/",
      "title": "Langflow OSS authenticated remote code execution",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01946,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.11.1",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so prioritize mitigation now by restricting access and applying vendor guidance where available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-18729",
        "https://www.cve.org/CVERecord?id=CVE-2026-18729",
        "https://www.ibm.com/support/pages/node/7284733"
      ],
      "published": "2026-09-29T16:48:51Z",
      "updated": "2026-09-29T16:48:51Z"
    },
    {
      "id": "CVE-2026-65643",
      "url": "https://labs.diras.sa/cve/cve-2026-65643/",
      "title": "CPanel eval injection authenticated code execution as root",
      "vendor": "WebPros",
      "product": "cPanel",
      "cwe": "CWE-95",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00875,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "11.x",
          "affected": "before 11.110.0.141",
          "fixed": "11.110.0.141"
        },
        {
          "branch": "11.x",
          "affected": "11.112.0.0 – before 11.134.0.53",
          "fixed": "11.134.0.53"
        },
        {
          "branch": "11.x",
          "affected": "11.136.0.0 – before 11.136.0.37",
          "fixed": "11.136.0.37"
        },
        {
          "branch": "11.x",
          "affected": "11.138.0.0 – before 11.138.0.2",
          "fixed": "11.138.0.2"
        },
        {
          "branch": "11.x",
          "affected": "11.138.1.0 – before 11.138.1.7",
          "fixed": "11.138.1.7"
        }
      ],
      "dirasTake": "Urgent — public exploit code exists, so vulnerable cPanel servers with any user accounts reachable over the network should be patched or isolated immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65643",
        "https://www.cve.org/CVERecord?id=CVE-2026-65643",
        "https://support.cpanel.net/hc/en-us/articles/42959571221527-Security-CVE-2026-65643-Park-API-Vulnerability-August-27-2026"
      ],
      "published": "2026-09-29T16:48:38Z",
      "updated": "2026-09-29T16:48:38Z"
    },
    {
      "id": "CVE-2026-84645",
      "url": "https://labs.diras.sa/cve/cve-2026-84645/",
      "title": "Jenkins remote code execution via crafted config.xml object injection",
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0079,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "Jenkins",
          "affected": "all versions",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — exploit code is public and no fixed version is available, and the flaw affects all Jenkins releases; reduce exposure and tighten access immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84645",
        "https://www.cve.org/CVERecord?id=CVE-2026-84645",
        "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3972"
      ],
      "published": "2026-09-29T16:48:24Z",
      "updated": "2026-09-29T16:48:24Z"
    },
    {
      "id": "CVE-2026-28618",
      "url": "https://labs.diras.sa/cve/cve-2026-28618/",
      "title": "Android heap buffer overflow in dec_frm_prepare allows remote code execution",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00375,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "17.x",
          "affected": "17",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16-qpr2",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code is available and no patch is listed, so prioritize containment and monitoring for affected Android 16/17 devices and apply vendor guidance as soon as patches are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-28618",
        "https://www.cve.org/CVERecord?id=CVE-2026-28618",
        "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
      ],
      "published": "2026-09-29T16:48:05Z",
      "updated": "2026-09-29T16:48:05Z"
    },
    {
      "id": "CVE-2026-28609",
      "url": "https://labs.diras.sa/cve/cve-2026-28609/",
      "title": "Android out-of-bounds write in MatroskaExtractor leads to remote code execution",
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-704",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00372,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "16.x",
          "affected": "16-qpr2",
          "fixed": null
        },
        {
          "branch": "16.x",
          "affected": "16",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: public exploit code exists, so prioritize mitigating exposure and applying vendor guidance as soon as patches are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-28609",
        "https://www.cve.org/CVERecord?id=CVE-2026-28609",
        "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
      ],
      "published": "2026-09-29T16:47:51Z",
      "updated": "2026-09-29T16:47:51Z"
    },
    {
      "id": "CVE-2026-65374",
      "url": "https://labs.diras.sa/cve/cve-2026-65374/",
      "title": "MacOS WebDAV memory corruption remote code execution",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00528,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgent: patch immediately where possible because public exploit code exists for this flaw. Prioritize upgrading internet-facing or frequently exposed macOS hosts to the fixed releases listed by Apple.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65374",
        "https://www.cve.org/CVERecord?id=CVE-2026-65374",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-29T16:47:38Z",
      "updated": "2026-09-29T16:47:38Z"
    },
    {
      "id": "CVE-2026-58704",
      "url": "https://labs.diras.sa/cve/cve-2026-58704/",
      "title": "Pixel cellular modem permission bypass privilege escalation",
      "vendor": "Google",
      "product": "Pixel",
      "cwe": "CWE-285",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00591,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-16",
        "dueDate": "2026-09-19"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "Android",
          "affected": "Android kernel",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a 2026-09-19 remediation requirement, so prioritize applying vendor mitigations or compensating controls immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-58704",
        "https://www.cve.org/CVERecord?id=CVE-2026-58704",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58704",
        "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
      ],
      "published": "2026-09-29T16:47:15Z",
      "updated": "2026-09-29T16:47:15Z"
    },
    {
      "id": "CVE-2026-86950",
      "url": "https://labs.diras.sa/cve/cve-2026-86950/",
      "title": "Apple CoreGraphics out-of-bounds write leads to code execution",
      "vendor": "Apple",
      "product": "Multiple Products",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00812,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-29",
        "dueDate": "2026-10-02"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.7.1",
          "fixed": "26.7.1"
        },
        {
          "branch": "macOS 15.x",
          "affected": "before 15.8.1",
          "fixed": "15.8.1"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.7.1",
          "fixed": "26.7.1"
        }
      ],
      "dirasTake": "Urgent: CISA put this issue on its Known Exploited Vulnerabilities list with a rapid remediation deadline, and public exploit code exists — update affected Apple devices to the listed fixes immediately or apply vendor mitigations.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-86950",
        "https://www.cve.org/CVERecord?id=CVE-2026-86950",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86950",
        "https://support.apple.com/en-us/149226",
        "https://support.apple.com/en-us/149228",
        "https://support.apple.com/en-us/149229"
      ],
      "published": "2026-09-29T16:47:00Z",
      "updated": "2026-09-29T16:47:00Z"
    },
    {
      "id": "CVE-2026-64638",
      "url": "https://labs.diras.sa/cve/cve-2026-64638/",
      "title": "WordPress pre-auth reflected XSS on login page",
      "vendor": "WordPress",
      "product": "WordPress",
      "cwe": "CWE-79",
      "cvss": {
        "version": "4.0",
        "score": 8.9,
        "severity": "high",
        "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": 0.00894,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "WordPress",
          "affected": "all versions",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so defenders should prioritize mitigations that reduce exposure of WordPress login endpoints and block malicious input at the edge.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-64638",
        "https://www.cve.org/CVERecord?id=CVE-2026-64638",
        "https://hackerone.com/reports/3877102",
        "https://wordpress.org/news/2026/08/wordpress-7-0-3-release/"
      ],
      "published": "2026-09-29T16:46:47Z",
      "updated": "2026-09-29T16:46:47Z"
    },
    {
      "id": "CVE-2026-48710",
      "url": "https://labs.diras.sa/cve/cve-2026-48710/",
      "title": "Starlette Host header validation bypass alters reconstructed request URL",
      "vendor": "Kludex",
      "product": "Starlette",
      "cwe": "CWE-444",
      "cvss": {
        "version": "3.1",
        "score": 6.5,
        "severity": "medium",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
      },
      "epss": 0.07056,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-02",
        "dueDate": "2026-09-16"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "starlette",
          "affected": "< 1.0.1",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added CVE-2026-48710 to its Known Exploited Vulnerabilities catalog with a remediation deadline, so prioritize mitigating internet-exposed Starlette instances now and follow vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-48710",
        "https://www.cve.org/CVERecord?id=CVE-2026-48710",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48710",
        "https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr",
        "https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6",
        "https://badhost.org",
        "https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-161.yaml",
        "https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette",
        "https://www.secwest.net/starlette",
        "https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette"
      ],
      "published": "2026-09-29T16:46:37Z",
      "updated": "2026-09-29T16:46:37Z"
    },
    {
      "id": "CVE-2026-89274",
      "url": "https://labs.diras.sa/cve/cve-2026-89274/",
      "title": "WP Recipe Maker arbitrary shortcode execution in metadata",
      "vendor": "brechtvds",
      "product": "WP Recipe Maker",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.00679,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "10.x",
          "affected": "10.8.1 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this flaw, so sites running WP Recipe Maker 10.8.1 or earlier with public comments should act now to block or moderate comments and follow vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-89274",
        "https://www.cve.org/CVERecord?id=CVE-2026-89274",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/d6ad49ff-85eb-4d05-ba23-51d89695add3?source=cve",
        "https://plugins.trac.wordpress.org/browser/wp-recipe-maker/tags/10.8.1/includes/public/class-wprm-metadata.php#L553",
        "https://plugins.trac.wordpress.org/browser/wp-recipe-maker/tags/10.8.1/includes/public/class-wprm-metadata.php#L1028",
        "https://plugins.trac.wordpress.org/browser/wp-recipe-maker/tags/10.8.1/includes/public/class-wprm-metadata.php#L181",
        "https://plugins.trac.wordpress.org/changeset?reponame=&old=3699793%40wp-recipe-maker&new=3699793%40wp-recipe-maker"
      ],
      "published": "2026-09-29T16:46:22Z",
      "updated": "2026-09-29T16:46:22Z"
    },
    {
      "id": "CVE-2026-93399",
      "url": "https://labs.diras.sa/cve/cve-2026-93399/",
      "title": "Bookly Insecure direct object reference exposes order tokens",
      "vendor": "ladela",
      "product": "Online Scheduling and Appointment Booking System – Bookly",
      "cwe": "CWE-639",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
      },
      "epss": 0.0037,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "28.x",
          "affected": "28.2 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists and the flaw requires no authentication, so expose-restricted Bookly installations should be mitigated immediately and patched when an update is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-93399",
        "https://www.cve.org/CVERecord?id=CVE-2026-93399",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/d45a01e5-0e69-4d95-b609-b9002b3776da?source=cve",
        "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/frontend/modules/booking/Ajax.php#L733",
        "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/frontend/modules/booking/Ajax.php#L46",
        "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/frontend/modules/booking/Ajax.php#L1111",
        "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/frontend/modules/payment/Ajax.php#L74",
        "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/lib/base/Gateway.php#L301",
        "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/28.2/lib/UserBookingData.php#L360",
        "https://plugins.trac.wordpress.org/changeset?reponame=&old=3707284%40bookly-responsive-appointment-booking-tool&new=3707284%40bookly-responsive-appointment-booking-tool"
      ],
      "published": "2026-09-29T16:45:48Z",
      "updated": "2026-09-29T16:45:48Z"
    },
    {
      "id": "CVE-2026-84388",
      "url": "https://labs.diras.sa/cve/cve-2026-84388/",
      "title": "FortiPAM Chrome Extension information disclosure via UI layer restriction",
      "vendor": "Fortinet",
      "product": "FortiPAM Chrome Extension",
      "cwe": "CWE-1021",
      "cvss": {
        "version": "3.1",
        "score": 9.6,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"
      },
      "epss": 0.00377,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "8.x",
          "affected": "8.0.1",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high priority: public exploit code exists and no fixed release is listed for the affected 8.0.1 build, so immediately block or limit the extension and apply compensating controls until Fortinet issues a patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84388",
        "https://www.cve.org/CVERecord?id=CVE-2026-84388",
        "https://fortiguard.fortinet.com/psirt/FG-IR-26-168"
      ],
      "published": "2026-09-29T16:45:36Z",
      "updated": "2026-09-29T16:45:36Z"
    },
    {
      "id": "CVE-2026-15826",
      "url": "https://labs.diras.sa/cve/cve-2026-15826/",
      "title": "User Profile Builder authentication bypass lets unauthenticated users become admin",
      "vendor": "cozmoslabs",
      "product": "User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor",
      "cwe": "CWE-704",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.03904,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.16.4 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists and the bug allows direct administrative takeover without authentication, so remove or take the plugin offline until a vendor fix is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-15826",
        "https://www.cve.org/CVERecord?id=CVE-2026-15826",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/9f606fba-f779-42ea-a160-6c3b20dc5e79?source=cve",
        "https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/default-fields/username/username.php#L28",
        "https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/default-fields/username/username.php#L49",
        "https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/class-formbuilder.php#L742",
        "https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/class-formbuilder.php#L364",
        "https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/class-formbuilder.php#L262",
        "https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/features/functions.php#L1481",
        "https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/class-formbuilder.php#L945",
        "https://plugins.trac.wordpress.org/changeset/3609855/profile-builder"
      ],
      "published": "2026-09-29T16:44:23Z",
      "updated": "2026-09-29T16:44:23Z"
    },
    {
      "id": "CVE-2026-12793",
      "url": "https://labs.diras.sa/cve/cve-2026-12793/",
      "title": "JetFormBuilder privilege escalation lets unauthenticated attacker create admin",
      "vendor": "jetmonsters",
      "product": "JetFormBuilder — Dynamic Blocks Form Builder",
      "cwe": "CWE-269",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00517,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.6.2 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists and the flaw allows unauthenticated admin creation, so treat vulnerable sites as high risk and act immediately to isolate and remediate exposed installations.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-12793",
        "https://www.cve.org/CVERecord?id=CVE-2026-12793",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/a61b2ecc-d4e1-4e71-9187-ddc3d3616a29?source=cve",
        "https://plugins.trac.wordpress.org/changeset/3575346/jetformbuilder"
      ],
      "published": "2026-09-29T16:44:13Z",
      "updated": "2026-09-29T16:44:13Z"
    },
    {
      "id": "CVE-2026-82901",
      "url": "https://labs.diras.sa/cve/cve-2026-82901/",
      "title": "Ultra Addons for Contact Form 7 arbitrary file upload (unauthenticated)",
      "vendor": "themefic",
      "product": "Ultra Addons for Contact Form 7",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01109,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.5.50 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code is available for an unauthenticated file-upload flaw that can enable remote code execution if the PDF Generator module is enabled, so treat internet-facing sites with this plugin as high priority to mitigate.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-82901",
        "https://www.cve.org/CVERecord?id=CVE-2026-82901",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/872e1a05-aacc-44fa-93c1-8c3f7b2fb46d?source=cve",
        "https://plugins.trac.wordpress.org/browser/ultimate-addons-for-contact-form-7/tags/3.5.48/addons/signature/ultimate-signature.php#L133",
        "https://plugins.trac.wordpress.org/browser/ultimate-addons-for-contact-form-7/tags/3.5.48/addons/signature/ultimate-signature.php#L192",
        "https://plugins.trac.wordpress.org/browser/ultimate-addons-for-contact-form-7/tags/3.5.48/addons/signature/ultimate-signature.php#L300",
        "https://plugins.trac.wordpress.org/browser/ultimate-addons-for-contact-form-7/tags/3.5.48/addons/pdf-generator/pdf-generator.php#L608",
        "https://plugins.trac.wordpress.org/browser/ultimate-addons-for-contact-form-7/tags/3.5.48/addons/pdf-generator/pdf-generator.php#L807",
        "https://plugins.trac.wordpress.org/changeset/3698232/ultimate-addons-for-contact-form-7"
      ],
      "published": "2026-09-29T16:44:00Z",
      "updated": "2026-09-29T16:44:00Z"
    },
    {
      "id": "CVE-2026-20303",
      "url": "https://labs.diras.sa/cve/cve-2026-20303/",
      "title": "Cisco Catalyst SD-WAN Controller improper input validation remote code execution",
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Controller",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 9.9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00487,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "Cisco Catalyst SD-WAN Controller 20.x",
          "affected": "20.6.4",
          "fixed": null
        },
        {
          "branch": "Cisco Catalyst SD-WAN Controller 20.x",
          "affected": "20.9.2",
          "fixed": null
        },
        {
          "branch": "Cisco Catalyst SD-WAN Controller 20.x",
          "affected": "20.3.6",
          "fixed": null
        },
        {
          "branch": "Cisco Catalyst SD-WAN Controller 20.x",
          "affected": "20.7.2",
          "fixed": null
        },
        {
          "branch": "Cisco Catalyst SD-WAN Controller 20.x",
          "affected": "20.7.1",
          "fixed": null
        },
        {
          "branch": "Cisco Catalyst SD-WAN Controller 20.x",
          "affected": "20.5.1",
          "fixed": null
        },
        {
          "branch": "Cisco Catalyst SD-WAN Controller 20.x",
          "affected": "20.6.2",
          "fixed": null
        },
        {
          "branch": "Cisco Catalyst SD-WAN Controller 19.x",
          "affected": "19.3.0",
          "fixed": null
        },
        {
          "branch": "Cisco Catalyst SD-WAN Controller 20.x",
          "affected": "20.6.1",
          "fixed": null
        },
        {
          "branch": "Cisco Catalyst SD-WAN Controller 17.x",
          "affected": "17.2.4",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as high urgency: public exploit code is available, so exposed controllers should be isolated or access restricted immediately while applying vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20303",
        "https://www.cve.org/CVERecord?id=CVE-2026-20303",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K"
      ],
      "published": "2026-09-29T16:43:51Z",
      "updated": "2026-09-29T16:43:51Z"
    },
    {
      "id": "CVE-2026-43825",
      "url": "https://labs.diras.sa/cve/cve-2026-43825/",
      "title": "Apache OpenNLP LibSVM untrusted Java deserialization remote code execution",
      "vendor": "Apache Software Foundation",
      "product": "Apache OpenNLP :: Core :: ML :: LibSVM",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 7.3,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
      },
      "epss": 0.13921,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "patch"
      ],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.0.0-M1 – before 3.0.0-M4",
          "fixed": "3.0.0-M4"
        }
      ],
      "dirasTake": "Act quickly: this flaw enables code execution when untrusted serialized data is processed and the vulnerable method can be invoked by any caller; prioritize updating to 3.0.0-M4 or preventing unverified serialized input from reaching the deserializer.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-43825",
        "https://www.cve.org/CVERecord?id=CVE-2026-43825",
        "https://lists.apache.org/thread/c7kom0pgk9cbpfnbooh5m3g85ndf50hn"
      ],
      "published": "2026-09-29T16:43:39Z",
      "updated": "2026-09-29T16:43:39Z"
    },
    {
      "id": "CVE-2026-20217",
      "url": "https://labs.diras.sa/cve/cve-2026-20217/",
      "title": "Cisco Secure Endpoint ClamAV PESpin parser remote denial-of-service",
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-120",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
      },
      "epss": 0.00573,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.0.5",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.2.19",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.3.3",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.13",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.1.5",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.3.1",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.2.5",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.3.5",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.2.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.7",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this pre-auth memory-corruption bug, so prioritize mitigations for internet-facing scanning endpoints and apply vendor fixes immediately when released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20217",
        "https://www.cve.org/CVERecord?id=CVE-2026-20217",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR"
      ],
      "published": "2026-09-29T16:43:13Z",
      "updated": "2026-09-29T16:43:13Z"
    },
    {
      "id": "CVE-2026-13181",
      "url": "https://labs.diras.sa/cve/cve-2026-13181/",
      "title": "Telerik UI for ASP.NET AJAX pre-auth remote code execution",
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-470",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00676,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "2026.x",
          "affected": "2010.1.309 – before 2026.2.708",
          "fixed": "2026.2.708"
        }
      ],
      "dirasTake": "Urgent — public exploit code exists, so prioritize remediation for internet-facing Telerik UI for ASP.NET AJAX instances and apply the vendor fix immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-13181",
        "https://www.cve.org/CVERecord?id=CVE-2026-13181",
        "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-asyncuploadtypename-deserialization-CVE-2026-13181"
      ],
      "published": "2026-09-29T16:43:00Z",
      "updated": "2026-09-29T16:43:00Z"
    },
    {
      "id": "CVE-2026-67276",
      "url": "https://labs.diras.sa/cve/cve-2026-67276/",
      "title": "RouterOS SSH RSA key validation authentication bypass",
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-347",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.06451,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.24 – before 7.24.2",
          "fixed": "7.24.2"
        },
        {
          "branch": "7.x",
          "affected": "7.9 – before 7.23.4",
          "fixed": "7.23.4"
        }
      ],
      "dirasTake": "Urgent: apply vendor fixes immediately because public exploit code exists and the flaw allows unauthenticated SSH access to an internet-facing service. Prioritize patching devices reachable from untrusted networks.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-67276",
        "https://www.cve.org/CVERecord?id=CVE-2026-67276",
        "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
        "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
        "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/",
        "https://mikrotik.com/supportsec/september-2026-vulnerability/",
        "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
        "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800"
      ],
      "published": "2026-09-29T16:42:51Z",
      "updated": "2026-09-29T16:42:51Z"
    },
    {
      "id": "CVE-2026-19516",
      "url": "https://labs.diras.sa/cve/cve-2026-19516/",
      "title": "Grafana MCP Server server-side request forgery (SSRF)",
      "vendor": "Grafana",
      "product": "Grafana MCP Server",
      "cwe": "CWE-918",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L"
      },
      "epss": 0.0031,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "Grafana MCP Server 1.x",
          "affected": "1.0.0 and earlier",
          "fixed": null
        },
        {
          "branch": "mcp-grafana 1.x",
          "affected": "1.0.0 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this SSRF, so prioritize mitigation for internet-facing or broadly reachable MCP instances and restrict outbound requests from the service immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-19516",
        "https://www.cve.org/CVERecord?id=CVE-2026-19516",
        "https://grafana.com/security/security-advisories/cve-2026-19516"
      ],
      "published": "2026-09-29T16:42:40Z",
      "updated": "2026-09-29T16:42:40Z"
    },
    {
      "id": "CVE-2026-82078",
      "url": "https://labs.diras.sa/cve/cve-2026-82078/",
      "title": "PaperCut NG/MF unsafe dynamic class loading allows remote code execution",
      "vendor": "PaperCut",
      "product": "NG/MF",
      "cwe": "CWE-470",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.03843,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-31",
        "dueDate": "2026-09-14"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "24.x",
          "affected": "before 24.1.10",
          "fixed": "24.1.10"
        },
        {
          "branch": "25.x",
          "affected": "25.0.0 – before 25.0.13",
          "fixed": "25.0.13"
        },
        {
          "branch": "26.x",
          "affected": "26.0.0 – before 26.0.5",
          "fixed": "26.0.5"
        }
      ],
      "dirasTake": "Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a remediation deadline, so prioritize updates or mitigations immediately; the flaw lets high-privilege users load arbitrary classes on the server. Apply vendor updates or follow vendor mitigation instructions without delay.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-82078",
        "https://www.cve.org/CVERecord?id=CVE-2026-82078",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078",
        "https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"
      ],
      "published": "2026-09-29T16:42:29Z",
      "updated": "2026-09-29T16:42:29Z"
    },
    {
      "id": "CVE-2026-48356",
      "url": "https://labs.diras.sa/cve/cve-2026-48356/",
      "title": "Adobe Commerce unrestricted file upload leading to remote code execution",
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.3,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
      },
      "epss": 0.01001,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "Adobe Commerce 2.x",
          "affected": "2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier",
          "fixed": null
        },
        {
          "branch": "Adobe Commerce B2B 1.x",
          "affected": "1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18 and earlier",
          "fixed": null
        },
        {
          "branch": "Magento Open Source 2.x",
          "affected": "2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15 and earlier",
          "fixed": null
        },
        {
          "branch": "Adobe Commerce Events 1.x",
          "affected": "1.20.0 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this web-exposed upload flaw that leads to code execution when a user interacts with malicious content—prioritize containment and protective controls now.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-48356",
        "https://www.cve.org/CVERecord?id=CVE-2026-48356",
        "https://helpx.adobe.com/security/products/magento/apsb26-73.html"
      ],
      "published": "2026-09-29T16:42:17Z",
      "updated": "2026-09-29T16:42:17Z"
    },
    {
      "id": "CVE-2026-58048",
      "url": "https://labs.diras.sa/cve/cve-2026-58048/",
      "title": "CPanel SQL injection lets low-privilege users run SQL as root",
      "vendor": "WebPros",
      "product": "cPanel",
      "cwe": "CWE-89",
      "cvss": {
        "version": "4.0",
        "score": 9.4,
        "severity": "critical",
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": 0.00561,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "cPanel 11.x",
          "affected": "before 11.110.0.137",
          "fixed": "11.110.0.137"
        },
        {
          "branch": "cPanel 11.x",
          "affected": "before 11.126.0.78",
          "fixed": "11.126.0.78"
        },
        {
          "branch": "cPanel 11.x",
          "affected": "before 11.134.0.48",
          "fixed": "11.134.0.48"
        },
        {
          "branch": "cPanel 11.x",
          "affected": "before 11.136.0.32",
          "fixed": "11.136.0.32"
        },
        {
          "branch": "cPanel 11.x",
          "affected": "before 11.137.9999.99",
          "fixed": "11.137.9999.99"
        },
        {
          "branch": "cPanel 11.x",
          "affected": "before 11.118.0.71",
          "fixed": "11.118.0.71"
        },
        {
          "branch": "WP Squared 11.x",
          "affected": "before 11.138.1.6",
          "fixed": "11.138.1.6"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists and vendor updates are available; apply the vendor fixes listed below promptly or restrict access to the cPanel management interfaces until you can patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-58048",
        "https://www.cve.org/CVERecord?id=CVE-2026-58048",
        "https://support.cpanel.net/hc/en-us/articles/42285745783703-CVE-2026-58048-Database-Privilege-Escalation",
        "https://docs.cpanel.net/changelogs/138-change-log"
      ],
      "published": "2026-09-29T16:41:57Z",
      "updated": "2026-09-29T16:41:57Z"
    },
    {
      "id": "CVE-2026-77179",
      "url": "https://labs.diras.sa/cve/cve-2026-77179/",
      "title": "Docker Sandboxes virtio-fs symlink escape to host code execution",
      "vendor": "Docker",
      "product": "Docker Sandboxes",
      "cwe": "CWE-59",
      "cvss": {
        "version": "4.0",
        "score": 9.4,
        "severity": "critical",
        "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      },
      "epss": 0.00199,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "0.x",
          "affected": "0.28.0 – before 0.42.0",
          "fixed": "0.42.0"
        }
      ],
      "dirasTake": "Treat this as urgent: public exploit code is available, so upgrade to the fixed Docker Sandboxes release 0.42.0 immediately or block use of affected sandbox instances until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-77179",
        "https://www.cve.org/CVERecord?id=CVE-2026-77179",
        "https://docs.docker.com/ai/sandboxes/",
        "https://docs.docker.com/ai/sandboxes/security/isolation/",
        "https://github.com/docker/sbx-releases/releases/tag/v0.42.0"
      ],
      "published": "2026-09-29T16:41:46Z",
      "updated": "2026-09-29T16:41:46Z"
    },
    {
      "id": "CVE-2026-14382",
      "url": "https://labs.diras.sa/cve/cve-2026-14382/",
      "title": "Chrome ANGLE sandbox escape via crafted HTML",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 9.6,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00345,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "150.x",
          "affected": "150.0.7871.46 – before 150.0.7871.46",
          "fixed": "150.0.7871.46"
        }
      ],
      "dirasTake": "Urgent — public exploit code exists and the vulnerability allows a browser sandbox escape; update Chrome to 150.0.7871.46 immediately or apply vendor guidance to mitigate exposure.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-14382",
        "https://www.cve.org/CVERecord?id=CVE-2026-14382",
        "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
        "https://issues.chromium.org/issues/492218546"
      ],
      "published": "2026-09-29T16:41:26Z",
      "updated": "2026-09-29T16:41:26Z"
    },
    {
      "id": "CVE-2026-76036",
      "url": "https://labs.diras.sa/cve/cve-2026-76036/",
      "title": "Chrome Dawn buffer overflow remote code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.6,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00506,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "151.x",
          "affected": "151.0.7922.169 – before 151.0.7922.169",
          "fixed": "151.0.7922.169"
        }
      ],
      "dirasTake": "Urgent: patch immediately — public exploit code exists and the issue is fixed in Chrome 151.0.7922.169. Prioritize updating Android Chrome clients that remain on the 151.x branch and restrict exposure until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76036",
        "https://www.cve.org/CVERecord?id=CVE-2026-76036",
        "https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0826575033.html",
        "https://issues.chromium.org/issues/540087398"
      ],
      "published": "2026-09-29T16:41:06Z",
      "updated": "2026-09-29T16:41:06Z"
    },
    {
      "id": "CVE-2026-78904",
      "url": "https://labs.diras.sa/cve/cve-2026-78904/",
      "title": "Chrome ANGLE type confusion remote code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "cvss": {
        "version": "3.1",
        "score": 9.6,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00503,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.65 – before 152.0.7977.65",
          "fixed": "152.0.7977.65"
        }
      ],
      "dirasTake": "Urgent — public exploit code is available for CVE-2026-78904, so update Chrome to 152.0.7977.65 immediately or otherwise block access to vulnerable builds until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-78904",
        "https://www.cve.org/CVERecord?id=CVE-2026-78904",
        "https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html",
        "https://issues.chromium.org/issues/537835609"
      ],
      "published": "2026-09-29T16:40:55Z",
      "updated": "2026-09-29T16:40:55Z"
    },
    {
      "id": "CVE-2026-87492",
      "url": "https://labs.diras.sa/cve/cve-2026-87492/",
      "title": "Chrome DevTools incorrect authorization allows remote code execution",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 9.6,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00444,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "153.x",
          "affected": "153.0.8010.36 – before 153.0.8010.36",
          "fixed": "153.0.8010.36"
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so update Chrome to 153.0.8010.36 immediately or block untrusted web content until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-87492",
        "https://www.cve.org/CVERecord?id=CVE-2026-87492",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html",
        "https://issues.chromium.org/issues/529123409"
      ],
      "published": "2026-09-29T16:40:42Z",
      "updated": "2026-09-29T16:40:42Z"
    },
    {
      "id": "CVE-2026-12944",
      "url": "https://labs.diras.sa/cve/cve-2026-12944/",
      "title": "Langflow OSS remote code execution as root via component imports",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "cvss": {
        "version": "3.1",
        "score": 9.6,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.00429,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.10.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so assume easy weaponization; prioritize applying the vendor's remediation and remove or restrict internet-facing access to Langflow servers immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-12944",
        "https://www.cve.org/CVERecord?id=CVE-2026-12944",
        "https://www.ibm.com/support/pages/node/7278919"
      ],
      "published": "2026-09-29T16:40:29Z",
      "updated": "2026-09-29T16:40:29Z"
    },
    {
      "id": "CVE-2026-19295",
      "url": "https://labs.diras.sa/cve/cve-2026-19295/",
      "title": "Langflow OSS authenticated OS command execution via crafted flow",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-95",
      "cvss": {
        "version": "3.1",
        "score": 9.9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.03269,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.11.1",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists for this high-severity RCE—immediately limit access to Langflow OSS and prioritize applying vendor fixes or mitigations. Internet-facing or broadly accessible deployments are especially at risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-19295",
        "https://www.cve.org/CVERecord?id=CVE-2026-19295",
        "https://www.ibm.com/support/pages/node/7284733"
      ],
      "published": "2026-09-29T16:39:54Z",
      "updated": "2026-09-29T16:39:54Z"
    },
    {
      "id": "CVE-2026-67401",
      "url": "https://labs.diras.sa/cve/cve-2026-67401/",
      "title": "CPanel EmailTrack SQL injection remote code execution",
      "vendor": "WebPros",
      "product": "cPanel",
      "cwe": "CWE-89",
      "cvss": {
        "version": "3.0",
        "score": 9.9,
        "severity": "critical",
        "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00861,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "11.x",
          "affected": "before 11.134.0.55",
          "fixed": "11.134.0.55"
        },
        {
          "branch": "11.x",
          "affected": "before 11.136.0.39",
          "fixed": "11.136.0.39"
        },
        {
          "branch": "11.x",
          "affected": "before 11.138.0.4",
          "fixed": "11.138.0.4"
        },
        {
          "branch": "11.x",
          "affected": "before 11.138.1.9",
          "fixed": "11.138.1.9"
        },
        {
          "branch": "11.x",
          "affected": "before 11.110.0.143",
          "fixed": "11.110.0.143"
        }
      ],
      "dirasTake": "Urgent: public proof-of-concept exploit code exists, so patch immediately to one of the fixed 11.x builds listed or restrict access to affected services until you can update.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-67401",
        "https://www.cve.org/CVERecord?id=CVE-2026-67401",
        "https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026"
      ],
      "published": "2026-09-29T16:39:34Z",
      "updated": "2026-09-29T16:39:34Z"
    },
    {
      "id": "CVE-2026-14802",
      "url": "https://labs.diras.sa/cve/cve-2026-14802/",
      "title": "Create-react-app os command injection in react-dev-utils openBrowser",
      "vendor": "react",
      "product": "create-react-app",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 7.3,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
      },
      "epss": 0.02109,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "5.x",
          "affected": "5.0.0",
          "fixed": null
        },
        {
          "branch": "5.x",
          "affected": "5.0.1",
          "fixed": null
        }
      ],
      "dirasTake": "Act urgently: public exploit code is available, so prioritize mitigation for developer machines and CI runners using create-react-app 5.0.0–5.0.1 and apply vendor guidance or containment until a fix is released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-14802",
        "https://www.cve.org/CVERecord?id=CVE-2026-14802",
        "https://vuldb.com/vuln/376396",
        "https://vuldb.com/vuln/376396/cti",
        "https://vuldb.com/cve/CVE-2026-14802",
        "https://vuldb.com/submit/850857",
        "https://github.com/react/create-react-app/issues/17269",
        "https://github.com/react/create-react-app/"
      ],
      "published": "2026-09-29T16:39:21Z",
      "updated": "2026-09-29T16:39:21Z"
    },
    {
      "id": "CVE-2026-18556",
      "url": "https://labs.diras.sa/cve/cve-2026-18556/",
      "title": "N-central authentication bypass via alternate path (pre-auth)",
      "vendor": "N-able",
      "product": "N-central",
      "cwe": "CWE-288",
      "cvss": {
        "version": "3.1",
        "score": 7.4,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.07882,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-04",
        "dueDate": "2026-08-07"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "2026.x",
          "affected": "2026.1 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this CVE is listed on CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline of 2026-08-07, so prioritize mitigation immediately; public exploit code also exists, increasing immediate risk.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-18556",
        "https://www.cve.org/CVERecord?id=CVE-2026-18556",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18556",
        "https://uptime.n-able.com/"
      ],
      "published": "2026-09-29T16:39:09Z",
      "updated": "2026-09-29T16:39:09Z"
    },
    {
      "id": "CVE-2023-4346",
      "url": "https://labs.diras.sa/cve/cve-2023-4346/",
      "title": "KNX Protocol Connection Authorization Option 1 account lockout vulnerability",
      "vendor": "KNX Association",
      "product": "KNX Protocol Connection Authorization Option 1",
      "cwe": "CWE-645",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
      },
      "epss": 0.01294,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-15",
        "dueDate": "2026-07-29"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "KNX Protocol Connection Authorization Option 1",
          "affected": "all versions",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this issue to the Known Exploited Vulnerabilities catalog with a 2026-07-29 remediation deadline, so prioritize mitigations immediately for internet-exposed or mission-critical KNX installations.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2023-4346",
        "https://www.cve.org/CVERecord?id=CVE-2023-4346",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4346",
        "https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01"
      ],
      "published": "2026-09-29T16:38:57Z",
      "updated": "2026-09-29T16:38:57Z"
    },
    {
      "id": "CVE-2026-42018",
      "url": "https://labs.diras.sa/cve/cve-2026-42018/",
      "title": "Artifactory improper authentication returns internal anonymous token",
      "vendor": "JFrog",
      "product": "Artifactory",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
      },
      "epss": 0.09805,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-11",
        "dueDate": "2026-09-25"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "before 7.111.20",
          "fixed": "7.111.20"
        },
        {
          "branch": "7.x",
          "affected": "7.117.0 – before 7.117.27",
          "fixed": "7.117.27"
        },
        {
          "branch": "7.x",
          "affected": "7.125.0 – before 7.125.19",
          "fixed": "7.125.19"
        },
        {
          "branch": "7.x",
          "affected": "7.133.0 – before 7.133.28",
          "fixed": "7.133.28"
        },
        {
          "branch": "7.x",
          "affected": "7.146.0 – before 7.146.8",
          "fixed": "7.146.8"
        }
      ],
      "dirasTake": "Urgent — CISA added this issue to its Known Exploited Vulnerabilities catalog with a federal remediation due date; prioritize installing vendor fixes or applying vendor mitigations immediately for internet-facing Artifactory instances.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-42018",
        "https://www.cve.org/CVERecord?id=CVE-2026-42018",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018",
        "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
        "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      ],
      "published": "2026-09-29T16:38:45Z",
      "updated": "2026-09-29T16:38:45Z"
    },
    {
      "id": "CVE-2026-73633",
      "url": "https://labs.diras.sa/cve/cve-2026-73633/",
      "title": "Apache Struts JSON plugin uncontrolled resource consumption",
      "vendor": "Apache Software Foundation",
      "product": "Apache Struts",
      "cwe": "CWE-400",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
      },
      "epss": 0.00698,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "2.x",
          "affected": "2.1.8 – 2.3.37",
          "fixed": null
        },
        {
          "branch": "2.x",
          "affected": "2.5.0 – 2.5.33",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.0.0 – 6.10.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – 7.2.1",
          "fixed": null
        }
      ],
      "dirasTake": "High priority: public exploit code exists, so immediately protect internet-facing Struts instances that accept JSON request bodies; disable JSON request-body handling or restrict access until a vendor fix is applied.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-73633",
        "https://www.cve.org/CVERecord?id=CVE-2026-73633",
        "https://cwiki.apache.org/confluence/display/WW/S2-072"
      ],
      "published": "2026-09-29T16:38:32Z",
      "updated": "2026-09-29T16:38:32Z"
    },
    {
      "id": "CVE-2026-65343",
      "url": "https://labs.diras.sa/cve/cve-2026-65343/",
      "title": "IOS and iPadOS use-after-free causes remote denial of service",
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
      },
      "epss": 0.00686,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "iOS and iPadOS 26.x",
          "affected": "before 26.6.1",
          "fixed": "26.6.1"
        },
        {
          "branch": "macOS 26.x",
          "affected": "before 26.6.2",
          "fixed": "26.6.2"
        },
        {
          "branch": "tvOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "visionOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        },
        {
          "branch": "watchOS 27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so update immediately to the listed fixed releases (26.6.1, 26.6.2, 27) or restrict network exposure to vulnerable devices until you can patch.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65343",
        "https://www.cve.org/CVERecord?id=CVE-2026-65343",
        "https://support.apple.com/en-us/148281",
        "https://support.apple.com/en-us/148282",
        "https://support.apple.com/en-us/149036",
        "https://support.apple.com/en-us/149037",
        "https://support.apple.com/en-us/149038"
      ],
      "published": "2026-09-29T16:38:07Z",
      "updated": "2026-09-29T16:38:07Z"
    },
    {
      "id": "CVE-2026-63072",
      "url": "https://labs.diras.sa/cve/cve-2026-63072/",
      "title": "OpenSSL CMS heap out-of-bounds write via CMS_decrypt",
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
      },
      "epss": 0.01009,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "4.x",
          "affected": "4.0.0 – before 4.0.2",
          "fixed": "4.0.2"
        },
        {
          "branch": "3.x",
          "affected": "3.6.0 – before 3.6.4",
          "fixed": "3.6.4"
        },
        {
          "branch": "3.x",
          "affected": "3.5.0 – before 3.5.8",
          "fixed": "3.5.8"
        },
        {
          "branch": "3.x",
          "affected": "3.4.0 – before 3.4.7",
          "fixed": "3.4.7"
        },
        {
          "branch": "3.x",
          "affected": "3.0.0 – before 3.0.22",
          "fixed": "3.0.22"
        },
        {
          "branch": "1.x",
          "affected": "1.1.1 – before 1.1.1zi",
          "fixed": "1.1.1zi"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists and the vulnerable routine is reachable from CMS_decrypt without special configuration, so prioritize upgrades to the fixed releases or apply mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-63072",
        "https://www.cve.org/CVERecord?id=CVE-2026-63072",
        "https://openssl-library.org/news/secadv/20260825.txt",
        "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335",
        "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756",
        "https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42",
        "https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a",
        "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
      ],
      "published": "2026-09-29T16:37:55Z",
      "updated": "2026-09-29T16:37:55Z"
    },
    {
      "id": "CVE-2026-84543",
      "url": "https://labs.diras.sa/cve/cve-2026-84543/",
      "title": "MacOS out-of-bounds SMB client access from a remote server",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-125",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
      },
      "epss": 0.00428,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "15.x",
          "affected": "before 15.8",
          "fixed": "15.8"
        },
        {
          "branch": "26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgent — public exploit code exists and the flaw can be triggered without authentication by a remote SMB server, so patch exposed macOS hosts promptly or block untrusted SMB servers.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84543",
        "https://www.cve.org/CVERecord?id=CVE-2026-84543",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149042",
        "https://support.apple.com/en-us/149043"
      ],
      "published": "2026-09-29T16:37:36Z",
      "updated": "2026-09-29T16:37:36Z"
    },
    {
      "id": "CVE-2026-42533",
      "url": "https://labs.diras.sa/cve/cve-2026-42533/",
      "title": "NGINX Plus heap buffer overflow with regex map leading to remote code execution",
      "vendor": "F5",
      "product": "NGINX Plus",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00894,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "NGINX Plus 37.x",
          "affected": "37.0.0.1 – before 37.0.3.1",
          "fixed": "37.0.3.1"
        },
        {
          "branch": "NGINX Plus",
          "affected": "R36 – before R36 P7",
          "fixed": "R36 P7"
        },
        {
          "branch": "NGINX Plus",
          "affected": "R33",
          "fixed": null
        },
        {
          "branch": "NGINX Open Source 1.x",
          "affected": "1.31.2 – before 1.31.3",
          "fixed": "1.31.3"
        },
        {
          "branch": "NGINX Open Source 1.x",
          "affected": "0.9.6 – before 1.30.4",
          "fixed": "1.30.4"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so apply vendor fixes or mitigations immediately; the presence of public exploit code makes internet-facing NGINX instances high priority to update.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-42533",
        "https://www.cve.org/CVERecord?id=CVE-2026-42533",
        "https://my.f5.com/manage/s/article/K000162097"
      ],
      "published": "2026-09-29T16:37:23Z",
      "updated": "2026-09-29T16:37:23Z"
    },
    {
      "id": "CVE-2021-27137",
      "url": "https://labs.diras.sa/cve/cve-2021-27137/",
      "title": "DD-WRT UPnP stack buffer overflow allows remote code execution",
      "vendor": "DD-WRT",
      "product": "DD-WRT",
      "cwe": "CWE-121",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.03995,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-21",
        "dueDate": "2026-07-24"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "45724.x",
          "affected": "before 45724",
          "fixed": "45724"
        }
      ],
      "dirasTake": "Urgent — this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a rapid remediation deadline, so prioritize upgrading or applying mitigations immediately for internet-facing or UPnP-enabled DD-WRT devices.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2021-27137",
        "https://www.cve.org/CVERecord?id=CVE-2021-27137",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27137",
        "https://svn.dd-wrt.com/changeset/45724",
        "https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/",
        "https://securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html",
        "https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/",
        "https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo"
      ],
      "published": "2026-09-29T16:37:12Z",
      "updated": "2026-09-29T16:37:12Z"
    },
    {
      "id": "CVE-2026-63520",
      "url": "https://labs.diras.sa/cve/cve-2026-63520/",
      "title": "Microsoft SharePoint Enterprise Server 2016 improper input validation RCE",
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00956,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SharePoint Enterprise Server 2016 16.x",
          "affected": "16.0.0 – before 16.0.5565.1001",
          "fixed": "16.0.5565.1001"
        },
        {
          "branch": "Microsoft SharePoint Server 2019 16.x",
          "affected": "16.0.0 – before 16.0.10417.20198",
          "fixed": "16.0.10417.20198"
        },
        {
          "branch": "Microsoft SharePoint Server Subscription Edition 16.x",
          "affected": "16.0.0 – before 16.0.19725.20522",
          "fixed": "16.0.19725.20522"
        }
      ],
      "dirasTake": "Urgent: public exploit code is available, so apply the vendor fixes immediately or otherwise block external access to SharePoint and monitor for suspicious activity.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-63520",
        "https://www.cve.org/CVERecord?id=CVE-2026-63520",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520"
      ],
      "published": "2026-09-29T16:37:00Z",
      "updated": "2026-09-29T16:37:00Z"
    },
    {
      "id": "CVE-2026-59822",
      "url": "https://labs.diras.sa/cve/cve-2026-59822/",
      "title": "LiteLLM improper authentication allows unauthenticated MCP session creation",
      "vendor": "BerriAI",
      "product": "LiteLLM",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 8.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
      },
      "epss": 0.00836,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-02",
        "dueDate": "2026-09-16"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "litellm",
          "affected": "< 1.84.0",
          "fixed": null
        }
      ],
      "dirasTake": "High priority: CISA placed this flaw on the Known Exploited Vulnerabilities list with a remediation deadline and public exploit code exists — immediately reduce exposure and apply vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-59822",
        "https://www.cve.org/CVERecord?id=CVE-2026-59822",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59822",
        "https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q",
        "https://github.com/BerriAI/litellm/pull/26463",
        "https://github.com/BerriAI/litellm/commit/73869f0faf7d11ee21adcb5f91b8c33a340b6c2c",
        "https://github.com/BerriAI/litellm/releases/tag/v1.84.0"
      ],
      "published": "2026-09-29T16:36:45Z",
      "updated": "2026-09-29T16:36:45Z"
    },
    {
      "id": "CVE-2026-15583",
      "url": "https://labs.diras.sa/cve/cve-2026-15583/",
      "title": "Grafana MCP Server confused-deputy header token exfiltration and SSRF",
      "vendor": "Grafana",
      "product": "Grafana MCP Server",
      "cwe": "CWE-610",
      "cvss": {
        "version": "3.1",
        "score": 8.6,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
      },
      "epss": 0.00529,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "0.x",
          "affected": "0.17.1 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: public exploit code exists and the bug is exploitable without authentication, so prioritize reducing exposure of internet-facing Grafana MCP Server instances and apply vendor guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-15583",
        "https://www.cve.org/CVERecord?id=CVE-2026-15583",
        "https://grafana.com/security/security-advisories/cve-2026-15583"
      ],
      "published": "2026-09-29T16:36:24Z",
      "updated": "2026-09-29T16:36:24Z"
    },
    {
      "id": "CVE-2026-48019",
      "url": "https://labs.diras.sa/cve/cve-2026-48019/",
      "title": "Laravel framework CRLF injection in email validation",
      "vendor": "laravel",
      "product": "framework",
      "cwe": "CWE-93",
      "cvss": {
        "version": "3.1",
        "score": 8.9,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L"
      },
      "epss": 0.00511,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc"
      ],
      "affected": [
        {
          "branch": "framework",
          "affected": ">= 13.0.0, < 13.10.0",
          "fixed": null
        },
        {
          "branch": "framework",
          "affected": "< 12.60.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: treat this as high priority because public exploit code is available; immediately restrict any ability to send mail to user-supplied addresses and apply vendor guidance or updates as soon as they are released.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-48019",
        "https://www.cve.org/CVERecord?id=CVE-2026-48019",
        "https://github.com/laravel/framework/security/advisories/GHSA-5vg9-5847-vvmq",
        "https://github.com/laravel/framework/pull/60151",
        "https://github.com/laravel/framework/commit/96e9a663db657cf37ef26cd794fda8ff60eaa451",
        "https://github.com/laravel/framework/commit/f336ba79e744257f84ebf0d096b0ebc62e8e1a4d",
        "https://github.com/laravel/framework/releases/tag/v12.60.0",
        "https://github.com/laravel/framework/releases/tag/v13.10.0"
      ],
      "published": "2026-09-29T16:36:09Z",
      "updated": "2026-09-29T16:36:09Z"
    },
    {
      "id": "CVE-2026-15733",
      "url": "https://labs.diras.sa/cve/cve-2026-15733/",
      "title": "WGDashboard command injection leads to remote code execution",
      "vendor": "WGDashboard",
      "product": "WGDashboard",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.1002,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [],
      "affected": [
        {
          "branch": "4.x",
          "affected": "4.3.2 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a critical (CVSS 9.8) remote code execution via command injection with no available patch; prioritize reducing exposure and applying vendor guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-15733",
        "https://www.cve.org/CVERecord?id=CVE-2026-15733",
        "https://github.com/WGDashboard/WGDashboard",
        "https://github.com/Stuub/WGDashboard-v4.3.2-OS-Command-Injection-to-Root-RCE-PoC"
      ],
      "published": "2026-09-29T16:35:56Z",
      "updated": "2026-09-29T16:35:56Z"
    },
    {
      "id": "CVE-2026-72530",
      "url": "https://labs.diras.sa/cve/cve-2026-72530/",
      "title": "TrueConf Server code injection allows remote unauthenticated code execution",
      "vendor": "TrueConf",
      "product": "Server",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.01686,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-20",
        "dueDate": "2026-09-03"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "5.x",
          "affected": "before 5.3",
          "fixed": "5.3"
        },
        {
          "branch": "5.x",
          "affected": "5.3 – before 5.3.9",
          "fixed": "5.3.9"
        },
        {
          "branch": "5.x",
          "affected": "5.4 – before 5.4.9",
          "fixed": "5.4.9"
        },
        {
          "branch": "5.x",
          "affected": "5.5 – before 5.5.5",
          "fixed": "5.5.5"
        }
      ],
      "dirasTake": "Urgent: CISA added this flaw to its Known Exploited Vulnerabilities catalog with a federal mitigation deadline, and public exploit code is available — prioritize patching or mitigations for any internet-facing TrueConf Server.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-72530",
        "https://www.cve.org/CVERecord?id=CVE-2026-72530",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72530",
        "https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/"
      ],
      "published": "2026-09-29T16:35:45Z",
      "updated": "2026-09-29T16:35:45Z"
    },
    {
      "id": "CVE-2021-23758",
      "url": "https://labs.diras.sa/cve/cve-2021-23758/",
      "title": "Ajax.NET Professional deserialization pre-auth remote code execution",
      "vendor": "Ajax.NET Professional",
      "product": "Ajax.NET Professional",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.82578,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-26",
        "dueDate": "2026-09-09"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "AjaxPro.2",
          "affected": "before unspecified",
          "fixed": "unspecified"
        }
      ],
      "dirasTake": "Urgent: this vulnerability is in CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline of 2026-09-09, and public exploit code exists — reduce exposure immediately and apply vendor guidance without delay.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2021-23758",
        "https://www.cve.org/CVERecord?id=CVE-2021-23758",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758",
        "https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971",
        "https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57",
        "http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html"
      ],
      "published": "2026-09-29T16:35:05Z",
      "updated": "2026-09-29T16:35:05Z"
    },
    {
      "id": "CVE-2023-49105",
      "url": "https://labs.diras.sa/cve/cve-2023-49105/",
      "title": "OwnCloud pre-auth improper authentication lets attackers modify or delete files",
      "vendor": "ownCloud",
      "product": "ownCloud",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.42919,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-27",
        "dueDate": "2026-08-30"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [],
      "dirasTake": "Urgent — CISA placed this vulnerability on the Known Exploited Vulnerabilities catalog with a tight remediation deadline, indicating rapid action is required for exposed systems.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2023-49105",
        "https://www.cve.org/CVERecord?id=CVE-2023-49105",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-49105",
        "https://owncloud.org/security",
        "https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/"
      ],
      "published": "2026-09-29T16:34:39Z",
      "updated": "2026-09-29T16:34:39Z"
    },
    {
      "id": "CVE-2025-39682",
      "url": "https://labs.diras.sa/cve/cve-2025-39682/",
      "title": "Linux Kernel TLS zero-length record handling leads to remote code execution",
      "vendor": "Linux",
      "product": "Kernel",
      "cwe": "CWE-754",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.0288,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-18",
        "dueDate": "2026-09-21"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "2902.x",
          "affected": "84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 2902c3ebcca52ca845c03182000e8d71d3a5196f",
          "fixed": "2902c3ebcca52ca845c03182000e8d71d3a5196f"
        },
        {
          "branch": "Linux",
          "affected": "84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677",
          "fixed": "c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677"
        },
        {
          "branch": "3439.x",
          "affected": "84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 3439c15ae91a517cf3c650ea15a8987699416ad9",
          "fixed": "3439c15ae91a517cf3c650ea15a8987699416ad9"
        },
        {
          "branch": "29.x",
          "affected": "84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e",
          "fixed": "29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e"
        },
        {
          "branch": "62708.x",
          "affected": "84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 62708b9452f8eb77513115b17c4f8d1a22ebf843",
          "fixed": "62708b9452f8eb77513115b17c4f8d1a22ebf843"
        },
        {
          "branch": "6.x",
          "affected": "6.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA added CVE-2025-39682 to its KEV catalog with a 2026-09-21 federal remediation deadline, and the issue can be triggered remotely without credentials.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2025-39682",
        "https://www.cve.org/CVERecord?id=CVE-2025-39682",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39682",
        "https://git.kernel.org/stable/c/2902c3ebcca52ca845c03182000e8d71d3a5196f",
        "https://git.kernel.org/stable/c/c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677",
        "https://git.kernel.org/stable/c/3439c15ae91a517cf3c650ea15a8987699416ad9",
        "https://git.kernel.org/stable/c/29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e",
        "https://git.kernel.org/stable/c/62708b9452f8eb77513115b17c4f8d1a22ebf843"
      ],
      "published": "2026-09-29T16:34:12Z",
      "updated": "2026-09-29T16:34:12Z"
    },
    {
      "id": "CVE-2026-46817",
      "url": "https://labs.diras.sa/cve/cve-2026-46817/",
      "title": "Oracle E-Business Suite Payments unauthenticated takeover",
      "vendor": "Oracle",
      "product": "E-Business Suite",
      "cwe": "CWE-269",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00814,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-15",
        "dueDate": "2026-07-18"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "12.x",
          "affected": "12.2.3 – 12.2.15",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this issue is listed on CISA’s Known Exploited Vulnerabilities catalog with a mandated remediation deadline, and public exploit code exists — treat exposed Oracle Payments instances as high priority for mitigation. Follow the vendor instructions and CISA guidance immediately to reduce internet exposure and apply recommended mitigations.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-46817",
        "https://www.cve.org/CVERecord?id=CVE-2026-46817",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-46817",
        "https://www.oracle.com/security-alerts/cspumay2026.html"
      ],
      "published": "2026-09-29T16:33:54Z",
      "updated": "2026-09-29T16:33:54Z"
    },
    {
      "id": "CVE-2026-48939",
      "url": "https://labs.diras.sa/cve/cve-2026-48939/",
      "title": "ICagenda file upload leads to remote PHP code execution",
      "vendor": "iCagenda",
      "product": "iCagenda",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.20069,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-10",
        "dueDate": "2026-07-13"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "3.x",
          "affected": "3.2.1-4.0.7",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this flaw to its Known Exploited Vulnerabilities catalog with a July 13, 2026 federal remediation deadline, and no vendor fix is listed — treat exposed installs as high priority to isolate and mitigate immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-48939",
        "https://www.cve.org/CVERecord?id=CVE-2026-48939",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939",
        "https://www.icagenda.com/"
      ],
      "published": "2026-09-29T16:33:37Z",
      "updated": "2026-09-29T16:33:37Z"
    },
    {
      "id": "CVE-2026-48908",
      "url": "https://labs.diras.sa/cve/cve-2026-48908/",
      "title": "SP Page Builder unrestricted file upload leads to remote code execution",
      "vendor": "JoomShaper",
      "product": "SP Page Builder",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.88512,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-07",
        "dueDate": "2026-07-10"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0-6.6.1",
          "fixed": null
        }
      ],
      "dirasTake": "High urgency: CISA added CVE-2026-48908 to its Known Exploited Vulnerabilities catalog with a July 10, 2026 remediation deadline, so treat internet-facing installations as emergency fixes and follow vendor guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-48908",
        "https://www.cve.org/CVERecord?id=CVE-2026-48908",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908",
        "https://www.joomshaper.com/page-builder"
      ],
      "published": "2026-09-29T16:33:19Z",
      "updated": "2026-09-29T16:33:19Z"
    },
    {
      "id": "CVE-2026-56290",
      "url": "https://labs.diras.sa/cve/cve-2026-56290/",
      "title": "Page Builder unauthenticated file upload leading to remote code execution",
      "vendor": "Joomlack",
      "product": "Page Builder",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.30866,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-07",
        "dueDate": "2026-07-10"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0-3.6.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added CVE-2026-56290 to its Known Exploited Vulnerabilities catalog with a July 10, 2026 remediation due date, and public exploit code is available, so immediately prioritize mitigating internet-exposed instances of the extension.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-56290",
        "https://www.cve.org/CVERecord?id=CVE-2026-56290",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56290",
        "https://www.joomlack.fr/"
      ],
      "published": "2026-09-29T16:33:05Z",
      "updated": "2026-09-29T16:33:05Z"
    },
    {
      "id": "CVE-2026-72529",
      "url": "https://labs.diras.sa/cve/cve-2026-72529/",
      "title": "TrueConf Server missing-authentication remote script execution via port 4307",
      "vendor": "TrueConf",
      "product": "Server",
      "cwe": "CWE-306",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01464,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-20",
        "dueDate": "2026-08-23"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "5.x",
          "affected": "before 5.3",
          "fixed": "5.3"
        },
        {
          "branch": "5.x",
          "affected": "5.3 – before 5.3.9",
          "fixed": "5.3.9"
        },
        {
          "branch": "5.x",
          "affected": "5.4 – before 5.4.9",
          "fixed": "5.4.9"
        },
        {
          "branch": "5.x",
          "affected": "5.5 – before 5.5.5",
          "fixed": "5.5.5"
        }
      ],
      "dirasTake": "Urgent: CISA added this flaw to the Known Exploited Vulnerabilities catalog with a rapid remediation deadline, so prioritize patching to the fixed releases or apply vendor mitigations immediately for internet-facing instances.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-72529",
        "https://www.cve.org/CVERecord?id=CVE-2026-72529",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529",
        "https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/"
      ],
      "published": "2026-09-29T16:32:53Z",
      "updated": "2026-09-29T16:32:53Z"
    },
    {
      "id": "CVE-2026-81578",
      "url": "https://labs.diras.sa/cve/cve-2026-81578/",
      "title": "PaperCut NG/MF missing authentication lets unauthenticated remote modify configs",
      "vendor": "PaperCut",
      "product": "NG/MF",
      "cwe": "CWE-305",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.04481,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-31",
        "dueDate": "2026-09-14"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "24.x",
          "affected": "before 24.1.10",
          "fixed": "24.1.10"
        },
        {
          "branch": "25.x",
          "affected": "25.0.0 – before 25.0.13",
          "fixed": "25.0.13"
        },
        {
          "branch": "26.x",
          "affected": "26.0.0 – before 26.0.5",
          "fixed": "26.0.5"
        }
      ],
      "dirasTake": "Urgent — CISA placed this vulnerability on its Known Exploited Vulnerabilities list with a remediation due date, and public exploit code exists; prioritize patching or mitigating internet-exposed PaperCut NG/MF instances immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-81578",
        "https://www.cve.org/CVERecord?id=CVE-2026-81578",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578",
        "https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"
      ],
      "published": "2026-09-29T16:32:42Z",
      "updated": "2026-09-29T16:32:42Z"
    },
    {
      "id": "CVE-2026-86218",
      "url": "https://labs.diras.sa/cve/cve-2026-86218/",
      "title": "N-central pre-auth remote code execution",
      "vendor": "N-able",
      "product": "N-central",
      "cwe": "CWE-96",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.12928,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-08",
        "dueDate": "2026-09-11"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "2026.x",
          "affected": "before 2026.3.1.14",
          "fixed": "2026.3.1.14"
        }
      ],
      "dirasTake": "Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid remediation requirement, so apply the vendor fixes or mitigations immediately, prioritizing internet-facing N-central instances.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-86218",
        "https://www.cve.org/CVERecord?id=CVE-2026-86218",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86218",
        "https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution"
      ],
      "published": "2026-09-29T16:32:27Z",
      "updated": "2026-09-29T16:32:27Z"
    },
    {
      "id": "CVE-2026-49869",
      "url": "https://labs.diras.sa/cve/cve-2026-49869/",
      "title": "Kestra OSS unauthenticated remote code execution",
      "vendor": "Kestra",
      "product": "Kestra OSS",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.02095,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-02",
        "dueDate": "2026-09-05"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "kestra",
          "affected": "< 1.0.45",
          "fixed": null
        },
        {
          "branch": "kestra",
          "affected": ">= 1.1.0, < 1.3.21",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA added this vulnerability to the Known Exploited Vulnerabilities catalog with a near-term remediation deadline, which indicates authorities require immediate action; treat internet-exposed Kestra services as high priority to mitigate now.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-49869",
        "https://www.cve.org/CVERecord?id=CVE-2026-49869",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-49869",
        "https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx"
      ],
      "published": "2026-09-29T16:32:13Z",
      "updated": "2026-09-29T16:32:13Z"
    },
    {
      "id": "CVE-2026-48282",
      "url": "https://labs.diras.sa/cve/cve-2026-48282/",
      "title": "ColdFusion path traversal pre-auth remote code execution",
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.42388,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-07",
        "dueDate": "2026-07-10"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "ColdFusion 2025 9.x",
          "affected": "9 and earlier",
          "fixed": null
        },
        {
          "branch": "ColdFusion 2023 20.x",
          "affected": "20 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA added this vulnerability to its KEV catalog with a short remediation deadline, and public exploit code exists; prioritize mitigations or vendor guidance immediately for internet-facing ColdFusion instances.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-48282",
        "https://www.cve.org/CVERecord?id=CVE-2026-48282",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48282",
        "https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html"
      ],
      "published": "2026-09-29T16:31:56Z",
      "updated": "2026-09-29T16:31:56Z"
    },
    {
      "id": "CVE-2026-16812",
      "url": "https://labs.diras.sa/cve/cve-2026-16812/",
      "title": "VeloCloud Orchestrator pre-auth command injection in on‑prem VCO",
      "vendor": "Arista",
      "product": "VeloCloud Orchestrator",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.01001,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-27",
        "dueDate": "2026-07-30"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "5.x",
          "affected": "5.2.0 – before 5.2.3.14",
          "fixed": "5.2.3.14"
        },
        {
          "branch": "6.x",
          "affected": "6.1.0 – before 6.1.3.4",
          "fixed": "6.1.3.4"
        },
        {
          "branch": "6.x",
          "affected": "6.4.0 – before 6.4.2.4",
          "fixed": "6.4.2.4"
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – before 7.0.0.1",
          "fixed": "7.0.0.1"
        }
      ],
      "dirasTake": "Urgent: this is listed on CISA’s Known Exploited Vulnerabilities catalog with a 2026-07-30 remediation date and the bug requires no authentication, so prioritize patching or mitigating internet-exposed VCO instances immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-16812",
        "https://www.cve.org/CVERecord?id=CVE-2026-16812",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16812",
        "https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144"
      ],
      "published": "2026-09-29T16:31:38Z",
      "updated": "2026-09-29T16:31:38Z"
    },
    {
      "id": "CVE-2026-5430",
      "url": "https://labs.diras.sa/cve/cve-2026-5430/",
      "title": "WSO2 Multiple Products JWT verification bypass remote code execution",
      "vendor": "WSO2",
      "product": "Multiple Products",
      "cwe": "CWE-347",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00588,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-24",
        "dueDate": "2026-09-27"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "WSO2 Universal Gateway 4.x",
          "affected": "4.5.0 – before 4.5.0.57",
          "fixed": "4.5.0.57"
        },
        {
          "branch": "WSO2 Universal Gateway 4.x",
          "affected": "4.6.0 – before 4.6.0.21",
          "fixed": "4.6.0.21"
        },
        {
          "branch": "WSO2 Traffic Manager 4.x",
          "affected": "4.5.0 – before 4.5.0.56",
          "fixed": "4.5.0.56"
        },
        {
          "branch": "WSO2 Traffic Manager 4.x",
          "affected": "4.6.0 – before 4.6.0.21",
          "fixed": "4.6.0.21"
        },
        {
          "branch": "WSO2 API Control Plane 4.x",
          "affected": "4.5.0 – before 4.5.0.58",
          "fixed": "4.5.0.58"
        },
        {
          "branch": "WSO2 API Control Plane 4.x",
          "affected": "4.6.0 – before 4.6.0.22",
          "fixed": "4.6.0.22"
        },
        {
          "branch": "WSO2 API Manager 4.x",
          "affected": "4.1.0 – before 4.1.0.257",
          "fixed": "4.1.0.257"
        },
        {
          "branch": "WSO2 API Manager 4.x",
          "affected": "4.2.0 – before 4.2.0.197",
          "fixed": "4.2.0.197"
        },
        {
          "branch": "WSO2 API Manager 4.x",
          "affected": "4.3.0 – before 4.3.0.108",
          "fixed": "4.3.0.108"
        },
        {
          "branch": "WSO2 API Manager 4.x",
          "affected": "4.4.0 – before 4.4.0.72",
          "fixed": "4.4.0.72"
        }
      ],
      "dirasTake": "Urgent — CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog with a federal remediation due date, and public exploit code exists, so prioritize patching or mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-5430",
        "https://www.cve.org/CVERecord?id=CVE-2026-5430",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-5430",
        "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/"
      ],
      "published": "2026-09-29T16:31:24Z",
      "updated": "2026-09-29T16:31:24Z"
    },
    {
      "id": "CVE-2026-93952",
      "url": "https://labs.diras.sa/cve/cve-2026-93952/",
      "title": "VeloCloud Orchestrator improper input validation allows remote privileged access",
      "vendor": "Arista",
      "product": "VeloCloud Orchestrator",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.01062,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-22",
        "dueDate": "2026-09-25"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "5.x",
          "affected": "5.2.0 – 5.2.3.15",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.1.0 – 6.1.3.7",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.4.0 – 6.4.2.7",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – 7.0.0.2",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a federal fix deadline, so prioritize mitigation for internet-exposed VeloCloud Orchestrator instances immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-93952",
        "https://www.cve.org/CVERecord?id=CVE-2026-93952",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952",
        "https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183"
      ],
      "published": "2026-09-29T16:31:07Z",
      "updated": "2026-09-29T16:31:07Z"
    },
    {
      "id": "CVE-2026-56155",
      "url": "https://labs.diras.sa/cve/cve-2026-56155/",
      "title": "Active Directory Federation Services insufficient access control local privilege elevation",
      "vendor": "Microsoft",
      "product": "Active Directory Federation Services",
      "cwe": "CWE-1220",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00346,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-14",
        "dueDate": "2026-07-28"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26226",
          "fixed": "6.2.9200.26226"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23291",
          "fixed": "6.3.9600.23291"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23291",
          "fixed": "6.3.9600.23291"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9339",
          "fixed": "10.0.14393.9339"
        },
        {
          "branch": "Windows Server 2019 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        },
        {
          "branch": "Windows Server 2019 (Server Core installation) 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9020",
          "fixed": "10.0.17763.9020"
        }
      ],
      "dirasTake": "Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a remediation due date of 2026-07-28, so prioritize patching AD FS servers or applying vendor mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-56155",
        "https://www.cve.org/CVERecord?id=CVE-2026-56155",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56155",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155"
      ],
      "published": "2026-09-29T16:30:54Z",
      "updated": "2026-09-29T16:30:54Z"
    },
    {
      "id": "CVE-2026-83549",
      "url": "https://labs.diras.sa/cve/cve-2026-83549/",
      "title": "SMA1000 Appliances OS command injection requiring admin credentials",
      "vendor": "SonicWall",
      "product": "SMA1000 Appliances",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.1076,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-02",
        "dueDate": "2026-09-05"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "12.x",
          "affected": "12.4.3-03453 (platform-hotfix) and older versions",
          "fixed": null
        },
        {
          "branch": "12.x",
          "affected": "12.5.0-02835 (platform-hotfix) and older versions",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA added this CVE to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline (2026-09-05), indicating immediate action is required for federal assets and high-risk internet-facing appliances.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-83549",
        "https://www.cve.org/CVERecord?id=CVE-2026-83549",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83549",
        "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016"
      ],
      "published": "2026-09-29T16:30:42Z",
      "updated": "2026-09-29T16:30:42Z"
    },
    {
      "id": "CVE-2019-1068",
      "url": "https://labs.diras.sa/cve/cve-2019-1068/",
      "title": "SQL Server remote code execution in internal function handling",
      "vendor": "Microsoft",
      "product": "SQL Server",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.57906,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-26",
        "dueDate": "2026-08-29"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)",
          "affected": "unspecified",
          "fixed": null
        },
        {
          "branch": "Microsoft SQL Server 2014.x",
          "affected": "2014 Service Pack 2 for 32-bit Systems (CU)",
          "fixed": null
        },
        {
          "branch": "Microsoft SQL Server 2014.x",
          "affected": "2014 Service Pack 2 for x64-based Systems (CU)",
          "fixed": null
        },
        {
          "branch": "Microsoft SQL Server 2016.x",
          "affected": "2016 for x64-based Systems Service Pack 1 (CU)",
          "fixed": null
        },
        {
          "branch": "Microsoft SQL Server 2017.x",
          "affected": "2017 for x64-based Systems (CU)",
          "fixed": null
        },
        {
          "branch": "Microsoft SQL Server 2016.x",
          "affected": "2016 for x64-based Systems Service Pack 2 (CU)",
          "fixed": null
        },
        {
          "branch": "Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)",
          "affected": "unspecified",
          "fixed": null
        },
        {
          "branch": "Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)",
          "affected": "unspecified",
          "fixed": null
        },
        {
          "branch": "Microsoft SQL Server 2017 for x64-based Systems (GDR)",
          "affected": "unspecified",
          "fixed": null
        },
        {
          "branch": "Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)",
          "affected": "unspecified",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this vulnerability was added to CISA’s Known Exploited Vulnerabilities list on 2026-08-26 with a federal remediation deadline of 2026-08-29, so prioritize mitigation for internet-facing and critical SQL Server instances immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2019-1068",
        "https://www.cve.org/CVERecord?id=CVE-2019-1068",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1068",
        "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068"
      ],
      "published": "2026-09-29T16:30:21Z",
      "updated": "2026-09-29T16:30:21Z"
    },
    {
      "id": "CVE-2026-7273",
      "url": "https://labs.diras.sa/cve/cve-2026-7273/",
      "title": "Zyxel GS1900 Series Switches stack-based buffer overflow in CGI",
      "vendor": "Zyxel",
      "product": "GS1900 Series Switches",
      "cwe": "CWE-121",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.02501,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-21",
        "dueDate": "2026-09-24"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "GS1900-48HPv2 firmware",
          "affected": "<= 2.90(ABTQ.1)C0",
          "fixed": null
        },
        {
          "branch": "GS1900-8 firmware",
          "affected": "<= 2.90(AAHH.1)C0",
          "fixed": null
        },
        {
          "branch": "GS1900-8HP firmware",
          "affected": "<= 2.90(AAHI.1)C0",
          "fixed": null
        },
        {
          "branch": "GS1900-10HP firmware",
          "affected": "<= 2.90(AAZI.1)C0",
          "fixed": null
        },
        {
          "branch": "GS1900-16 firmware",
          "affected": "<= 2.90(AAHJ.1)C0",
          "fixed": null
        },
        {
          "branch": "GS1900-24 firmware",
          "affected": "<= 2.90(AAHL.1)C0",
          "fixed": null
        },
        {
          "branch": "GS1900-24E firmware",
          "affected": "<= 2.90(AAHK.1)C0",
          "fixed": null
        },
        {
          "branch": "GS1900-24EP firmware",
          "affected": "<= 2.90(ABTO.1)C0",
          "fixed": null
        },
        {
          "branch": "GS1900-24HPv2 firmware",
          "affected": "<= 2.90(ABTP.1)C0",
          "fixed": null
        },
        {
          "branch": "GS1900-48 firmware",
          "affected": "<= 2.90(AAHN.1)C0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline, indicating high operational priority; treat internet- or LAN-exposed GS1900 management interfaces as high risk and act immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-7273",
        "https://www.cve.org/CVERecord?id=CVE-2026-7273",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7273",
        "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026"
      ],
      "published": "2026-09-29T16:30:07Z",
      "updated": "2026-09-29T16:30:07Z"
    },
    {
      "id": "CVE-2026-68820",
      "url": "https://labs.diras.sa/cve/cve-2026-68820/",
      "title": "Windows Ancillary Function Driver for WinSock use-after-free local privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows Ancillary Function Driver for WinSock",
      "cwe": "CWE-416",
      "cvss": {
        "version": "3.1",
        "score": 7,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00332,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-11",
        "dueDate": "2026-08-25"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9418",
          "fixed": "10.0.14393.9418"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9121",
          "fixed": "10.0.17763.9121"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7663",
          "fixed": "10.0.19044.7663"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7663",
          "fixed": "10.0.19045.7663"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7517",
          "fixed": "10.0.22631.7517"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9168",
          "fixed": "10.0.26100.9168"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9168",
          "fixed": "10.0.26200.9168"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2704",
          "fixed": "10.0.28000.2704"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26280",
          "fixed": "6.2.9200.26280"
        }
      ],
      "dirasTake": "Urgently prioritize remediation: CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog with a required action date of 2026-08-25, so apply vendor updates or mitigations immediately for exposed assets.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-68820",
        "https://www.cve.org/CVERecord?id=CVE-2026-68820",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-68820",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820"
      ],
      "published": "2026-09-29T16:29:54Z",
      "updated": "2026-09-29T16:29:54Z"
    },
    {
      "id": "CVE-2026-81963",
      "url": "https://labs.diras.sa/cve/cve-2026-81963/",
      "title": "Windows local privilege escalation in Windows Update Stack (link following)",
      "vendor": "Microsoft",
      "product": "Windows",
      "cwe": "CWE-59",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.00393,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-08",
        "dueDate": "2026-09-22"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.7582",
          "fixed": "10.0.22631.7582"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.9445",
          "fixed": "10.0.26100.9445"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.9445",
          "fixed": "10.0.26200.9445"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.2954",
          "fixed": "10.0.28000.2954"
        },
        {
          "branch": "Windows Server 2025 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33438",
          "fixed": "10.0.26100.33438"
        },
        {
          "branch": "Windows Server 2025 (Server Core installation) 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.33438",
          "fixed": "10.0.26100.33438"
        }
      ],
      "dirasTake": "Urgent patching is warranted: CISA added this vulnerability to the Known Exploited Vulnerabilities catalog with a remediation deadline, so prioritize installing the vendor fixes listed for the affected builds immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-81963",
        "https://www.cve.org/CVERecord?id=CVE-2026-81963",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81963",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963"
      ],
      "published": "2026-09-29T16:29:41Z",
      "updated": "2026-09-29T16:29:41Z"
    },
    {
      "id": "CVE-2026-85880",
      "url": "https://labs.diras.sa/cve/cve-2026-85880/",
      "title": "Windows ALPC heap overflow local privilege escalation",
      "vendor": "Microsoft",
      "product": "Windows",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 7.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.03616,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-08",
        "dueDate": "2026-09-22"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.9245",
          "fixed": "10.0.17763.9245"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7725",
          "fixed": "10.0.19044.7725"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7725",
          "fixed": "10.0.19045.7725"
        },
        {
          "branch": "Windows Server 2012 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 (Server Core installation) 6.x",
          "affected": "6.2.9200.0 – before 6.2.9200.26349",
          "fixed": "6.2.9200.26349"
        },
        {
          "branch": "Windows Server 2012 R2 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2012 R2 (Server Core installation) 6.x",
          "affected": "6.3.9600.0 – before 6.3.9600.23398",
          "fixed": "6.3.9600.23398"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        },
        {
          "branch": "Windows Server 2016 (Server Core installation) 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9512",
          "fixed": "10.0.14393.9512"
        }
      ],
      "dirasTake": "Urgent: CISA placed this defect on its Known Exploited Vulnerabilities list with a remediation deadline, so prioritize installing vendor fixes or mitigations immediately to meet that requirement.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85880",
        "https://www.cve.org/CVERecord?id=CVE-2026-85880",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85880",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880"
      ],
      "published": "2026-09-29T16:29:25Z",
      "updated": "2026-09-29T16:29:25Z"
    },
    {
      "id": "CVE-2008-4128",
      "url": "https://labs.diras.sa/cve/cve-2008-4128/",
      "title": "Cisco IOS cross-site request forgery lets remote attackers run commands",
      "vendor": "Cisco",
      "product": "IOS",
      "cwe": "CWE-352",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
      },
      "epss": 0.33871,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-13",
        "dueDate": "2026-07-16"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [],
      "dirasTake": "Urgent: CISA added CVE-2008-4128 to the Known Exploited Vulnerabilities catalog with a July 16, 2026 remediation deadline, so prioritize mitigation for internet-facing IOS management interfaces immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2008-4128",
        "https://www.cve.org/CVERecord?id=CVE-2008-4128",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128",
        "https://www.exploit-db.com/exploits/6476",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/45226",
        "http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html",
        "https://www.exploit-db.com/exploits/6477",
        "http://www.securityfocus.com/bid/31218"
      ],
      "published": "2026-09-29T16:29:12Z",
      "updated": "2026-09-29T16:29:12Z"
    },
    {
      "id": "CVE-2026-55255",
      "url": "https://labs.diras.sa/cve/cve-2026-55255/",
      "title": "Langflow authorization bypass lets authenticated users run other users' flows",
      "vendor": "Langflow",
      "product": "Langflow",
      "cwe": "CWE-639",
      "cvss": {
        "version": "3.1",
        "score": 8.4,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L"
      },
      "epss": 0.00887,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-07",
        "dueDate": "2026-07-10"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "langflow",
          "affected": "< 1.9.1",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this CVE to the Known Exploited Vulnerabilities catalog with a 2026-07-10 remediation requirement for federal agencies, so prioritize mitigations now and restrict internet exposure of Langflow instances until a vendor fix is installed.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-55255",
        "https://www.cve.org/CVERecord?id=CVE-2026-55255",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255",
        "https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2",
        "https://github.com/langflow-ai/langflow/pull/12832",
        "https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e"
      ],
      "published": "2026-09-29T16:28:49Z",
      "updated": "2026-09-29T16:28:49Z"
    },
    {
      "id": "CVE-2026-45659",
      "url": "https://labs.diras.sa/cve/cve-2026-45659/",
      "title": "SharePoint Server deserialization flaw allows authenticated remote code execution",
      "vendor": "Microsoft",
      "product": "SharePoint Server",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.02704,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-01",
        "dueDate": "2026-07-04"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SharePoint Enterprise Server 2016 16.x",
          "affected": "16.0.0 – before 16.0.5552.1002",
          "fixed": "16.0.5552.1002"
        },
        {
          "branch": "Microsoft SharePoint Server 2019 16.x",
          "affected": "16.0.0 – before 16.0.10417.20128",
          "fixed": "16.0.10417.20128"
        },
        {
          "branch": "Microsoft SharePoint Server Subscription Edition 16.x",
          "affected": "16.0.0 – before 16.0.19725.20280",
          "fixed": "16.0.19725.20280"
        }
      ],
      "dirasTake": "Urgent: this issue was added to CISA’s Known Exploited Vulnerabilities catalog with a July 4, 2026 federal remediation deadline, so prioritize patching or mitigations immediately for internet-facing or high-value SharePoint servers.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-45659",
        "https://www.cve.org/CVERecord?id=CVE-2026-45659",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659"
      ],
      "published": "2026-09-29T16:28:23Z",
      "updated": "2026-09-29T16:28:23Z"
    },
    {
      "id": "CVE-2026-85046",
      "url": "https://labs.diras.sa/cve/cve-2026-85046/",
      "title": "Chromium V8 type confusion remote code execution",
      "vendor": "Google",
      "product": "Chromium V8",
      "cwe": "CWE-843",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.48881,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-04",
        "dueDate": "2026-09-18"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "152.x",
          "affected": "152.0.7977.82 – before 152.0.7977.82",
          "fixed": "152.0.7977.82"
        }
      ],
      "dirasTake": "Urgent: this defect is listed on CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline, so prioritize updating or applying vendor mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85046",
        "https://www.cve.org/CVERecord?id=CVE-2026-85046",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html",
        "https://issues.chromium.org/issues/542403045"
      ],
      "published": "2026-09-29T16:28:08Z",
      "updated": "2026-09-29T16:28:08Z"
    },
    {
      "id": "CVE-2026-87491",
      "url": "https://labs.diras.sa/cve/cve-2026-87491/",
      "title": "Chromium V8 out-of-bounds write remote code execution",
      "vendor": "Google",
      "product": "Chromium V8",
      "cwe": "CWE-787",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "epss": 0.03142,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-09",
        "dueDate": "2026-09-23"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "153.x",
          "affected": "153.0.8010.36 – before 153.0.8010.36",
          "fixed": "153.0.8010.36"
        }
      ],
      "dirasTake": "Urgent — CISA added this defect to the Known Exploited Vulnerabilities catalog on 2026-09-09 with a federal remediation deadline of 2026-09-23, and public exploit code is available, so prioritize applying the vendor fix immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-87491",
        "https://www.cve.org/CVERecord?id=CVE-2026-87491",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87491",
        "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html",
        "https://issues.chromium.org/issues/543557673"
      ],
      "published": "2026-09-29T16:27:54Z",
      "updated": "2026-09-29T16:27:54Z"
    },
    {
      "id": "CVE-2025-68686",
      "url": "https://labs.diras.sa/cve/cve-2025-68686/",
      "title": "FortiOS exposure of sensitive information to unauthenticated remote actors",
      "vendor": "Fortinet",
      "product": "FortiOS",
      "cwe": "CWE-200",
      "cvss": {
        "version": "3.1",
        "score": 5.9,
        "severity": "medium",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
      },
      "epss": 0.29601,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-27",
        "dueDate": "2026-08-10"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.6.0 – 7.6.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.4.0 – 7.4.6",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0 – 7.2.13",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – 7.0.19",
          "fixed": null
        },
        {
          "branch": "6.x",
          "affected": "6.4.0 – 6.4.16",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a mandated remediation date, so organisations with internet-facing FortiOS instances should prioritise risk assessment and apply vendor mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2025-68686",
        "https://www.cve.org/CVERecord?id=CVE-2025-68686",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68686",
        "https://fortiguard.fortinet.com/psirt/FG-IR-25-934"
      ],
      "published": "2026-09-29T16:27:36Z",
      "updated": "2026-09-29T16:27:36Z"
    },
    {
      "id": "CVE-2026-60137",
      "url": "https://labs.diras.sa/cve/cve-2026-60137/",
      "title": "WordPress Core SQL injection via author__not_in parameter",
      "vendor": "WordPress",
      "product": "Core",
      "cwe": "CWE-89",
      "cvss": {
        "version": "3.1",
        "score": 5.9,
        "severity": "medium",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
      },
      "epss": 0.05906,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-21",
        "dueDate": "2026-08-04"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "6.x",
          "affected": "6.8.0 – before 6.8.6",
          "fixed": "6.8.6"
        },
        {
          "branch": "6.x",
          "affected": "6.9.0 – before 6.9.5",
          "fixed": "6.9.5"
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – before 7.0.2",
          "fixed": "7.0.2"
        }
      ],
      "dirasTake": "Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a federal remediation deadline, and public exploit code exists — prioritize patching or mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-60137",
        "https://www.cve.org/CVERecord?id=CVE-2026-60137",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137",
        "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf",
        "https://wordpress.org/news/2026/07/wordpress-7-0-2-release/"
      ],
      "published": "2026-09-29T16:27:22Z",
      "updated": "2026-09-29T16:27:22Z"
    },
    {
      "id": "CVE-2026-84869",
      "url": "https://labs.diras.sa/cve/cve-2026-84869/",
      "title": "ScreenConnect missing authorization lets active-session attacker transfer and run files",
      "vendor": "ConnectWise",
      "product": "ScreenConnect",
      "cwe": "CWE-862",
      "cvss": {
        "version": "3.1",
        "score": 9.9,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.00924,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-11",
        "dueDate": "2026-09-14"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "ScreenConnect",
          "affected": "All versions prior to 26.6.5",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a short remediation deadline (2026-09-14), so prioritize mitigation for internet-facing and high-value ScreenConnect instances immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-84869",
        "https://www.cve.org/CVERecord?id=CVE-2026-84869",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869",
        "https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin",
        "https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869",
        "https://www.connectwise.com/company/trust/advisories"
      ],
      "published": "2026-09-29T16:27:07Z",
      "updated": "2026-09-29T16:27:07Z"
    },
    {
      "id": "CVE-2026-67277",
      "url": "https://labs.diras.sa/cve/cve-2026-67277/",
      "title": "RouterOS missing-auth btest service kernel crash and memory disclosure",
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-306",
      "cvss": {
        "version": "3.1",
        "score": 8.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
      },
      "epss": 0.0156,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-10",
        "dueDate": "2026-09-13"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.24 – before 7.24.2",
          "fixed": "7.24.2"
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – before 7.23.4",
          "fixed": "7.23.4"
        },
        {
          "branch": "6.x",
          "affected": "6.0.0 – before 6.49.21",
          "fixed": "6.49.21"
        }
      ],
      "dirasTake": "Urgent — CISA added this issue to its Known Exploited Vulnerabilities catalog with a remediation deadline of 2026-09-13, so prioritize applying vendor fixes or mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-67277",
        "https://www.cve.org/CVERecord?id=CVE-2026-67277",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67277",
        "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
        "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
        "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/",
        "https://mikrotik.com/supportsec/september-2026-vulnerability/",
        "https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802",
        "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
        "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800"
      ],
      "published": "2026-09-29T16:26:54Z",
      "updated": "2026-09-29T16:26:54Z"
    },
    {
      "id": "CVE-2026-34486",
      "url": "https://labs.diras.sa/cve/cve-2026-34486/",
      "title": "Tomcat encrypt interceptor bypass exposes sensitive data",
      "vendor": "Apache",
      "product": "Tomcat",
      "cwe": "CWE-311",
      "cvss": {
        "version": "3.1",
        "score": 7.5,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
      },
      "epss": 0.06561,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-04",
        "dueDate": "2026-08-07"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "11.x",
          "affected": "11.0.20",
          "fixed": null
        },
        {
          "branch": "10.x",
          "affected": "10.1.53",
          "fixed": null
        },
        {
          "branch": "9.x",
          "affected": "9.0.116",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this CVE to its KEV catalog with a remediation deadline for federal agencies and public exploit code exists—treat exposed Tomcat servers as high priority and apply mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-34486",
        "https://www.cve.org/CVERecord?id=CVE-2026-34486",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486",
        "https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly"
      ],
      "published": "2026-09-29T16:26:10Z",
      "updated": "2026-09-29T16:26:10Z"
    },
    {
      "id": "CVE-2025-25249",
      "url": "https://labs.diras.sa/cve/cve-2025-25249/",
      "title": "Fortinet FortiOS and FortiSwitchManager heap buffer overflow remote code execution",
      "vendor": "Fortinet",
      "product": "Multiple Products",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.03859,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-09",
        "dueDate": "2026-09-12"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "FortiSwitchManager 7.x",
          "affected": "7.2.2 – 7.2.5",
          "fixed": null
        },
        {
          "branch": "FortiOS 7.x",
          "affected": "7.6.0 – 7.6.2",
          "fixed": null
        },
        {
          "branch": "FortiOS 7.x",
          "affected": "7.4.0 – 7.4.7",
          "fixed": null
        },
        {
          "branch": "FortiOS 7.x",
          "affected": "7.2.4 – 7.2.11",
          "fixed": null
        }
      ],
      "dirasTake": "Treat this as urgent: CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog with a federal remediation deadline, so prioritize mitigations for internet-facing FortiOS and FortiSwitchManager assets immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2025-25249",
        "https://www.cve.org/CVERecord?id=CVE-2025-25249",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249",
        "https://fortiguard.fortinet.com/psirt/FG-IR-25-084"
      ],
      "published": "2026-09-29T16:25:43Z",
      "updated": "2026-09-29T16:25:43Z"
    },
    {
      "id": "CVE-2026-39808",
      "url": "https://labs.diras.sa/cve/cve-2026-39808/",
      "title": "FortiSandbox OS command injection unauthenticated remote code execution",
      "vendor": "Fortinet",
      "product": "FortiSandbox",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.47362,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-16",
        "dueDate": "2026-07-19"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "FortiSandbox 4.x",
          "affected": "4.4.0 – 4.4.8",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 23.x",
          "affected": "23.4.4374",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 23.x",
          "affected": "23.4.4350",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 23.x",
          "affected": "23.3.4329",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 23.x",
          "affected": "23.1.4245",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 22.x",
          "affected": "22.2.4151",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 22.x",
          "affected": "22.2.4134",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 22.x",
          "affected": "22.1.4113",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 21.x",
          "affected": "21.4.4072",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 21.x",
          "affected": "21.3.4055",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added CVE-2026-39808 to the Known Exploited Vulnerabilities catalog with a July 19, 2026 remediation deadline and proof-of-concept code is public — immediately reduce internet exposure and apply vendor mitigations.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-39808",
        "https://www.cve.org/CVERecord?id=CVE-2026-39808",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808",
        "https://fortiguard.fortinet.com/psirt/FG-IR-26-100"
      ],
      "published": "2026-09-29T16:25:29Z",
      "updated": "2026-09-29T16:25:29Z"
    },
    {
      "id": "CVE-2026-33824",
      "url": "https://labs.diras.sa/cve/cve-2026-33824/",
      "title": "Internet Key Exchange (IKE) Service Extensions double free remote code execution",
      "vendor": "Microsoft",
      "product": "Internet Key Exchange (IKE) Service Extensions",
      "cwe": "CWE-415",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01619,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-18",
        "dueDate": "2026-08-21"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Windows 10 Version 1607 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9060",
          "fixed": "10.0.14393.9060"
        },
        {
          "branch": "Windows 10 Version 1809 10.x",
          "affected": "10.0.17763.0 – before 10.0.17763.8644",
          "fixed": "10.0.17763.8644"
        },
        {
          "branch": "Windows 10 Version 21H2 10.x",
          "affected": "10.0.19044.0 – before 10.0.19044.7184",
          "fixed": "10.0.19044.7184"
        },
        {
          "branch": "Windows 10 Version 22H2 10.x",
          "affected": "10.0.19045.0 – before 10.0.19045.7184",
          "fixed": "10.0.19045.7184"
        },
        {
          "branch": "Windows 11 version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.6936",
          "fixed": "10.0.22631.6936"
        },
        {
          "branch": "Windows 11 Version 23H2 10.x",
          "affected": "10.0.22631.0 – before 10.0.22631.6936",
          "fixed": "10.0.22631.6936"
        },
        {
          "branch": "Windows 11 Version 24H2 10.x",
          "affected": "10.0.26100.0 – before 10.0.26100.8246",
          "fixed": "10.0.26100.8246"
        },
        {
          "branch": "Windows 11 Version 25H2 10.x",
          "affected": "10.0.26200.0 – before 10.0.26200.8246",
          "fixed": "10.0.26200.8246"
        },
        {
          "branch": "Windows 11 version 26H1 10.x",
          "affected": "10.0.28000.0 – before 10.0.28000.1836",
          "fixed": "10.0.28000.1836"
        },
        {
          "branch": "Windows Server 2016 10.x",
          "affected": "10.0.14393.0 – before 10.0.14393.9060",
          "fixed": "10.0.14393.9060"
        }
      ],
      "dirasTake": "Urgent — CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog with a rapid mitigation deadline, so prioritize installing the vendor fixes or applying mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-33824",
        "https://www.cve.org/CVERecord?id=CVE-2026-33824",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824"
      ],
      "published": "2026-09-29T16:24:58Z",
      "updated": "2026-09-29T16:24:58Z"
    },
    {
      "id": "CVE-2026-8037",
      "url": "https://labs.diras.sa/cve/cve-2026-8037/",
      "title": "LoadMaster command injection pre-auth remote code execution",
      "vendor": "Progress",
      "product": "LoadMaster",
      "cwe": "CWE-77",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.77362,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-07",
        "dueDate": "2026-08-10"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "LoadMaster",
          "affected": "V7.2.60.0 – before V7.2.63.2",
          "fixed": "V7.2.63.2"
        },
        {
          "branch": "LoadMaster",
          "affected": "V7.2.45.12 – before V7.2.54.18",
          "fixed": "V7.2.54.18"
        },
        {
          "branch": "ECS Connections Manager",
          "affected": "V7.2.60.0 – before V7.2.63.2",
          "fixed": "V7.2.63.2"
        },
        {
          "branch": "Object Scale Connection Manager",
          "affected": "V7.2.60.0 – before V7.2.63.2",
          "fixed": "V7.2.63.2"
        },
        {
          "branch": "MOVEit WAF",
          "affected": "V7.2.60.0 – before V7.2.63.2",
          "fixed": "V7.2.63.2"
        }
      ],
      "dirasTake": "Urgent: CISA placed this CVE on its Known Exploited Vulnerabilities list with a federal remediation deadline of 2026-08-10, indicating immediate patching or mitigation is required for exposed systems.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-8037",
        "https://www.cve.org/CVERecord?id=CVE-2026-8037",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8037",
        "https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691"
      ],
      "published": "2026-09-29T16:24:39Z",
      "updated": "2026-09-29T16:24:39Z"
    },
    {
      "id": "CVE-2026-25089",
      "url": "https://labs.diras.sa/cve/cve-2026-25089/",
      "title": "FortiSandbox OS command injection unauthenticated remote command execution",
      "vendor": "Fortinet",
      "product": "FortiSandbox",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.76112,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-16",
        "dueDate": "2026-07-19"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "FortiSandbox 5.x",
          "affected": "5.0.0 – 5.0.5",
          "fixed": null
        },
        {
          "branch": "FortiSandbox 4.x",
          "affected": "4.4.0 – 4.4.8",
          "fixed": null
        },
        {
          "branch": "FortiSandbox 4.x",
          "affected": "4.2.1 – 4.2.8",
          "fixed": null
        },
        {
          "branch": "FortiSandbox Cloud 5.x",
          "affected": "5.0.4 – 5.0.5",
          "fixed": null
        },
        {
          "branch": "FortiSandbox PaaS 5.x",
          "affected": "5.0.4 – 5.0.5",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA placed this issue on the Known Exploited Vulnerabilities list with a July 19, 2026 remediation deadline, and public exploit code exists—treat internet-exposed FortiSandbox instances as high priority to isolate or mitigate immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-25089",
        "https://www.cve.org/CVERecord?id=CVE-2026-25089",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089",
        "https://fortiguard.fortinet.com/psirt/FG-IR-26-141"
      ],
      "published": "2026-09-29T16:24:11Z",
      "updated": "2026-09-29T16:24:11Z"
    },
    {
      "id": "CVE-2026-86060",
      "url": "https://labs.diras.sa/cve/cve-2026-86060/",
      "title": "RouterOS SSH login username handling lets unauthenticated users escalate privileges",
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-88",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01849,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-10",
        "dueDate": "2026-09-13"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.24 – before 7.24.2",
          "fixed": "7.24.2"
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – before 7.23.4",
          "fixed": "7.23.4"
        },
        {
          "branch": "6.x",
          "affected": "6.0.0 – before 6.49.21",
          "fixed": "6.49.21"
        }
      ],
      "dirasTake": "Urgent — CISA added this CVE to its Known Exploited Vulnerabilities catalog with a rapid remediation due date, so prioritize patching or mitigating internet-exposed RouterOS SSH services immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-86060",
        "https://www.cve.org/CVERecord?id=CVE-2026-86060",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060",
        "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
        "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
        "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/",
        "https://mikrotik.com/supportsec/september-2026-vulnerability/",
        "https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802",
        "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
        "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800"
      ],
      "published": "2026-09-29T16:23:54Z",
      "updated": "2026-09-29T16:23:54Z"
    },
    {
      "id": "CVE-2026-85102",
      "url": "https://labs.diras.sa/cve/cve-2026-85102/",
      "title": "Quantum Security Gateway improper certificate validation lets unauthenticated attacker run code",
      "vendor": "Check Point",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-295",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.07546,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-22",
        "dueDate": "2026-09-25"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "Quantum Security Gateway",
          "affected": "R82.10 with Jumbo Hotfix Take 43 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Gateway",
          "affected": "R82 with Jumbo Hotfix Take 125 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Gateway",
          "affected": "R81.20 with Jumbo Hotfix Take 165 or below",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this flaw to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline, so prioritize mitigation for internet-facing Quantum Security Gateway instances and follow vendor guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85102",
        "https://www.cve.org/CVERecord?id=CVE-2026-85102",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85102",
        "https://support.checkpoint.com/results/sk/sk1000117"
      ],
      "published": "2026-09-29T16:23:41Z",
      "updated": "2026-09-29T16:23:41Z"
    },
    {
      "id": "CVE-2026-76461",
      "url": "https://labs.diras.sa/cve/cve-2026-76461/",
      "title": "Cisco Secure Email Gateway SQL injection leads to pre-auth remote code execution",
      "vendor": "Cisco",
      "product": "Secure Email Gateway",
      "cwe": "CWE-89",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.28269,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-14",
        "dueDate": "2026-09-17"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "14.0.0-698",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.5.1-277",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.0.0-392",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.2.0-620",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.0.5-007",
          "fixed": null
        },
        {
          "branch": "13.x",
          "affected": "13.5.4-038",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.2.1-020",
          "fixed": null
        },
        {
          "branch": "14.x",
          "affected": "14.3.0-032",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15.0.0-104",
          "fixed": null
        },
        {
          "branch": "15.x",
          "affected": "15.0.1-030",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a short federal remediation deadline, so prioritize mitigation now and follow Cisco and CISA guidance immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76461",
        "https://www.cve.org/CVERecord?id=CVE-2026-76461",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX"
      ],
      "published": "2026-09-29T16:23:26Z",
      "updated": "2026-09-29T16:23:26Z"
    },
    {
      "id": "CVE-2026-93616",
      "url": "https://labs.diras.sa/cve/cve-2026-93616/",
      "title": "Quantum Security Management directory traversal allows unauthenticated code execution",
      "vendor": "Check Point",
      "product": "Quantum Security Management",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.19654,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-22",
        "dueDate": "2026-09-25"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "Quantum Security Management",
          "affected": "R82.20 with no Jumbo Hotfix",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R82.10 with Jumbo Hotfix Take 44 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R82 with Jumbo Hotfix Take 126 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R81.20 with Jumbo Hotfix Take 166 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R81.10 (EOS) with Jumbo Hotfix Take 190 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R81 (EOS)",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R80.40 (EOS)",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R80.30 (EOS)",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R80.20 (EOS)",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R80.10 (EOS)",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation deadline, and public exploit code is available, so owners should act immediately to reduce internet exposure and apply vendor guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-93616",
        "https://www.cve.org/CVERecord?id=CVE-2026-93616",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616",
        "https://support.checkpoint.com/results/sk/sk1000171"
      ],
      "published": "2026-09-29T16:23:12Z",
      "updated": "2026-09-29T16:23:12Z"
    },
    {
      "id": "CVE-2026-20079",
      "url": "https://labs.diras.sa/cve/cve-2026-20079/",
      "title": "Cisco Secure Firewall Management Center authentication bypass and RCE",
      "vendor": "Cisco",
      "product": "Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management",
      "cwe": "CWE-288",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.8818,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-09",
        "dueDate": "2026-09-12"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.0.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.1.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.1.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.3",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a full pre-auth root compromise and CISA added it to the Known Exploited Vulnerabilities catalog with a mandatory remediation date, so treat exposed FMC/SCC management interfaces as high priority for mitigation.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20079",
        "https://www.cve.org/CVERecord?id=CVE-2026-20079",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20079",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2"
      ],
      "published": "2026-09-29T16:22:55Z",
      "updated": "2026-09-29T16:22:55Z"
    },
    {
      "id": "CVE-2026-15409",
      "url": "https://labs.diras.sa/cve/cve-2026-15409/",
      "title": "SonicWall SMA1000 SSRF allows unauthenticated request forging",
      "vendor": "SonicWall",
      "product": "SMA1000 Appliances",
      "cwe": "CWE-918",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.06795,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-14",
        "dueDate": "2026-07-17"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "12.x",
          "affected": "12.4.3-03245 – 12.4.3-03434",
          "fixed": null
        },
        {
          "branch": "12.x",
          "affected": "12.5.0-02283 – 12.5.0-02800",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA added this flaw to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline and the vulnerability has known ransomware campaign use, so prioritize mitigation for internet-facing SMA1000 Appliances immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-15409",
        "https://www.cve.org/CVERecord?id=CVE-2026-15409",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409",
        "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008"
      ],
      "published": "2026-09-29T16:22:43Z",
      "updated": "2026-09-29T16:22:43Z"
    },
    {
      "id": "CVE-2026-0770",
      "url": "https://labs.diras.sa/cve/cve-2026-0770/",
      "title": "Langflow exec_globals pre-auth remote code execution",
      "vendor": "Langflow",
      "product": "Langflow",
      "cwe": "CWE-829",
      "cvss": {
        "version": "3.0",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.63839,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-21",
        "dueDate": "2026-07-24"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.4.2",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog with a mitigation due date of 2026-07-24, and the flaw can be triggered without authentication and has public exploit code available.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-0770",
        "https://www.cve.org/CVERecord?id=CVE-2026-0770",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0770",
        "https://www.zerodayinitiative.com/advisories/ZDI-26-036/"
      ],
      "published": "2026-09-29T16:22:29Z",
      "updated": "2026-09-29T16:22:29Z"
    },
    {
      "id": "CVE-2026-8452",
      "url": "https://labs.diras.sa/cve/cve-2026-8452/",
      "title": "Citrix NetScaler ADC and Gateway memory overflow pre-auth remote code execution",
      "vendor": "Citrix",
      "product": "NetScaler ADC and NetScaler Gateway",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01011,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-26",
        "dueDate": "2026-08-29"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "ADC 72.x",
          "affected": "14.1 – before 72.61",
          "fixed": "72.61"
        },
        {
          "branch": "ADC 63.x",
          "affected": "13.1 – before 63.18",
          "fixed": "63.18"
        },
        {
          "branch": "ADC 72.x",
          "affected": "14.1 FIPS – before 72.61",
          "fixed": "72.61"
        },
        {
          "branch": "ADC 37.x",
          "affected": "13.1 FIPS and NDcPP – before 37.272",
          "fixed": "37.272"
        },
        {
          "branch": "Gateway 72.x",
          "affected": "14.1 – before 72.61",
          "fixed": "72.61"
        },
        {
          "branch": "Gateway 63.x",
          "affected": "13.1 – before 63.18",
          "fixed": "63.18"
        }
      ],
      "dirasTake": "Urgent: this is listed on CISA’s Known Exploited Vulnerabilities catalog with a short federal remediation deadline, and public exploit code exists, so prioritize applying vendor fixes or mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-8452",
        "https://www.cve.org/CVERecord?id=CVE-2026-8452",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8452",
        "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604"
      ],
      "published": "2026-09-29T16:22:14Z",
      "updated": "2026-09-29T16:22:14Z"
    },
    {
      "id": "CVE-2026-50522",
      "url": "https://labs.diras.sa/cve/cve-2026-50522/",
      "title": "SharePoint deserialization pre-auth remote code execution",
      "vendor": "Microsoft",
      "product": "SharePoint",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.03042,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-22",
        "dueDate": "2026-07-25"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SharePoint Enterprise Server 2016 16.x",
          "affected": "16.0.0 – before 16.0.5561.1001",
          "fixed": "16.0.5561.1001"
        },
        {
          "branch": "Microsoft SharePoint Server 2019 16.x",
          "affected": "16.0.0 – before 16.0.10417.20175",
          "fixed": "16.0.10417.20175"
        },
        {
          "branch": "Microsoft SharePoint Server Subscription Edition 16.x",
          "affected": "16.0.0 – before 16.0.19725.20434",
          "fixed": "16.0.19725.20434"
        }
      ],
      "dirasTake": "Urgent — CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog with a near-term remediation deadline, and public exploit code exists, so prioritize patching or applying vendor mitigations for internet-facing SharePoint deployments.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-50522",
        "https://www.cve.org/CVERecord?id=CVE-2026-50522",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522"
      ],
      "published": "2026-09-29T16:22:01Z",
      "updated": "2026-09-29T16:22:01Z"
    },
    {
      "id": "CVE-2026-56164",
      "url": "https://labs.diras.sa/cve/cve-2026-56164/",
      "title": "SharePoint Server missing authentication allows privilege elevation",
      "vendor": "Microsoft",
      "product": "SharePoint Server",
      "cwe": "CWE-306",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01011,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-14",
        "dueDate": "2026-07-17"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SharePoint Enterprise Server 2016 16.x",
          "affected": "16.0.0 – before 16.0.5561.1001",
          "fixed": "16.0.5561.1001"
        },
        {
          "branch": "Microsoft SharePoint Server 2019 16.x",
          "affected": "16.0.0 – before 16.0.10417.20175",
          "fixed": "16.0.10417.20175"
        },
        {
          "branch": "Microsoft SharePoint Server Subscription Edition 16.x",
          "affected": "16.0.0 – before 16.0.19725.20434",
          "fixed": "16.0.19725.20434"
        }
      ],
      "dirasTake": "Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog, imposing a federal remediation deadline; prioritize applying the vendor fixes or mitigations immediately for internet-facing SharePoint servers.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-56164",
        "https://www.cve.org/CVERecord?id=CVE-2026-56164",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56164",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164"
      ],
      "published": "2026-09-29T16:21:48Z",
      "updated": "2026-09-29T16:21:48Z"
    },
    {
      "id": "CVE-2026-59310",
      "url": "https://labs.diras.sa/cve/cve-2026-59310/",
      "title": "VMware vCenter directory traversal lets network attacker execute code",
      "vendor": "Broadcom",
      "product": "VMware vCenter",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.02565,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-18",
        "dueDate": "2026-08-21"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Cloud Foundation 9.x",
          "affected": "9.1.x.x",
          "fixed": null
        },
        {
          "branch": "Cloud Foundation 9.x",
          "affected": "9.0.x.x",
          "fixed": null
        },
        {
          "branch": "Cloud Foundation 5.x",
          "affected": "5.x",
          "fixed": null
        },
        {
          "branch": "vSphere Foundation 9.x",
          "affected": "9.1.x.x",
          "fixed": null
        },
        {
          "branch": "vSphere Foundation 9.x",
          "affected": "9.0.x.x",
          "fixed": null
        },
        {
          "branch": "vCenter 9.x",
          "affected": "9.1.x.x – before 9.1.0.0300",
          "fixed": "9.1.0.0300"
        },
        {
          "branch": "vCenter 9.x",
          "affected": "9.0.x.x – before 9.0.2.0100",
          "fixed": "9.0.2.0100"
        },
        {
          "branch": "vCenter 8.x",
          "affected": "8.0 – before 8.0 U3k",
          "fixed": "8.0 U3k"
        },
        {
          "branch": "Telco Cloud Infrastructure 3.x",
          "affected": "3.0",
          "fixed": null
        },
        {
          "branch": "Telco Cloud Platform 5.x",
          "affected": "5.1.x",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a fast remediation deadline, so prioritize patching or implementing vendor mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-59310",
        "https://www.cve.org/CVERecord?id=CVE-2026-59310",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310",
        "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017"
      ],
      "published": "2026-09-29T16:21:28Z",
      "updated": "2026-09-29T16:21:28Z"
    },
    {
      "id": "CVE-2026-65400",
      "url": "https://labs.diras.sa/cve/cve-2026-65400/",
      "title": "MacOS Screen Sharing improper authentication lets network attacker bypass credentials",
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01219,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-18",
        "dueDate": "2026-08-21"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "14.x",
          "affected": "before 14.8.9",
          "fixed": "14.8.9"
        },
        {
          "branch": "15.x",
          "affected": "before 15.7.9",
          "fixed": "15.7.9"
        },
        {
          "branch": "26.x",
          "affected": "before 26.6.1",
          "fixed": "26.6.1"
        },
        {
          "branch": "26.x",
          "affected": "before 26.7",
          "fixed": "26.7"
        },
        {
          "branch": "27.x",
          "affected": "before 27",
          "fixed": "27"
        }
      ],
      "dirasTake": "Urgent: CISA added this flaw to the Known Exploited Vulnerabilities catalog with a federal remediation deadline, and public exploit code exists, so prioritize patching or mitigations for internet-facing and high-value macOS hosts immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65400",
        "https://www.cve.org/CVERecord?id=CVE-2026-65400",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400",
        "https://support.apple.com/en-us/148170",
        "https://support.apple.com/en-us/148171",
        "https://support.apple.com/en-us/148172",
        "https://support.apple.com/en-us/149035",
        "https://support.apple.com/en-us/149042"
      ],
      "published": "2026-09-29T16:21:14Z",
      "updated": "2026-09-29T16:21:14Z"
    },
    {
      "id": "CVE-2026-19478",
      "url": "https://labs.diras.sa/cve/cve-2026-19478/",
      "title": "GitLab GraphQL directive lets unauthenticated users modify public projects",
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
      },
      "epss": 0.60204,
      "kev": {
        "listed": false,
        "dateAdded": null,
        "dueDate": null
      },
      "flags": [
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "18.x",
          "affected": "18.2 – before 18.11.11",
          "fixed": "18.11.11"
        },
        {
          "branch": "19.x",
          "affected": "19.0 – before 19.0.8",
          "fixed": "19.0.8"
        },
        {
          "branch": "19.x",
          "affected": "19.1 – before 19.1.6",
          "fixed": "19.1.6"
        },
        {
          "branch": "19.x",
          "affected": "19.2 – before 19.2.4",
          "fixed": "19.2.4"
        }
      ],
      "dirasTake": "Urgent: public exploit code exists, so update immediately to a fixed release listed below or block access to affected instances until patched.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-19478",
        "https://www.cve.org/CVERecord?id=CVE-2026-19478",
        "https://gitlab.com/gitlab-org/gitlab/-/work_items/611377",
        "https://hackerone.com/reports/3926431",
        "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/"
      ],
      "published": "2026-09-29T16:20:05Z",
      "updated": "2026-09-29T16:20:05Z"
    },
    {
      "id": "CVE-2026-18577",
      "url": "https://labs.diras.sa/cve/cve-2026-18577/",
      "title": "N-central authentication bypass that can enable account takeover",
      "vendor": "N-able",
      "product": "N-central",
      "cwe": "CWE-288",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.14622,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-03",
        "dueDate": "2026-08-06"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "2026.x",
          "affected": "2026.3 and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of 2026-08-06, so prioritize mitigation immediately and follow vendor and CISA guidance.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-18577",
        "https://www.cve.org/CVERecord?id=CVE-2026-18577",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577",
        "https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm",
        "https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/",
        "https://www.cve.org/CVERecord?id=CVE-2026-18556"
      ],
      "published": "2026-09-29T16:19:47Z",
      "updated": "2026-09-29T16:19:47Z"
    },
    {
      "id": "CVE-2026-56291",
      "url": "https://labs.diras.sa/cve/cve-2026-56291/",
      "title": "Balbooa Forms unauthenticated file upload remote code execution",
      "vendor": "Balbooa",
      "product": "Forms",
      "cwe": "CWE-434",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.14854,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-10",
        "dueDate": "2026-07-13"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0-2.4.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth remote code execution added to CISA’s Known Exploited Vulnerabilities catalog with a short federal mitigation deadline, so prioritize mitigation or removal of the extension immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-56291",
        "https://www.cve.org/CVERecord?id=CVE-2026-56291",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56291",
        "https://www.balbooa.com/joomla-forms",
        "https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/"
      ],
      "published": "2026-09-29T16:19:34Z",
      "updated": "2026-09-29T16:19:34Z"
    },
    {
      "id": "CVE-2026-9586",
      "url": "https://labs.diras.sa/cve/cve-2026-9586/",
      "title": "Switchvox SQL injection allows unauthenticated remote SQL execution",
      "vendor": "Sangoma",
      "product": "Switchvox",
      "cwe": "CWE-89",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.18979,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-02",
        "dueDate": "2026-09-05"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "8.x",
          "affected": "8.3 (104997) – before 8.4.0.2",
          "fixed": "8.4.0.2"
        }
      ],
      "dirasTake": "Treat this as urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid mitigation due date, and public exploit code is available—apply vendor fixes or mitigations immediately for exposed systems.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-9586",
        "https://www.cve.org/CVERecord?id=CVE-2026-9586",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9586",
        "https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026",
        "https://labs.sra.io/posts/switchvox/"
      ],
      "published": "2026-09-29T16:19:21Z",
      "updated": "2026-09-29T16:19:21Z"
    },
    {
      "id": "CVE-2026-60004",
      "url": "https://labs.diras.sa/cve/cve-2026-60004/",
      "title": "Gitea code injection via diffpatch API remote code execution",
      "vendor": "Gitea",
      "product": "Gitea",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.23988,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-25",
        "dueDate": "2026-08-28"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.17 – before 1.27.1",
          "fixed": "1.27.1"
        }
      ],
      "dirasTake": "Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline, and public exploit code exists, so prioritize updating to 1.27.1 or applying vendor mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-60004",
        "https://www.cve.org/CVERecord?id=CVE-2026-60004",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60004",
        "https://blog.gitea.com/release-of-1.27.1/",
        "https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m",
        "https://www.runzero.com/blog/gitea/",
        "https://github.com/0xBlackash/CVE-2026-60004"
      ],
      "published": "2026-09-29T16:19:09Z",
      "updated": "2026-09-29T16:19:09Z"
    },
    {
      "id": "CVE-2026-82329",
      "url": "https://labs.diras.sa/cve/cve-2026-82329/",
      "title": "Artifactory authentication weakness allows pre-auth admin takeover",
      "vendor": "JFrog",
      "product": "Artifactory",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.14121,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-02",
        "dueDate": "2026-09-05"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "before 7.111.21",
          "fixed": "7.111.21"
        },
        {
          "branch": "7.x",
          "affected": "7.117.0 – before 7.117.28",
          "fixed": "7.117.28"
        },
        {
          "branch": "7.x",
          "affected": "7.125.0 – before 7.125.20",
          "fixed": "7.125.20"
        },
        {
          "branch": "7.x",
          "affected": "7.133.0 – before 7.133.29",
          "fixed": "7.133.29"
        },
        {
          "branch": "7.x",
          "affected": "7.146.0 – before 7.146.38",
          "fixed": "7.146.38"
        },
        {
          "branch": "7.x",
          "affected": "7.161.0 – before 7.161.20",
          "fixed": "7.161.20"
        }
      ],
      "dirasTake": "Urgent: this is a pre-auth administrative takeover added to CISA’s KEV with a short federal remediation deadline, and public exploit code exists — prioritize patching exposed Artifactory instances immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-82329",
        "https://www.cve.org/CVERecord?id=CVE-2026-82329",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82329",
        "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
        "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      ],
      "published": "2026-09-29T16:18:57Z",
      "updated": "2026-09-29T16:18:57Z"
    },
    {
      "id": "CVE-2026-72898",
      "url": "https://labs.diras.sa/cve/cve-2026-72898/",
      "title": "Metabase SQL injection in reset_password allows remote admin takeover",
      "vendor": "Metabase",
      "product": "Metabase",
      "cwe": "CWE-89",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.19048,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-11",
        "dueDate": "2026-08-14"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Metabase",
          "affected": "x.58.0 – before x.58.24",
          "fixed": "x.58.24"
        },
        {
          "branch": "Metabase",
          "affected": "x.59.0 – before x.59.21",
          "fixed": "x.59.21"
        },
        {
          "branch": "Metabase",
          "affected": "x.60.0 – before x.60.17",
          "fixed": "x.60.17"
        },
        {
          "branch": "Metabase",
          "affected": "x.61.0 – before x.61.11",
          "fixed": "x.61.11"
        },
        {
          "branch": "Metabase",
          "affected": "x.62.0 – before x.62.9",
          "fixed": "x.62.9"
        },
        {
          "branch": "Metabase",
          "affected": "x.63.0 – before x.63.5",
          "fixed": "x.63.5"
        }
      ],
      "dirasTake": "Urgent — CISA placed this flaw on its Known Exploited Vulnerabilities list with a required mitigation date, and public exploit code exists, so prioritize patching or blocking access to the reset_password endpoint immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-72898",
        "https://www.cve.org/CVERecord?id=CVE-2026-72898",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72898",
        "https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf",
        "https://www.metabase.com/blog/security-update",
        "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json"
      ],
      "published": "2026-09-29T16:18:45Z",
      "updated": "2026-09-29T16:18:45Z"
    },
    {
      "id": "CVE-2026-15410",
      "url": "https://labs.diras.sa/cve/cve-2026-15410/",
      "title": "SMA1000 Appliances post-auth code injection allows OS command execution",
      "vendor": "SonicWall",
      "product": "SMA1000 Appliances",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 7.2,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.11791,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-14",
        "dueDate": "2026-07-17"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "12.x",
          "affected": "12.4.3-03245 – 12.4.3-03434",
          "fixed": null
        },
        {
          "branch": "12.x",
          "affected": "12.5.0-02283 – 12.5.0-02800",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added CVE-2026-15410 to its Known Exploited Vulnerabilities catalog with a July 17, 2026 mitigation deadline, so prioritize remediation for internet-exposed SMA1000 Appliances immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-15410",
        "https://www.cve.org/CVERecord?id=CVE-2026-15410",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410",
        "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008"
      ],
      "published": "2026-09-29T16:18:30Z",
      "updated": "2026-09-29T16:18:30Z"
    },
    {
      "id": "CVE-2026-20316",
      "url": "https://labs.diras.sa/cve/cve-2026-20316/",
      "title": "Cisco Secure Firewall Management Center hard-coded low-privileged login",
      "vendor": "Cisco",
      "product": "Secure Firewall Management Center (FMC)",
      "cwe": "CWE-259",
      "cvss": {
        "version": "3.1",
        "score": 5.3,
        "severity": "medium",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
      },
      "epss": 0.35096,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-29",
        "dueDate": "2026-08-01"
      },
      "flags": [
        "kev",
        "exploited"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.0.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.1.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.2.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.3",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.2.0.1",
          "fixed": null
        },
        {
          "branch": "7.x",
          "affected": "7.0.4",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a mandatory remediation date, highlighting immediate risk to internet-accessible FMC instances; prioritize mitigations per vendor guidance and CISA instructions.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-20316",
        "https://www.cve.org/CVERecord?id=CVE-2026-20316",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh"
      ],
      "published": "2026-09-29T16:18:16Z",
      "updated": "2026-09-29T16:18:16Z"
    },
    {
      "id": "CVE-2026-63077",
      "url": "https://labs.diras.sa/cve/cve-2026-63077/",
      "title": "TeamCity unauthenticated remote code execution via agent polling",
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.8957,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-05",
        "dueDate": "2026-08-08"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "2026.x",
          "affected": "before 2026.1.3, 2025.11.7",
          "fixed": "2026.1.3, 2025.11.7"
        }
      ],
      "dirasTake": "Urgent: this flaw was added to CISA’s Known Exploited Vulnerabilities catalog (KEV) with a short federal remediation deadline, indicating high real-world risk; prioritize deploying vendor fixes or isolating TeamCity from untrusted networks immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-63077",
        "https://www.cve.org/CVERecord?id=CVE-2026-63077",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63077",
        "https://www.jetbrains.com/privacy-security/issues-fixed/"
      ],
      "published": "2026-09-29T16:18:03Z",
      "updated": "2026-09-29T16:18:03Z"
    },
    {
      "id": "CVE-2026-73570",
      "url": "https://labs.diras.sa/cve/cve-2026-73570/",
      "title": "Zimbra Collaboration Suite OS command injection via SMTP/SNMP",
      "vendor": "Synacor",
      "product": "Zimbra Collaboration Suite (ZCS)",
      "cwe": "CWE-78",
      "cvss": {
        "version": "3.1",
        "score": 8.9,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L"
      },
      "epss": 0.11736,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-21",
        "dueDate": "2026-08-24"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "10.x",
          "affected": "before 10.1.20",
          "fixed": "10.1.20"
        }
      ],
      "dirasTake": "Urgent — CISA placed this flaw on its Known Exploited Vulnerabilities list with a short remediation window, so prioritize applying Synacor’s update or temporary mitigations on exposed Zimbra servers now.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-73570",
        "https://www.cve.org/CVERecord?id=CVE-2026-73570",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570",
        "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories",
        "https://wiki.zimbra.com/wiki/Security_Center"
      ],
      "published": "2026-09-29T16:17:51Z",
      "updated": "2026-09-29T16:17:51Z"
    },
    {
      "id": "CVE-2026-55040",
      "url": "https://labs.diras.sa/cve/cve-2026-55040/",
      "title": "SharePoint weak authentication pre-auth bypass vulnerability",
      "vendor": "Microsoft",
      "product": "SharePoint",
      "cwe": "CWE-1390",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.17535,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-18",
        "dueDate": "2026-08-21"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SharePoint Enterprise Server 2016 16.x",
          "affected": "16.0.0 – before 16.0.5561.1001",
          "fixed": "16.0.5561.1001"
        },
        {
          "branch": "Microsoft SharePoint Server 2019 16.x",
          "affected": "16.0.0 – before 16.0.10417.20175",
          "fixed": "16.0.10417.20175"
        },
        {
          "branch": "Microsoft SharePoint Server Subscription Edition 16.x",
          "affected": "16.0.0 – before 16.0.19725.20434",
          "fixed": "16.0.19725.20434"
        }
      ],
      "dirasTake": "Urgent: CISA placed this vulnerability on the Known Exploited Vulnerabilities catalog with an August 21, 2026 remediation requirement, so prioritize applying vendor fixes or mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-55040",
        "https://www.cve.org/CVERecord?id=CVE-2026-55040",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040"
      ],
      "published": "2026-09-29T16:17:34Z",
      "updated": "2026-09-29T16:17:34Z"
    },
    {
      "id": "CVE-2026-58644",
      "url": "https://labs.diras.sa/cve/cve-2026-58644/",
      "title": "SharePoint deserialization remote code execution",
      "vendor": "Microsoft",
      "product": "SharePoint",
      "cwe": "CWE-502",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.15873,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-16",
        "dueDate": "2026-07-19"
      },
      "flags": [
        "kev",
        "exploited",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SharePoint Enterprise Server 2016 16.x",
          "affected": "16.0.0 – before 16.0.5556.1005",
          "fixed": "16.0.5556.1005"
        },
        {
          "branch": "Microsoft SharePoint Server 2019 16.x",
          "affected": "16.0.0 – before 16.0.10417.20153",
          "fixed": "16.0.10417.20153"
        },
        {
          "branch": "Microsoft SharePoint Server Subscription Edition 16.x",
          "affected": "16.0.0 – before 16.0.19725.20384",
          "fixed": "16.0.19725.20384"
        }
      ],
      "dirasTake": "Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid fix deadline, and the flaw allows unauthenticated remote code execution over the network; apply vendor updates immediately or isolate affected systems.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-58644",
        "https://www.cve.org/CVERecord?id=CVE-2026-58644",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58644",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644"
      ],
      "published": "2026-09-29T16:17:22Z",
      "updated": "2026-09-29T16:17:22Z"
    },
    {
      "id": "CVE-2026-9198",
      "url": "https://labs.diras.sa/cve/cve-2026-9198/",
      "title": "Langflow unauthenticated remote code execution",
      "vendor": "IBM",
      "product": "Langflow",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.28658,
      "kev": {
        "listed": true,
        "dateAdded": "2026-08-04",
        "dueDate": "2026-08-07"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "1.x",
          "affected": "1.0.0 – 1.10.0",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent — CISA added this CVE to the Known Exploited Vulnerabilities catalog with a federal remediation due date, and public exploit code exists; apply the vendor’s mitigations or patches and restrict internet exposure immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-9198",
        "https://www.cve.org/CVERecord?id=CVE-2026-9198",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198",
        "https://www.ibm.com/support/pages/node/7278927"
      ],
      "published": "2026-09-29T16:17:09Z",
      "updated": "2026-09-29T16:17:09Z"
    },
    {
      "id": "CVE-2026-63030",
      "url": "https://labs.diras.sa/cve/cve-2026-63030/",
      "title": "WordPress Core REST API route confusion remote code execution",
      "vendor": "WordPress",
      "product": "Core",
      "cwe": "CWE-436",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.10119,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-21",
        "dueDate": "2026-07-24"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "6.x",
          "affected": "6.9.0 – before 6.9.5",
          "fixed": "6.9.5"
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – before 7.0.2",
          "fixed": "7.0.2"
        }
      ],
      "dirasTake": "Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a July 24, 2026 remediation deadline, and public exploit code exists — prioritize immediate mitigation or upgrade.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-63030",
        "https://www.cve.org/CVERecord?id=CVE-2026-63030",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030",
        "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q",
        "https://wordpress.org/news/2026/07/wordpress-7-0-2-release/"
      ],
      "published": "2026-09-29T16:16:59Z",
      "updated": "2026-09-29T16:16:59Z"
    },
    {
      "id": "CVE-2026-16232",
      "url": "https://labs.diras.sa/cve/cve-2026-16232/",
      "title": "SmartConsole authentication bypass allows full admin takeover",
      "vendor": "Check Point",
      "product": "SmartConsole",
      "cwe": "CWE-287",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.77972,
      "kev": {
        "listed": true,
        "dateAdded": "2026-07-22",
        "dueDate": "2026-07-25"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "Quantum Security Management",
          "affected": "R82.10 with Jumbo Hotfix Take 36 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R82 with Jumbo Hotfix Take 118 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R81.20 with Jumbo Hotfix Take 158 or below",
          "fixed": null
        },
        {
          "branch": "Quantum Security Management",
          "affected": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30",
          "fixed": null
        },
        {
          "branch": "Multi-Domain Security Management",
          "affected": "R82.10 with Jumbo Hotfix Take 36 or below",
          "fixed": null
        },
        {
          "branch": "Multi-Domain Security Management",
          "affected": "R82 with Jumbo Hotfix Take 118 or below",
          "fixed": null
        },
        {
          "branch": "Multi-Domain Security Management",
          "affected": "R81.20 with Jumbo Hotfix Take 158 or below",
          "fixed": null
        },
        {
          "branch": "Multi-Domain Security Management",
          "affected": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: this vulnerability is high risk and is on CISA’s Known Exploited Vulnerabilities list with a short remediation window; immediately restrict or isolate affected management interfaces and apply vendor instructions at once.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-16232",
        "https://www.cve.org/CVERecord?id=CVE-2026-16232",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232",
        "https://support.checkpoint.com/results/sk/sk185169"
      ],
      "published": "2026-09-29T16:16:42Z",
      "updated": "2026-09-29T16:16:42Z"
    },
    {
      "id": "CVE-2026-71362",
      "url": "https://labs.diras.sa/cve/cve-2026-71362/",
      "title": "Adobe Commerce and Magento incorrect authorization pre-auth privilege escalation",
      "vendor": "Adobe",
      "product": "Commerce and Magento",
      "cwe": "CWE-863",
      "cvss": {
        "version": "3.1",
        "score": 9.1,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
      },
      "epss": 0.87507,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-24",
        "dueDate": "2026-09-27"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "Adobe Commerce 2.x",
          "affected": "2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug and earlier",
          "fixed": null
        },
        {
          "branch": "Adobe Commerce B2B 1.x",
          "affected": "1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul and earlier",
          "fixed": null
        },
        {
          "branch": "Magento Open Source 2.x",
          "affected": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a September 27, 2026 remediation deadline, making rapid action imperative; treat internet-facing Adobe Commerce and Magento instances as high priority.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-71362",
        "https://www.cve.org/CVERecord?id=CVE-2026-71362",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-71362",
        "https://helpx.adobe.com/security/products/magento/apsb26-92.html"
      ],
      "published": "2026-09-29T16:16:21Z",
      "updated": "2026-09-29T16:16:21Z"
    },
    {
      "id": "CVE-2026-94127",
      "url": "https://labs.diras.sa/cve/cve-2026-94127/",
      "title": "BIG-IP APM heap buffer overflow remote code execution",
      "vendor": "F5",
      "product": "BIG-IP APM",
      "cwe": "CWE-122",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.02226,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-22",
        "dueDate": "2026-09-25"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "BIG-IP",
          "affected": "21.1.0 – before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG",
          "fixed": "Hotfix-BIGIP-21.1.0.2.0.30.22-ENG"
        },
        {
          "branch": "BIG-IP",
          "affected": "17.5.0 – before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG",
          "fixed": "Hotfix-BIGIP-17.5.1.9.0.160.12-ENG"
        },
        {
          "branch": "BIG-IP",
          "affected": "17.1.0 – before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG",
          "fixed": "Hotfix-BIGIP-17.1.3.5.0.41.14-ENG"
        }
      ],
      "dirasTake": "Urgent: CISA added this issue to its Known Exploited Vulnerabilities list with a fast remediation deadline, and public exploit code exists — prioritize patching or mitigation for internet-facing BIG-IP APM instances configured as OAuth Authorization Servers.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-94127",
        "https://www.cve.org/CVERecord?id=CVE-2026-94127",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127",
        "https://my.f5.com/manage/s/article/K000162605"
      ],
      "published": "2026-09-29T14:49:02Z",
      "updated": "2026-09-29T14:49:02Z"
    },
    {
      "id": "CVE-2026-83548",
      "url": "https://labs.diras.sa/cve/cve-2026-83548/",
      "title": "SMA1000 Appliances pre-auth server-side request forgery (SSRF)",
      "vendor": "SonicWall",
      "product": "SMA1000 Appliances",
      "cwe": "CWE-918",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.08757,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-02",
        "dueDate": "2026-09-05"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "12.x",
          "affected": "12.4.3-03453 (platform-hotfix) and older versions",
          "fixed": null
        },
        {
          "branch": "12.x",
          "affected": "12.5.0-02835 (platform-hotfix) and older versions",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent—CISA added CVE-2026-83548 to its Known Exploited Vulnerabilities catalog with a near-term remediation deadline, so prioritize applying vendor mitigations immediately and isolate exposed SMA1000 devices.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-83548",
        "https://www.cve.org/CVERecord?id=CVE-2026-83548",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548",
        "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016"
      ],
      "published": "2026-09-29T14:48:48Z",
      "updated": "2026-09-29T14:48:48Z"
    },
    {
      "id": "CVE-2026-76460",
      "url": "https://labs.diras.sa/cve/cve-2026-76460/",
      "title": "Cisco Identity Services Engine API authentication bypass",
      "vendor": "Cisco",
      "product": "Identity Services Engine",
      "cwe": "CWE-648",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.14026,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-16",
        "dueDate": "2026-09-19"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p8",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p9",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.3 Patch 2",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.3 Patch 1",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.3 Patch 3",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.4.0",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.2.0 p7",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.3 Patch 4",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.4 Patch 1",
          "fixed": null
        },
        {
          "branch": "Cisco Identity Services Engine Software 3.x",
          "affected": "3.1.0 p10",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a short remediation deadline, and public exploit code exists, so prioritize mitigations or take affected ISE instances offline if they are internet-exposed.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-76460",
        "https://www.cve.org/CVERecord?id=CVE-2026-76460",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460",
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5"
      ],
      "published": "2026-09-29T14:48:34Z",
      "updated": "2026-09-29T14:48:34Z"
    },
    {
      "id": "CVE-2026-75650",
      "url": "https://labs.diras.sa/cve/cve-2026-75650/",
      "title": "Adobe Commerce and Magento remote code execution via template engine",
      "vendor": "Adobe",
      "product": "Commerce and Magento",
      "cwe": "CWE-1336",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "epss": 0.03949,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-08",
        "dueDate": "2026-09-11"
      },
      "flags": [
        "kev",
        "exploited",
        "poc"
      ],
      "affected": [
        {
          "branch": "Adobe Commerce 2.x",
          "affected": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug and earlier",
          "fixed": null
        },
        {
          "branch": "Adobe Commerce B2B 1.x",
          "affected": "1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug and earlier",
          "fixed": null
        },
        {
          "branch": "Magento Open Source 2.x",
          "affected": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug and earlier",
          "fixed": null
        }
      ],
      "dirasTake": "Urgent: CISA placed CVE-2026-75650 on its Known Exploited Vulnerabilities catalog with a rapid remediation due date, and exploit code is publicly available, so prioritize mitigation or removal of internet exposure immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-75650",
        "https://www.cve.org/CVERecord?id=CVE-2026-75650",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650",
        "https://helpx.adobe.com/security/products/magento/apsb26-146.html"
      ],
      "published": "2026-09-29T14:48:13Z",
      "updated": "2026-09-29T14:48:13Z"
    },
    {
      "id": "CVE-2026-85706",
      "url": "https://labs.diras.sa/cve/cve-2026-85706/",
      "title": "GitLab repository commits API path traversal lets unauthenticated read files",
      "vendor": "GitLab",
      "product": "Community Edition and Enterprise Edition",
      "cwe": "CWE-22",
      "cvss": {
        "version": "3.1",
        "score": 10,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
      },
      "epss": 0.91425,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-11",
        "dueDate": "2026-09-14"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "18.x",
          "affected": "18.7 – before 18.11.12",
          "fixed": "18.11.12"
        },
        {
          "branch": "19.x",
          "affected": "19.0 – before 19.0.9",
          "fixed": "19.0.9"
        },
        {
          "branch": "19.x",
          "affected": "19.1 – before 19.1.8",
          "fixed": "19.1.8"
        },
        {
          "branch": "19.x",
          "affected": "19.2 – before 19.2.6",
          "fixed": "19.2.6"
        },
        {
          "branch": "19.x",
          "affected": "19.3 – before 19.3.2",
          "fixed": "19.3.2"
        }
      ],
      "dirasTake": "Urgent — CISA listed this vulnerability in the Known Exploited Vulnerabilities catalog with a firm remediation timeline, so immediately apply vendor fixes or compensating controls for internet-facing GitLab servers.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85706",
        "https://www.cve.org/CVERecord?id=CVE-2026-85706",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706",
        "https://gitlab.com/gitlab-org/gitlab/-/work_items/627748",
        "https://hackerone.com/reports/3909881"
      ],
      "published": "2026-09-29T14:47:59Z",
      "updated": "2026-09-29T14:47:59Z"
    },
    {
      "id": "CVE-2026-87902",
      "url": "https://labs.diras.sa/cve/cve-2026-87902/",
      "title": "Remote file inclusion via page-template resolution (get_page_template)",
      "vendor": "WordPress",
      "product": "Core",
      "cwe": "CWE-98",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.19756,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-25",
        "dueDate": "2026-09-28"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "before 7.1.2",
          "fixed": "7.1.2"
        }
      ],
      "dirasTake": "Prioritize immediate action: this is a high-severity RCE with public exploit code and a CISA listing. Patch or apply mitigations without delay.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-87902",
        "https://www.cve.org/CVERecord?id=CVE-2026-87902",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902",
        "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp"
      ],
      "published": "2026-09-29T09:28:33Z",
      "updated": "2026-09-29T14:49:03Z"
    },
    {
      "id": "CVE-2026-65660",
      "url": "https://labs.diras.sa/cve/cve-2026-65660/",
      "title": "code injection in SharePoint server allowing remote code execution",
      "vendor": "Microsoft",
      "product": "SharePoint",
      "cwe": "CWE-94",
      "cvss": {
        "version": "3.1",
        "score": 8.8,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
      },
      "epss": 0.02101,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-25",
        "dueDate": "2026-09-28"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "Microsoft SharePoint Enterprise Server 2016 16.x",
          "affected": "16.0.0 – before 16.0.5565.1001",
          "fixed": "16.0.5565.1001"
        },
        {
          "branch": "Microsoft SharePoint Server 2019 16.x",
          "affected": "16.0.0 – before 16.0.10417.20198",
          "fixed": "16.0.10417.20198"
        },
        {
          "branch": "Microsoft SharePoint Server Subscription Edition 16.x",
          "affected": "16.0.0 – before 16.0.19725.20522",
          "fixed": "16.0.19725.20522"
        }
      ],
      "dirasTake": "Act urgently: this is a high-severity, network-exploitable code-injection flaw with public exploit code and CISA listing. Prioritize patching exposed SharePoint servers or apply vendor mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-65660",
        "https://www.cve.org/CVERecord?id=CVE-2026-65660",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660",
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660"
      ],
      "published": "2026-09-29T09:28:16Z",
      "updated": "2026-09-29T14:49:03Z"
    },
    {
      "id": "CVE-2026-67279",
      "url": "https://labs.diras.sa/cve/cve-2026-67279/",
      "title": "Improper workflow enforcement in RouterOS SSH allows unauthenticated file writes",
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-841",
      "cvss": {
        "version": "3.1",
        "score": 6.5,
        "severity": "medium",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
      },
      "epss": 0.01027,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-25",
        "dueDate": "2026-09-28"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "7.x",
          "affected": "7.24 – before 7.24.2",
          "fixed": "7.24.2"
        },
        {
          "branch": "7.x",
          "affected": "7.0.0 – before 7.23.4",
          "fixed": "7.23.4"
        },
        {
          "branch": "6.x",
          "affected": "6.0.0 – before 6.49.21",
          "fixed": "6.49.21"
        }
      ],
      "dirasTake": "Act urgently: vendor fixes are available and the issue is listed by CISA as exploited in the wild, and public exploit code exists. Patch exposed systems or apply compensating controls immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-67279",
        "https://www.cve.org/CVERecord?id=CVE-2026-67279",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67279",
        "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
        "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
        "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/",
        "https://mikrotik.com/supportsec/september-2026-vulnerability/",
        "https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802",
        "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
        "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800"
      ],
      "published": "2026-09-29T09:28:06Z",
      "updated": "2026-09-29T14:49:03Z"
    },
    {
      "id": "CVE-2026-88771",
      "url": "https://labs.diras.sa/cve/cve-2026-88771/",
      "title": "Improper input validation in NetScaler ADC and Gateway allowing remote command execution",
      "vendor": "Citrix",
      "product": "NetScaler",
      "cwe": "CWE-20",
      "cvss": {
        "version": "3.1",
        "score": 9.8,
        "severity": "critical",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01063,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-27",
        "dueDate": "2026-09-30"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        },
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37 FIPS",
          "fixed": "14.1-73.37 FIPS"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1.37.279 FIPS and NDcPP",
          "fixed": "13.1.37.279 FIPS and NDcPP"
        },
        {
          "branch": "Gateway 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "Gateway 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        }
      ],
      "dirasTake": "Act immediately. The issue is critical (CVSS 9.8), public exploit code exists, and vendor updates are available for the affected releases.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-88771",
        "https://www.cve.org/CVERecord?id=CVE-2026-88771",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771",
        "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
      ],
      "published": "2026-09-29T09:27:53Z",
      "updated": "2026-09-29T14:49:03Z"
    },
    {
      "id": "CVE-2026-88772",
      "url": "https://labs.diras.sa/cve/cve-2026-88772/",
      "title": "stack-based memory buffer flaw in NetScaler ADC and Gateway",
      "vendor": "Citrix",
      "product": "NetScaler",
      "cwe": "CWE-119",
      "cvss": {
        "version": "3.1",
        "score": 8.1,
        "severity": "high",
        "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "epss": 0.01301,
      "kev": {
        "listed": true,
        "dateAdded": "2026-09-27",
        "dueDate": "2026-09-30"
      },
      "flags": [
        "kev",
        "exploited",
        "poc",
        "patch"
      ],
      "affected": [
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        },
        {
          "branch": "ADC 14.x",
          "affected": "before 14.1-73.37 FIPS",
          "fixed": "14.1-73.37 FIPS"
        },
        {
          "branch": "ADC 13.x",
          "affected": "before 13.1.37.279 FIPS and NDcPP",
          "fixed": "13.1.37.279 FIPS and NDcPP"
        },
        {
          "branch": "Gateway 14.x",
          "affected": "before 14.1-73.37",
          "fixed": "14.1-73.37"
        },
        {
          "branch": "Gateway 13.x",
          "affected": "before 13.1-64.23",
          "fixed": "13.1-64.23"
        }
      ],
      "dirasTake": "Act urgently: the vulnerability enables remote code execution and has public exploit code, and a CISA listing indicates active concern. Prioritise patching exposed appliances or applying vendor mitigations immediately.",
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-88772",
        "https://www.cve.org/CVERecord?id=CVE-2026-88772",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772",
        "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
      ],
      "published": "2026-09-29T09:27:35Z",
      "updated": "2026-09-29T14:49:03Z"
    }
  ]
}
