Executive assessment
Today's brief leads with SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 02 should lead today because it is critical, enables unauthorised file transfer and execution, and has in-the-wild exploitation. The SAP kernel flaw is CVSS 10.0 unauthenticated remote code execution, but the listing says no exploitation is reported. Themes: In-the-wild exploitation; Remote code and file execution; Edge and remote-access exposure. Patch order: Finding 02 (Critical unauthorised file transfer and execution is being exploited in the wild, with ScreenConnect 26.6.5 listed as fixed); Finding 05 (Critical Kemp LoadMaster remote code execution is being exploited in the wild, with fixed GA and LTSF releases listed); Finding 06 (High-severity Windows heap-based buffer overflow is being exploited in the wild, with fixed Windows builds listed); Finding 07 (High-severity Chrome zero-day is being exploited in the wild, with fixed Chrome 153 builds listed); Finding 01 (CVSS 10.0 SAP kernel flaw enables unauthenticated remote code execution, although no exploitation is reported).
Finding 01 — SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
What changed: SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-44756; CVSS v3.1 10; weakness CWE-120; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Where HTTP terminates at a standalone Web Dispatcher, apply the workaround in SAP Note 3756304; for kernel ICM ports, restrict network reachability. Alert on sap-passport headers from untrusted sources and investigate repeated worker crashes. Onapsis Research Labs reports that it had not observed active in-the-wild exploitation as of publication. ([support.sap.com](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html), [redrays.io](https://redrays.io/blog/sap-note-3747649-extended-passport-stack-overflow-cve-2026-44756/), [onapsis.com](https://onapsis.com/blog/sap-overpass-remediation/))
Affected: KRNL64NUC 7.22 and 7.22EXT; KRNL64UC 7.22, 7.22EXT, 7.53 and 8.04; WEBDISP 9.16, 9.18, 9.19 and 9.20; KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20. ([support.sap.com](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html))
Fix: For kernel 9.16, the corrections were observed in sapwebdisp patch level 100 and were absent from patch level 71. ([redrays.io](https://redrays.io/blog/sap-note-3747649-extended-passport-stack-overflow-cve-2026-44756/))
Action: Map CVE-2026-44756 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html)
Finding 02 — ScreenConnect CVE-2026-84869 enables unauthorised file transfer and execution
What changed: Successful exploitation of CVE-2026-84869 may allow unauthorised file transfer and execution through an active ScreenConnect remote session. The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-84869; CVSS v3.1 9.9; weakness CWE-862, CWE-269; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: For every role, deselect the TransferFiles permission for each session group until the update is applied. Monitor ScreenConnect audit logs for RunFiles or RanFiles entries involving suspect scripts executed from Process: Guest. ([connectwise.com](https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin), [huntress.com](https://www.huntress.com/blog/rogue-screenconnect-installations), [buttondown.com](https://buttondown.com/exploit-bulletin/archive/the-exploit-bulletin-wednesday-september-9-2026-4/))
Affected: All ScreenConnect versions prior to 26.6.5. ([connectwise.com](https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin))
Fix: ScreenConnect 26.6.5. ([connectwise.com](https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin))
Action: Map CVE-2026-84869 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: digital.nhs.uk](https://digital.nhs.uk/cyber-alerts/2026/cc-4848)
Finding 03 — WatchGuard FireWare OS epm connect Stack-based Buffer Overflow Remote Code Execution Vulnerability
What changed: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability.
Technical evidence: CVE-2026-13086; CVSS v4.0 9.3; weakness CWE-121, CWE-787, CWE-798; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict access to trusted interfaces to authorised systems, and monitor for specially crafted JSON-RPC requests to the epm service or repeated epm process crashes. WatchGuard reports that it is not aware of any exploitation in the wild. ([psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-13086/))
Fix: Fireware OS 2026.3.1, 2026.2.2, 12.12.2 and 12.5.20. ([psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-13086/))
Action: Map CVE-2026-13086 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-632/)
Finding 04 — Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability
What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability.
Technical evidence: CVE-2026-70477; CVSS v4.0 9.5; weakness CWE-94; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If immediate upgrading is not possible, disable or remove CSV Agent nodes from all public-facing chatflows. ([securelayer7.net](https://securelayer7.net/lab/cve-2026-70477-flowise-csv-agent-prompt-injection-rce), [github.com](https://github.com/advisories/GHSA-5xvg-pmgg-3mxr))
Affected: Flowise versions up to and including 3.1.2. ([github.com](https://github.com/advisories/GHSA-5xvg-pmgg-3mxr))
Fix: Flowise 3.1.3. ([github.com](https://github.com/advisories/GHSA-5xvg-pmgg-3mxr))
Panel assessment: Patch now: unauthenticated RCE, affected versions through 3.1.2, a public PoC, and the chance of public-facing chatflows make exposed Flowise CSV Agent deployments a high-value target with service-host blast radius. The likely path is attacker-controlled input reaching a CSV Agent node and triggering code execution under the Flowise process, putting configured credentials, connected pipelines, and accessible data at risk. (priority: patch now)
Action: Map CVE-2026-70477 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-634/)
Finding 05 — Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability
What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability.
Technical evidence: CVE-2026-8037; CVSS v3.1 9.6; weakness CWE-77; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Disable the LoadMaster API until patched; if it must remain enabled, restrict network access to authorised management hosts. Monitor requests to the /accessv2 endpoint. eSentire's Threat Response Unit reports exploitation attempts beginning on 29 June 2026. ([labs.watchtowr.com](https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/), [esentire.com](https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037), [community.progress.com](https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691))
Affected: Kemp LoadMaster GA v7.2.63.1 and older; Kemp LoadMaster LTSF v7.2.54.17 and older. ([community.progress.com](https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691))
Fix: Kemp LoadMaster GA v7.2.63.2; Kemp LoadMaster LTSF v7.2.54.18. ([community.progress.com](https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691))
Action: Map CVE-2026-8037 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-646/)
Finding 06 — Microsoft Windows Heap-Based Buffer Overflow Vulnerability — Windows
What changed: CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability — Windows The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-85880.
Technical evidence: CVE-2026-85880; CVSS v3.1 7.8; weakness CWE-122, CWE-908; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Monitor for compromised low-privilege accounts, sandbox-escape behaviour, unusual SYSTEM-level processes, unauthorised changes to protected files, and suspicious activity following execution from user-controlled contexts. Microsoft reports exploitation detected. ([msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880), [socprime.com](https://socprime.com/blog/cve-2026-85880-and-cve-2026-81963-analysis/))
Affected: Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows Server 2012, 2012 R2, 2016, 2019 and 2022, including applicable Server Core installations. ([socprime.com](https://socprime.com/blog/cve-2026-85880-and-cve-2026-81963-analysis/))
Fix: Windows 10 22H2 build 19045.7725; Windows Server 2016 build 14393.9512; Windows Server 2019 build 17763.9245; Windows Server 2022 build 20348.5622. ([socprime.com](https://socprime.com/blog/cve-2026-85880-and-cve-2026-81963-analysis/))
Action: Map CVE-2026-85880 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-85880)
Finding 07 — Chrome 153 Patches Seventh Zero-Day of 2026
What changed: The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-87491; CVSS v3.1 8.8; weakness CWE-787; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Monitor unpatched systems for unexpected Chrome renderer crashes, browser memory-corruption alerts and unusual Chrome child-process behaviour. Correlate endpoint telemetry with DNS, secure web gateway, proxy, email and network records. Google reports that an exploit for CVE-2026-87491 exists in the wild. ([socprime.com](https://socprime.com/blog/cve-2026-87491-chrome-v8-zero-day-exploited/), [securityweek.com](https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/))
Affected: Google Chrome releases earlier than 153.0.8010.36. ([socprime.com](https://socprime.com/blog/cve-2026-87491-chrome-v8-zero-day-exploited/))
Fix: Chrome 153.0.8010.36/.37 for Windows and macOS, and 153.0.8010.36 for Linux. ([socprime.com](https://socprime.com/blog/cve-2026-87491-chrome-v8-zero-day-exploited/))
Action: Map CVE-2026-87491 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: securityweek.com](https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/)
Finding 08 — Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download.
What changed: Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended dependency directory, allowing attacker-controlled paths (via relative traversal such as ../ or absolute paths) to target filesystem locations outside that directory.
Technical evidence: CVE-2026-32146; CVSS v4.0 8.3; weakness CWE-22; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Avoid untrusted git dependencies and pin dependencies to verified commit SHAs. Run dependency resolution commands in a restricted or isolated environment, such as a container. The Gleam project's GitHub security advisory provides a simplified proof of concept. ([github.com](https://github.com/gleam-lang/gleam/security/advisories/GHSA-vq5j-55vx-wq8j), [cna.erlef.org](https://cna.erlef.org/cves/CVE-2026-32146.html))
Affected: Gleam versions from 1.9.0-rc1 up to, but not including, 1.15.4. ([cna.erlef.org](https://cna.erlef.org/cves/CVE-2026-32146.html))
Fix: Gleam 1.15.4 or later. ([cna.erlef.org](https://cna.erlef.org/cves/CVE-2026-32146.html))
Action: Map CVE-2026-32146 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-32146)
Finding 09 — Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability — Multiple Products
What changed: CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability — Multiple Products The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2025-25249.
Technical evidence: CVE-2025-25249; CVSS v3.1 7.4; weakness CWE-122; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Remove “fabric” access from each interface. Alternatively, block CAPWAP-CONTROL access to UDP ports 5246-5249 through a local-in policy. SOCRadar Threat Research Unit reports active exploitation since at least July 2026. ([threatprotect.qualys.com](https://threatprotect.qualys.com/2026/01/14/fortios-and-fortiswitchmanager-code-execution-vulnerability-cve-2025-25249/), [socradar.io](https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2025-25249), +1 more)
Affected: FortiOS 7.6.0-7.6.3, 7.4.0-7.4.8, 7.2.0-7.2.11, 7.0.0-7.0.17 and 6.4.0-6.4.16; FortiSASE 25.2.b and 25.1.a.2; FortiSwitchManager 7.2.0-7.2.6 and 7.0.0-7.0.5. Siemens also lists RUGGEDCOM APE1808 versi ([threatprotect.qualys.com](https://threatprotect.qualys.com/2026/01/14/fortios-and-fortiswitchmanager-code-execution-vulnerability-cve-2025-25249/), [cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-864900.html))
Fix: FortiOS 7.6.4+, 7.4.9+, 7.2.12+, 7.0.18+ and 6.4.17+; FortiSwitchManager 7.2.7+ and 7.0.6+; FortiSASE 25.2.c and 25.1.b. For RUGGEDCOM APE1808, Siemens specifies Fortinet NGFW 7.4.9+. ([threatprotect.qualys.com](https://threatprotect.qualys.com/2026/01/14/fortios-and-fortiswitchmanager-code-execution-vulnerability-cve-2025-25249/), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2025-25249), [cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-864900.html))
Action: Map CVE-2025-25249 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2025-25249)
Finding 10 — smol-toml: Denial of Service via malformed TOML documents
What changed: smol-toml: Denial of Service via malformed TOML documents The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-85730.
Technical evidence: CVE-2026-85730; CVSS v4.0 8.2; weakness CWE-606, CWE-835; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until upgrading, run parse() inside a worker thread with a timeout as a stopgap. Do not rely on input-size limits for this flaw. The GitHub Security Advisory publishes a proof of concept that causes parse() never to return while pinning the CPU at 100%. ([medium.com](https://medium.com/@ravindu.lakmina1/seven-bytes-that-freeze-a-node-js-server-forever-the-story-of-cve-2026-85730-3213328b38f0), [github.com](https://github.com/advisories/GHSA-7w5x-hrqm-74c2), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-85730))
Affected: smol-toml versions earlier than 1.7.1. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-85730))
Fix: smol-toml 1.7.1. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-85730))
Action: Map CVE-2026-85730 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-7w5x-hrqm-74c2)
Finding 11 — Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
What changed: Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-59185.
Technical evidence: CVE-2026-59185; CVSS v3.1 8.5; weakness CWE-639, CWE-862; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until upgrading, disable the Identrail GitHub App connection flow or block POST requests to both GitHub connection-completion endpoints at the reverse proxy. Monitor for attempted requests to these endpoints, particularly those supplying installation_id. CyberKareem publishes an offline, synthetic authorisation-invariant proof of concept that performs no HTTP request. ([github.com](https://github.com/identrail/identrail/releases/tag/v1.0.2), [cyberkareem.com](https://cyberkareem.com/writing/cve-2026-59185-identrail-installation-id-ownership/), [github.com](https://github.com/advisories/GHSA-cp3j-m783-3ph5))
Affected: Versions earlier than 1.0.2; the vendor specifically identifies v1.0.0 and v1.0.1 as vulnerable. ([github.com](https://github.com/identrail/identrail/releases/tag/v1.0.2), [github.com](https://github.com/advisories/GHSA-cp3j-m783-3ph5))
Fix: 1.0.2. ([github.com](https://github.com/advisories/GHSA-cp3j-m783-3ph5))
Action: Map CVE-2026-59185 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-cp3j-m783-3ph5)
Finding 12 — Multiple vulnerabilities in Oracle VirtualBox
What changed: CVE coverage: CVE-2026-60155, CVE-2026-60159, CVE-2026-71116, CVE-2026-60162, CVE-2026-71114, CVE-2026-71132. The cited advisories disclose: VMSVGA Race Condition Local Privilege Escalation Vulnerability; IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability; VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability; VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability; VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability.
Technical evidence: CVE-2026-60155; CVSS v3.1 7.5; weakness CWE-284; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-60155 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-644/)
Finding 13 — Multiple vulnerabilities in Oracle Outside In Technology
What changed: CVE coverage: CVE-2026-60414, CVE-2026-60413, CVE-2026-60412, CVE-2026-60392. The cited advisories disclose: WPS File Parsing Memory Corruption Remote Code Execution Vulnerability; GEM File Parsing Integer Overflow Remote Code Execution Vulnerability; PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability; PDF File Parsing Integer Overflow Remote Code Execution Vulnerability.
Technical evidence: CVE-2026-60414; CVSS v3.1 7.8; weakness CWE-200; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Restrict logon access to infrastructure hosting Outside In, and block WPS, GEM, PostScript and PDF files from Outside In processing until patched. ([oracle.com](https://www.oracle.com/security-alerts/cspuaug2026verbose.html#FMW), [zerodayinitiative.com](https://www.zerodayinitiative.com/advisories/ZDI-26-638/), [zerodayinitiative.com](https://www.zerodayinitiative.com/advisories/ZDI-26-637/), +2 more)
Affected: Oracle Outside In Technology 8.5.8. ([oracle.com](https://www.oracle.com/security-alerts/cspuaug2026verbose.html#FMW))
Action: Map CVE-2026-60414 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-638/)
Finding 14 — GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability
What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Technical evidence: CVE-2026-4153; CVSS v3.1 7.8; weakness CWE-122; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Avoid opening untrusted PSP (PaintShop Pro) files with GIMP and restrict PSP-file sources to trusted origins. ([access.redhat.com](https://access.redhat.com/security/cve/cve-2026-4153), [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-4153), [lists.opensuse.org](https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MFTWAWOOTL7SNDU6JIYC77TA6PDMCUED/))
Affected: GIMP 3.0.8. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-4153))
Fix: openSUSE Leap 16.0 package: gimp-3.0.8-bp160.3.1. ([lists.opensuse.org](https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MFTWAWOOTL7SNDU6JIYC77TA6PDMCUED/))
Action: Map CVE-2026-4153 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-633/)
Finding 15 — @openhop/server: Path Traversal in Flow ID File Operations
What changed: @openhop/server: Path Traversal in Flow ID File Operations The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-59179.
Technical evidence: CVE-2026-59179; CVSS v3.1 8.3; weakness CWE-22; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patching, restrict access to the server and block GET or DELETE requests to /api/flows/:id whose decoded ID contains traversal sequences such as ../. Prevent untrusted browser origins from reaching local instances, and bind container deployments to a trusted interface rather than 0.0.0.0. ([github.com](https://github.com/naorsabag/openhop/security/advisories/GHSA-g72f-jw3w-mgh7))
Affected: @openhop/server versions <= 0.3.5. ([github.com](https://github.com/naorsabag/openhop/security/advisories/GHSA-g72f-jw3w-mgh7))
Fix: @openhop/server version 0.3.6. ([github.com](https://github.com/naorsabag/openhop/security/advisories/GHSA-g72f-jw3w-mgh7))
Action: Map CVE-2026-59179 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-g72f-jw3w-mgh7)