Executive assessment
Today's brief leads with CISA: WatchGuard RCE flaw now exploited in ransomware attacks. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 01 leads because it is critical, CISA reports exploitation in ransomware attacks, and fixed Fireware OS versions are listed. Themes: Actively exploited network appliances; PoC-backed critical flaws; Access restriction as interim control. Patch order: Finding 01 (Act first because CISA reports exploitation in ransomware attacks and fixed Fireware OS versions are listed); Finding 04 (Prioritise because exploitation is in the wild and fixed RouterOS versions are listed); Finding 03 (Treat urgently because a PoC exists and no patched version is listed; restrict /api/acp/agents to loopback-only); Finding 05 (Patch early because a PoC exists and fixed Traefik versions are listed); Finding 07 (Patch early because a PoC exists, version 1.75.1 is listed as fixed, and the mitigation requires explicit --auth-key plus trusted-network restriction).
Finding 01 — CISA: WatchGuard RCE flaw now exploited in ransomware attacks
What changed: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.
Technical evidence: CVE-2025-14733; CVSS v4.0 9.3; weakness CWE-787; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: For Fireboxes used only with static-peer BOVPNs, disable dynamic-peer BOVPNs, permit UDP 500 to the Firebox only from aliases containing the remote peers’ static IP addresses, and disable the default VPN policies. Monitor for IKE_AUTH CERT payloads greater than 2,000 bytes and IKED process hangs. WatchGuard reports observing threat actors actively attempting exploitation in the wild. ([psirt.watchguard.com](https://psirt.watchguard.com/CVE-2025-14733/), [techsearch.watchguard.com](https://techsearch.watchguard.com/KB?type=Article&SFDCID=kA1Vr000000DMXNKA4&lang=en_US))
Fix: Fireware OS 2025.1.4, 12.11.6, 12.5.15, and 12.3.1-b728352. ([psirt.watchguard.com](https://psirt.watchguard.com/CVE-2025-14733/))
Action: Map CVE-2025-14733 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/)
Finding 02 — Multiple vulnerabilities in Check Point
What changed: CVE coverage: CVE-2026-85102, CVE-2026-85103. The cited advisories disclose: VPN certificate parsing flaws enable unauthenticated RCE; Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE.
Technical evidence: CVE-2026-85102; CVSS v3.1 9.8; weakness CWE-295; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: For Site-to-Site VPN, disable implied VPN rules and permit UDP/500 and UDP/4500 only from specific peer IP addresses. This mitigation does not apply to locally managed Spark Firewall. SecurityOnline.info reports no active in-the-wild exploitation and no public proof-of-concept exploits. ([support.checkpoint.com](https://support.checkpoint.com/results/sk/sk1000117/), [support.checkpoint.com](https://support.checkpoint.com/results/sk/sk1000118/), [securityonline.info](https://securityonline.info/checkpoint-vpn-vulnerabilities/))
Affected: CVE-2026-85102 affects Security Gateway and Spark Firewall using Site-to-Site or Remote Access VPN; CVE-2026-85103 affects Security Management Server, Security Gateway and Spark Firewall. Affected rel ([support.checkpoint.com](https://support.checkpoint.com/results/sk/sk1000117/), [support.checkpoint.com](https://support.checkpoint.com/results/sk/sk1000118/))
Fix: Jumbo Hotfix Accumulator: R82.10 Take 44, R82 Take 126 and R81.20 Take 166. Spark Firewall: R82.00.10 Build 2325 and R81.10.17 Build 4968. ([support.checkpoint.com](https://support.checkpoint.com/results/sk/sk1000117/))
Panel assessment: Patch now: these are critical unauthenticated RCE flaws in VPN certificate handling across broad Check Point gateway, Spark Firewall and management-server releases, so perimeter-exposed VPN services carry high blast-radius risk even without reported exploitation or public PoC. (priority: patch now)
Action: Map CVE-2026-85102 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cert.europa.eu](https://cert.europa.eu/publications/security-advisories/2026-012/)
Finding 03 — OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
What changed: OmniRoute ACP Custom-Agent Remote Code Execution (RCE) The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-88062.
Technical evidence: CVE-2026-88062; CVSS v4.0 9.5; weakness CWE-94, CWE-306; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict /api/acp/agents to loopback-only access. Keep requireLogin=true and configure a management password. ([github.com](https://github.com/advisories/GHSA-hf57-cqmx-p4gr), [github.com](https://github.com/diegosouzapw/OmniRoute/issues/7948))
Affected: <= 3.8.50 ([github.com](https://github.com/advisories/GHSA-hf57-cqmx-p4gr))
Fix: No patched version is listed. ([github.com](https://github.com/advisories/GHSA-hf57-cqmx-p4gr))
Action: Map CVE-2026-88062 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-hf57-cqmx-p4gr)
Finding 04 — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability — RouterOS
What changed: CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability — RouterOS The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-86060.
Technical evidence: CVE-2026-86060; CVSS v4.0 9.2; weakness CWE-88; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Restrict SSH to trusted management addresses or access it through a VPN; do not expose management ports to untrusted networks. Monitor for SSH login attempts using user -2, users added by ssh:-2, and an unexpected privileged user named ops. ([mikrotik.com](https://mikrotik.com/supportsec/september-2026-vulnerability), [cert.pl](https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-86060))
Affected: RouterOS 6.0.0 before 6.49.21, 7.0.0 before 7.23.4, and 7.24 before 7.24.2. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-86060))
Fix: RouterOS 6.49.21, 7.23.4, 7.24.2, and 7.25 beta 3. ([mikrotik.com](https://mikrotik.com/supportsec/september-2026-vulnerability))
Panel assessment: Patch affected RouterOS devices now, prioritising any with SSH reachable from untrusted networks, because exploitation is confirmed and the reported chain can take full control of exposed devices. The likely path is a crafted SSH username that manipulates session privileges, reaching the router management plane and enabling attacker-created privileged access. (priority: patch now)
Action: Map CVE-2026-86060 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-86060)
Finding 05 — Traefik HTTP/3 Backend NTLM Connection Reuse
What changed: Traefik HTTP/3 Backend NTLM Connection Reuse The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-88007.
Technical evidence: CVE-2026-88007; CVSS v4.0 9.1; weakness CWE-287, CWE-863; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Disable HTTP/3 on Traefik entrypoints until patched; alternatively, disable backend keep-alive and connection reuse for routes using NTLM or Negotiate. ([github.com](https://github.com/traefik/traefik/security/advisories/GHSA-qqjf-53cj-pwvv), [community.traefik.io](https://community.traefik.io/t/new-security-update-for-traefik-2-11-2-11-57-and-3-7-3-7-13/30229))
Fix: Traefik v2.11.57 and v3.7.13. ([community.traefik.io](https://community.traefik.io/t/new-security-update-for-traefik-2-11-2-11-57-and-3-7-3-7-13/30229))
Panel assessment: Patch now where the prerequisite configuration exists: this is a critical authentication-bypass class issue with a PoC/verifier, and connection-bound identity reuse can turn one user’s backend session into another user’s access. The likely path is HTTP/3 traffic through Traefik being mapped onto a keep-alive backend connection already authenticated with NTLM/Negotiate, reaching protected backend application actions or data without stealing credentials. (priority: patch now)
Action: Map CVE-2026-88007 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-qqjf-53cj-pwvv)
Finding 06 — rclone: http backend forwards custom/auth headers to a different host
What changed: CVE coverage: CVE-2026-88013, CVE-2026-88016, CVE-2026-88044, CVE-2026-88017, CVE-2026-88046, CVE-2026-88045. rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-88044; CVSS v3.1 9.1; weakness CWE-863; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-88044 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-486v-q2wf-fp2r)
Finding 07 — rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
What changed: rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-88018.
Technical evidence: CVE-2026-88018; CVSS v3.1 9.8; weakness CWE-287, CWE-306; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is not immediately possible, explicitly configure --auth-key and restrict the S3 server to trusted networks. Review access logs for suspicious administrative activity or unexpected bucket listings. SecurityOnline reports that proof-of-concept exploit code has been publicly disclosed. ([api.github.com](https://api.github.com/advisories/GHSA-xwwr-4h3p-r22c), [securityonline.info](https://securityonline.info/rclone-auth-proxy-bypass-poc/))
Affected: Versions earlier than 1.75.1. ([api.github.com](https://api.github.com/advisories/GHSA-xwwr-4h3p-r22c))
Fix: 1.75.1. ([api.github.com](https://api.github.com/advisories/GHSA-xwwr-4h3p-r22c))
Action: Map CVE-2026-88018 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-xwwr-4h3p-r22c)
Finding 08 — New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
What changed: The exploit provides full System privileges on Windows machines running the September 2026 patches. The published proof of concept demonstrates a local privilege escalation path to SYSTEM; in-the-wild exploitation was not established.
Technical evidence: CVE-2026-50656; CVSS v3.1 7.8; weakness CWE-59; technical confidence High.
Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.
Analyst note: Restrict untrusted code execution, remove unnecessary local administrative privileges and limit interactive access to sensitive systems. Monitor for unexpected sensitive-file reads involving MsMpEng.exe or related Defender processes. SOCRadar reports that a public PoC is available but there is no confirmed evidence of in-the-wild exploitation. ([socradar.io](https://socradar.io/blog/shieldcrash-poc-microsoft-defender-fix-bypass/))
Affected: Nightmare Eclipse reports all supported Windows versions, including updated Windows 10, Windows 11 and Windows Server. ([socradar.io](https://socradar.io/blog/shieldcrash-poc-microsoft-defender-fix-bypass/))
Action: Map CVE-2026-50656 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: securityweek.com](https://www.securityweek.com/new-shieldcrash-zero-day-exploit-targets-microsoft-defender/)
Finding 09 — Multiple vulnerabilities in Open WebUI
What changed: CVE coverage: CVE-2026-87999, CVE-2026-87017, CVE-2026-87994, CVE-2026-87995, CVE-2026-87996, CVE-2026-87998, CVE-2026-88005, CVE-2026-87015, CVE-2026-87016, CVE-2026-88006, CVE-2026-87011, CVE-2026-87014. The cited advisories disclose: Any authenticated user can reach the Azure platform channel via server-side web fetch; Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends; Channel members can overwrite another member's message via the chat completions endpoint; Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin; SSRF into internal services via DNS rebinding in the Playwright web loader; Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion; Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange; A user's session cookies are sent to tool servers configured for bearer authentication; Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite; Users denied by the OAuth role policy can still sign in via token exchange; Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout; Admin demoted through SSO role sync keeps read and write access to all users' notes.
Technical evidence: CVE-2026-87999; CVSS v3.1 7.1; weakness CWE-918; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patching, keep channels disabled (ENABLE_CHANNELS=False) and OAuth token exchange disabled (ENABLE_OAUTH_TOKEN_EXCHANGE=False). Add 168.63.129.16 to WEB_FETCH_FILTER_LIST on affected Azure-hosted instances. GitHub's reviewed advisory publishes proof-of-concept steps for CVE-2026-87999. ([github.com](https://github.com/advisories/GHSA-34r3-9m95-vq73), [github.com](https://github.com/advisories/GHSA-pcvc-8vrv-8q6w), [github.com](https://github.com/advisories/GHSA-fmqh-xp37-5hr8), +9 more)
Fix: 0.11.1 for all listed CVEs except CVE-2026-88005, which is patched in 0.9.0. ([github.com](https://github.com/advisories/GHSA-34r3-9m95-vq73), [github.com](https://github.com/advisories/GHSA-pcvc-8vrv-8q6w), [github.com](https://github.com/advisories/GHSA-fmqh-xp37-5hr8), +9 more)
Action: Map CVE-2026-87999 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-34r3-9m95-vq73)
Finding 10 — ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability
What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of ASUS Control Center Express Agent. Authentication is not required to exploit this vulnerability.
Technical evidence: CVE-2026-19397; CVSS v4.0 7.7; weakness CWE-306; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Block or restrict inbound TCP port 10637 to authorised management systems, and monitor connection attempts to that port. SecurityOnline.info reports that ASUS has identified no active exploitation or public proof-of-concept. ([zerodayinitiative.com](https://www.zerodayinitiative.com/advisories/ZDI-26-657/), [asus.com](https://www.asus.com/security-advisory/), [securityonline.info](https://securityonline.info/asus-control-center-express-armoury-crate/))
Affected: ASUS Control Center Express Agent versions earlier than v1.7.24. ([asus.com](https://www.asus.com/security-advisory/))
Fix: ASUS Control Center Express v1.7.24 or later, followed by updating the client agents. ([asus.com](https://www.asus.com/security-advisory/))
Action: Map CVE-2026-19397 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-657/)
Finding 11 — Multiple vulnerabilities in Photoshop and Adobe Acrobat
What changed: CVE coverage: CVE-2026-75862, CVE-2026-75863, CVE-2026-75771, CVE-2026-81987, CVE-2026-81977. The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-75862; CVSS v3.1 7.8; weakness CWE-190; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict web content and block unnecessary file types at the email gateway; enable anti-exploitation features and host-based intrusion prevention on endpoints. Run the software as a non-privileged user. Adobe reports no known in-the-wild exploits for the issues addressed in either update; CIS likewise reports no exploitation. ([helpx.adobe.com](https://helpx.adobe.com/security/products/photoshop/apsb26-130.html), [helpx.adobe.com](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html), [cisecurity.org](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2026-091))
Affected: Photoshop 2026 27.6 and earlier and Photoshop 2025 26.11.6 and earlier; Adobe Acrobat and Acrobat Reader Continuous 26.002.21900 and earlier, and Acrobat 2024 Classic 2024 24.001.30383 and earlier, on ([helpx.adobe.com](https://helpx.adobe.com/security/products/photoshop/apsb26-130.html), [helpx.adobe.com](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html))
Fix: Photoshop 2026 27.7 and Photoshop 2025 26.11.7; Adobe Acrobat and Acrobat Reader Continuous 26.002.21901, and Acrobat 2024 Classic 2024 24.001.30429, for Windows and macOS. ([helpx.adobe.com](https://helpx.adobe.com/security/products/photoshop/apsb26-130.html), [helpx.adobe.com](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html))
Action: Map CVE-2026-75862 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-679/)
Finding 12 — Multiple vulnerabilities in Adobe Acrobat
What changed: CVE coverage: CVE-2026-81973, CVE-2026-81976, CVE-2026-81981, CVE-2026-80161, CVE-2026-81975, CVE-2026-79909, CVE-2026-81986, CVE-2026-81990, CVE-2026-81985, CVE-2026-81991, CVE-2026-81978, CVE-2026-81984, CVE-2026-79910, CVE-2026-80162, CVE-2026-80160. The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-81973; CVSS v3.1 7.8; weakness CWE-416; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Prevent users who cannot patch from opening untrusted files or visiting untrusted pages. Adobe reports that it is not aware of any in-the-wild exploitation of the issues addressed by this update. ([zerodayinitiative.com](https://www.zerodayinitiative.com/advisories/ZDI-26-676/), [helpx.adobe.com](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html))
Affected: Adobe Acrobat and Acrobat Reader Continuous 26.002.21900 and earlier; Acrobat 2024 Classic 2024 24.001.30383 and earlier, on Windows and macOS. ([helpx.adobe.com](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html))
Fix: Adobe Acrobat and Acrobat Reader Continuous 26.002.21901; Acrobat 2024 Classic 2024 24.001.30429, on Windows and macOS. ([helpx.adobe.com](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html))
Action: Map CVE-2026-81973 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-676/)
Finding 13 — Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability
What changed: CVE coverage: CVE-2026-81988, CVE-2026-81989. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC.
Technical evidence: CVE-2026-81988; CVSS v3.1 7.8; weakness CWE-416; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patching is possible, restrict websites and block downloads, attachments and JavaScript. Run Acrobat as a non-privileged user. Adobe reports that it is not aware of any in-the-wild exploitation of issues addressed by APSB26-141. ([helpx.adobe.com](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html), [cisecurity.org](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2026-091))
Affected: Adobe Acrobat Continuous 26.002.21900 and earlier, and Acrobat 2024 Classic 24.001.30383 and earlier, on Windows and macOS. ([helpx.adobe.com](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html))
Fix: Adobe Acrobat Continuous 26.002.21901, and Acrobat 2024 Classic 24.001.30429, on Windows and macOS. ([helpx.adobe.com](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html))
Action: Map CVE-2026-81988 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-673/)
Finding 14 — Multiple vulnerabilities in AVEVA Pipeline Integrity Monitor
What changed: Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824).
Technical evidence: CVE-2026-81821; CVSS v4.0 8.3; weakness CWE-321; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict network access to PIMBoards API hosts with host-based or network firewalls, permitting only trusted client systems. Apply strong access-control lists to project-file folders so only trusted users have read access. CISA reports that no known public exploitation specifically targeting these vulnerabilities has been reported to it. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01), [aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))
Affected: AVEVA Pipeline Integrity Monitor 2025 SP1 P1 (build 7.1.9580.8513) and all prior versions. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))
Fix: AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))
Action: Map CVE-2026-81821 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01)
Finding 15 — Multiple vulnerabilities in n8n
What changed: CVE coverage: CVE-2026-86082, CVE-2026-86081, CVE-2026-86075, CVE-2026-86076, CVE-2026-86080, CVE-2026-86073, CVE-2026-86074, CVE-2026-86995, CVE-2026-86085, CVE-2026-86993, CVE-2026-86084, CVE-2026-86079, CVE-2026-86078, CVE-2026-86994, CVE-2026-86083, CVE-2026-86077. The cited advisories disclose: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node; Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path; Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint; Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution; GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open; Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution; Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content; Git Node branch.
Technical evidence: CVE-2026-86082; CVSS v4.0 7.1; weakness CWE-918; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-86082 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-34ff-336r-5q23)