ELEVATED 12 min read 4 Sep 2026

Critical Elementor Pro flaw exploited to take over WordPress sites Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-32475, cwe-434, cve-2026-78012, cwe-121, cve-2026-84323, cve-2026-84325, cve-2026-84326, cve-2026-84327, cve-2026-84329, cve-2026-84332

Key findings
01
Critical Elementor Pro flaw exploited to take over WordPress sites
CRITICAL
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.
02
Pyramid Solutions NetStaX EtherNet/IP Stack
CRITICAL
Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The assigned identifier is CVE-2026-78012.
03
Multiple vulnerabilities in Chromium
CRITICAL
CVE coverage: CVE-2026-84323, CVE-2026-84325, CVE-2026-84326, CVE-2026-84327, CVE-2026-84329, CVE-2026-84332, CVE-2026-84354, CVE-2026-84358, CVE-2026-84324, CVE-2026-84328, CVE-2026-84331, CVE-2026-84334, CVE-2026-84335, CVE-2026-84347, CVE-2026-84348, CVE-2026-84349, CVE-2026-84350, CVE-2026-84351, CVE-2026-84353, CVE-2026-84355, CVE-2026-84356, CVE-2026-84357, CVE-2026-84359.
04
Multiple vulnerabilities in SiYuan
CRITICAL
CVE coverage: CVE-2026-68585, CVE-2026-68586, CVE-2026-68587, CVE-2026-69083, CVE-2026-69086, CVE-2026-69084, CVE-2026-72800, CVE-2026-72801, CVE-2026-72802, CVE-2026-72803, CVE-2026-72804, CVE-2026-72805, CVE-2026-72806, CVE-2026-72807, CVE-2026-72808, CVE-2026-72809, CVE-2026-72810, CVE-2026-72811, CVE-2026-72812.
05
Multiple vulnerabilities in Orval
CRITICAL
CVE coverage: CVE-2026-62681, CVE-2026-62682, CVE-2026-72717, CVE-2026-71869, CVE-2026-71871, CVE-2026-71867, CVE-2026-71868, CVE-2026-71865, CVE-2026-71864.
06
Azure AI Language Elevation of Privilege Vulnerability
CRITICAL
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. The cited source identifies the affected product and the available advisory or remediation status. The assigned identifier is CVE-2026-70352.
07
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
CRITICAL
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. The cited source identifies the affected product and the available advisory or remediation status. The assigned identifier is CVE-2026-83711.
08
Microsoft Entra ID Elevation of Privilege Vulnerability
CRITICAL
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. The cited source identifies the affected product and the available advisory or remediation status. The assigned identifier is CVE-2026-62916.
09
Copilot Studio Elevation of Privilege Vulnerability
CRITICAL
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. The cited source identifies the affected product and the available advisory or remediation status. The assigned identifier is CVE-2026-80098.
10
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
HIGH
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody. The cited source identifies the affected product and the available advisory or remediation status. The assigned identifier is CVE-2025-13845.
11
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop.
HIGH
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop. CVE coverage: CVE-2026-82397.
12
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
HIGH
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The cited source identifies the affected product and the available advisory or remediation status.
13
The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input.
HIGH
The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax. The assigned identifier is CVE-2025-12107.
14
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
HIGH
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-73293.
15
Multiple vulnerabilities in Rockwell Automation
HIGH
CVE coverage: CVE-2025-10478, CVE-2026-12663, CVE-2026-19471, CVE-2026-19472. The cited advisories disclose: 1756-ENBT Module; ControlFLASH; ArmorStart LT.

Executive assessment

Today's brief leads with Critical Elementor Pro flaw exploited to take over WordPress sites. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — Critical Elementor Pro flaw exploited to take over WordPress sites

What changed: A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...] The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-32475; CVSS v3.1 9; weakness CWE-434; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If patching cannot be completed immediately, enable Wordfence Firewall's built-in Malicious File Upload protection and 'Disable Code Execution for Uploads directory' option; inspect /wp-content/uploads/elementor/forms/ for PHP files and monitor POST requests to /wp-admin/admin-ajax.php with action=elementor_pro_forms_send_form. Wordfence reports active exploitation and more than 190,000 blocked attempts since 19 August 2026, and a working public PoC is available. ([wordfence.com](https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/), [github.com](https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE))

Action: Map CVE-2026-32475 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/)

Finding 02 — Pyramid Solutions NetStaX EtherNet/IP Stack

What changed: Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

Technical evidence: CVE-2026-78012; CVSS v3.1 9.8; weakness CWE-121; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If patching is not immediately possible, minimise network exposure, deny internet access, firewall and isolate control networks from business networks, and monitor for Class 3 explicit-message payloads larger than the application’s MAX_REQUEST_DATA_SIZE. CISA reports no known public exploitation specifically targeting CVE-2026-78012; neither the CISA advisory nor Pyramid Solutions’ disclosure identifies a public PoC. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07), [pyramidsolutions.com](https://pyramidsolutions.com/netstax-v-5-6-1-protecting-against-silent-buffer-overflow-in-ethernet-ip-stack-explicit-messages/))

Action: Map CVE-2026-78012 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07)

Finding 03 — Multiple vulnerabilities in Chromium

What changed: CVE coverage: CVE-2026-84323, CVE-2026-84325, CVE-2026-84326, CVE-2026-84327, CVE-2026-84329, CVE-2026-84332, CVE-2026-84354, CVE-2026-84358, CVE-2026-84324, CVE-2026-84328, CVE-2026-84331, CVE-2026-84334, CVE-2026-84335, CVE-2026-84347, CVE-2026-84348, CVE-2026-84349, CVE-2026-84350, CVE-2026-84351, CVE-2026-84353, CVE-2026-84355, CVE-2026-84356, CVE-2026-84357, CVE-2026-84359. The cited advisories disclose: Missing authorization in FileSystem; Improper input validation in DataTransfer; Uninitialized resource in V8; Incorrect authorization in Autofill; Confused deputy in CredentialProvider; Incorrect authorization in SiteSettings; Incorrect authorization in FileSystem; Improper privilege management in Downloads; Use after free in Proxy; Missing authorization in FileSystem; Incorrect authorization in Actor; Incorrect authorization in Chromoting; Incorrect authorization in TabStrip; Use after free in WebRTC; Information leak in MediaCapture; Use after free in Browser; Use after free in TabStrip; Buffer overflow in GPU; Use after free in Shared Tab Groups; Incorrect authorization in Navigation; UI misrepresentation in FullScreen; Improper input validation in Omnibox; Information leak in Skia.

Technical evidence: CVE-2026-84325; CVSS v3.1 9.8; weakness CWE-20; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Until patching, block JavaScript and access to unapproved or known-malicious websites, run browsers as non-administrative users, and enable endpoint anti-exploitation protections. MS-ISAC reports no known exploitation in the wild. Chrome versions before 152.0.7977.75/.76 on Windows and macOS and before 152.0.7977.75 on Linux are affected; Microsoft Edge is fixed in 152.0.4191.62. ([cisecurity.org](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-085), [msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84323))

Action: Map CVE-2026-84325 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: affected product not structured

[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84323)

Finding 04 — Multiple vulnerabilities in SiYuan

What changed: CVE coverage: CVE-2026-68585, CVE-2026-68586, CVE-2026-68587, CVE-2026-69083, CVE-2026-69086, CVE-2026-69084, CVE-2026-72800, CVE-2026-72801, CVE-2026-72802, CVE-2026-72803, CVE-2026-72804, CVE-2026-72805, CVE-2026-72806, CVE-2026-72807, CVE-2026-72808, CVE-2026-72809, CVE-2026-72810, CVE-2026-72811, CVE-2026-72812. The cited advisories disclose: Cross-boundary metadata disclosure via getBlockInfo : reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered; Full-content disclosure of publish-disabled documents via getHeadingTransaction endpoints : reader-reachable rendered DOM with no publish-access check; Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent : reader-reachable raw SQL and unescaped REGEXP on read-write asset-content DB; Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure; Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles; Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking; Absolute filesystem path and OS username disclosure via resolveAssetPath; Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes of protected documents; Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents; Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents; Password tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password; Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents; Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy; Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents; SQL injection in backlink/mention search via unescaped stored and client input : first-order and second-order breakout on read-write handle; Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification.

Technical evidence: CVE-2026-68586; CVSS v4.0 9.2; weakness CWE-862; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: If patching is impossible, restrict the SiYuan kernel and Publish service to trusted clients, disable anonymous Publish access, and do not import untrusted SiYuan documents or packages. ([ionix.io](https://www.ionix.io/threat-center/cve-2026-68587/), [ionix.io](https://www.ionix.io/threat-center/cve-2026-69084/), [github.com](https://github.com/siyuan-note/siyuan/security/advisories/GHSA-x67c-8pwr-m8g3), +19 more)

Action: Map CVE-2026-68586 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](https://github.com/advisories/GHSA-pm3w-vxp9-ccwc)

Finding 05 — Multiple vulnerabilities in Orval

What changed: CVE coverage: CVE-2026-62681, CVE-2026-62682, CVE-2026-72717, CVE-2026-71869, CVE-2026-71871, CVE-2026-71867, CVE-2026-71868, CVE-2026-71865, CVE-2026-71864. The cited advisories disclose: Import-time RCE via schema default -> zod module-level template literal; Import-time RCE via array-items default -> zod module-level template literal; Import-time RCE via header-parameter default -> zod module-level template literal; RCE via schema property name -> computed-property-key injection in the MSW mock generator; Import-time RCE via enum-typed default -> zod module-level template literal; Import-time RCE via query parameter name -> computed-property-key injection in the zod cli; Import-time RCE via header parameter name -> computed-property-key injection in the zod client.

Technical evidence: CVE-2026-62681; CVSS v4.0 9.3; weakness CWE-94, CWE-116, CWE-1336; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-62681 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](https://github.com/advisories/GHSA-fg9p-mrxr-hvq7)

Finding 06 — Azure AI Language Elevation of Privilege Vulnerability

What changed: Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-70352; CVSS v3.1 10; weakness CWE-306; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-70352 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70352)

Finding 07 — Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability

What changed: Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-83711; CVSS v3.1 10; weakness CWE-639; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-83711 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83711)

Finding 08 — Microsoft Entra ID Elevation of Privilege Vulnerability

What changed: Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-62916; CVSS v3.1 9.1; weakness CWE-288; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-62916 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62916)

Finding 09 — Copilot Studio Elevation of Privilege Vulnerability

What changed: Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-80098; CVSS v3.1 9.3; weakness CWE-347; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-80098 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80098)

Finding 10 — CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

What changed: CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody. The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2025-13845; CVSS v4.0 8.4; weakness CWE-416; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If patching is not possible, only open Rapsody projects from trusted sources and malware-scan every externally created SSD project before opening it. No in-the-wild exploitation is reported on the retrieved Schneider Electric, CISA or ZDI pages; GitHub lists no known source code. ([download.schneider-electric.com](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-013-04.pdf), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-10), [zerodayinitiative.com](https://www.zerodayinitiative.com/advisories/ZDI-26-094/), +1 more)

Action: Map CVE-2025-13845 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-13845)

Finding 11 — Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop.

What changed: Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop. CVE coverage: CVE-2026-82397.

Technical evidence: CVE-2026-82397; CVSS v3.1 7.5; weakness CWE-400, CWE-1284; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If patching is delayed, block application/x-www-form-urlencoded requests where they are unnecessary; otherwise impose a reduced max_body_size and monitor for large form bodies dominated by separators. Tenable reports that no known exploits are available, and CVE-2026-82397 is absent from CISA's current Known Exploited Vulnerabilities catalogue. Tornado versions earlier than 6.5.8 are affected, and 6.5.8 contains the fix. ([github.com](https://github.com/tornadoweb/tornado/security/advisories/GHSA-mpf4-983q-p7j4), [tornadoweb.org](https://www.tornadoweb.org/en/stable/httpserver.html), [tenable.com](https://www.tenable.com/plugins/nessus/342168), +1 more)

Action: Map CVE-2026-82397 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](https://github.com/advisories/GHSA-mpf4-983q-p7j4)

Finding 12 — Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

What changed: The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-19949; CVSS v3.1 8.8; weakness CWE-89; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-19949 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: securityweek.com](https://www.securityweek.com/over-3-million-wordpress-sites-affected-by-migration-plugin-vulnerability/)

Finding 13 — The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input.

What changed: The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax.

Technical evidence: CVE-2025-12107; CVSS v3.1 8.4; weakness CWE-77, CWE-94; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: If patching is delayed, restrict the WSO2 Identity Server administrative console to a dedicated management network with strict IP allowlisting, deploy WAF rules for server-side template injection, and monitor administrative requests for Velocity syntax and the WSO2 Java process for unexpected child processes or network connections. GitHub’s advisory lists no known source code. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2025-12107/), [github.com](https://github.com/advisories/GHSA-8v9w-wqxw-hp8g), [security.docs.wso2.com](https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4517/), +1 more)

Action: Map CVE-2025-12107 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-12107)

Finding 14 — Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

What changed: Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-73293.

Technical evidence: CVE-2026-73293; CVSS v3.1 8.8; weakness CWE-269; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If patching is delayed, block POST /api/project//roles for non-owner accounts, alert on successful requests to that endpoint, and remove custom roles whose slugs match owner, manager, task_runner or guest. A public proof of concept reproducing the escalation request is available; no in-the-wild exploitation was identified in the retrieved sources. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-73293/), [turingpoint.de](https://turingpoint.de/en/advisories/tp-2026-042/), [osv.dev](https://osv.dev/vulnerability/CVE-2026-73293))

Action: Map CVE-2026-73293 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](https://github.com/advisories/GHSA-cxvf-gvfq-36w2)

Finding 15 — Multiple vulnerabilities in Rockwell Automation

What changed: CVE coverage: CVE-2025-10478, CVE-2026-12663, CVE-2026-19471, CVE-2026-19472. The cited advisories disclose: 1756-ENBT Module; ControlFLASH; ArmorStart LT.

Technical evidence: CVE-2026-12663; CVSS v4.0 7; weakness CWE-306; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: If patching is not immediately possible, remove the 'Everyone' group from permissions on C:\Program Files (x86)\ControlFLASH\0001; keep the networked modules off the internet, behind firewalls and isolated from business networks, using an up-to-date VPN where remote access is required. CISA reports no known public exploitation targeting any of these vulnerabilities. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05), +2 more)

Action: Map CVE-2026-12663 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05)

cve-2025-10478cve-2025-12107cve-2025-13845cve-2026-19949cve-2026-32475cve-2026-62681cve-2026-62916cve-2026-68585cve-2026-70352cve-2026-73293

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.