Executive assessment
Today's brief leads with MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure).. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 05 should lead today because it is critical, exploited in the wild, and the listing says the Artifactory flaws are being chained in attacks deploying backdoor malware. Finding 01 is critical and urgent, but the listing reports proof-of-concept exploitation rather than active attacks. Themes: In-the-wild exploitation of enterprise platforms; Authentication and validation failures; Chromium browser memory-safety cluster. Patch order: Finding 05 (Critical Artifactory flaws are being exploited in the wild and chained to deploy backdoor malware, with fixed versions listed); Finding 06 (High-severity Sogou Input Method vulnerabilities are exploited in the wild, with version 16.3.0.3498 deployed through automatic update); Finding 01 (Critical MySQL MCP Server issue has proof-of-concept unauthenticated exploitation via SSE transport, and mysql-mcp-server 0.4.2 fixes it); Finding 03 (Critical Prowler issue has proof-of-concept SAML domain claiming that enables cross-tenant account takeover, and 5.30.3 fixes it).
Finding 01 — MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure).
What changed: MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure). CVE coverage: CVE-2026-59971.
Technical evidence: CVE-2026-59971; CVSS v3.1 10.0; weakness CWE-306, CWE-346; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Disable SSE by using the unaffected default stdio mode; if SSE must remain enabled, place authentication in front of it with a reverse proxy and block direct access to the backend. ([github.com](https://github.com/designcomputer/mysql_mcp_server/security/advisories/GHSA-rqfv-2mw9-78g2), [github.com](https://github.com/designcomputer/mysql_mcp_server/releases/tag/v0.4.2), [github.com](https://github.com/designcomputer/mysql_mcp_server/issues/92))
Affected: mysql-mcp-server versions up to and including 0.4.1. ([github.com](https://github.com/designcomputer/mysql_mcp_server/issues/92))
Fix: mysql-mcp-server 0.4.2. ([github.com](https://github.com/designcomputer/mysql_mcp_server/security/advisories/GHSA-rqfv-2mw9-78g2))
Panel assessment: Patch or disable SSE now because an exposed SSE endpoint on mysql-mcp-server 0.4.1 or earlier can be driven without authentication, there is a PoC, and the blast radius is the database access granted to the server account. The likely path is a direct SSE handshake, or DNS rebinding where browser access is in play, followed by execute_sql to read or alter reachable MySQL data. (priority: patch now)
Action: Map CVE-2026-59971 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-rqfv-2mw9-78g2)
Finding 02 — Multiple vulnerabilities in Chromium
What changed: Chromium fixes 8 CVEs in one release: Use after free in DevTools; Incomplete cleanup in Network; Type confusion in Compositing; Use after free in Compositing; Use after free in Skia; Improper resource exposure in CacheStorage; Race condition in V8; Out of bounds read in CrashReporting. CVE coverage: CVE-2026-85042, CVE-2026-85043, CVE-2026-85051, CVE-2026-85048, CVE-2026-85049, CVE-2026-85053, CVE-2026-85045, CVE-2026-85052.
Technical evidence: CVE-2026-85042; CVSS v3.1 9.6; weakness CWE-416; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is delayed, restrict unpatched browsers to approved sites and block externally supplied HTML pages. Set Chrome Enterprise's DeveloperToolsAvailability policy to 2 to disable developer tools. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-85042), [chromeenterprise.google](https://chromeenterprise.google/policies/developer-tools-availability/), [chromereleases.googleblog.com](https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html), +9 more)
Affected: Google Chrome versions prior to 152.0.7977.82 ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-85042), [hkcert.org](https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260904), [cisecurity.org](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-088), +1 more)
Fix: Chrome 152.0.7977.82/.83 for Windows and Mac; 152.0.7977.82 for Linux ([chromereleases.googleblog.com](https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html), [hkcert.org](https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260904))
Action: Map CVE-2026-85042 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: chromereleases.googleblog.com](https://chromereleases.googleblog.com/2026)
Finding 03 — Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
What changed: Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover. CVE coverage: CVE-2026-59151.
Technical evidence: CVE-2026-59151; CVSS v3.1 9.6; weakness CWE-287; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is not immediately possible, disable SAML authentication for multi-tenant Prowler deployments and use an alternative identity provider. Restrict SAML IdP registration to trusted administrators and require out-of-band verification of new domain associations. Prowler's security advisory publishes a manual HTTP exploitation chain against a live Prowler API. ([github.com](https://github.com/prowler-cloud/prowler/security/advisories/GHSA-h8m9-jgf8-vwvp), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-59151/))
Affected: Prowler API Docker Image versions up to and including 5.30.2. ([github.com](https://github.com/prowler-cloud/prowler/security/advisories/GHSA-h8m9-jgf8-vwvp))
Fix: 5.30.3 ([github.com](https://github.com/prowler-cloud/prowler/security/advisories/GHSA-h8m9-jgf8-vwvp))
Panel assessment: Patch now: affected Prowler API Docker images have a published manual HTTP exploitation chain, and successful abuse enables cross-tenant account takeover rather than a single-user compromise. The likely path is attacker-controlled SAML IdP/domain claiming followed by authentication into another tenant’s account, reaching that tenant’s Prowler access and data exposed to the compromised identity. (priority: patch now)
Action: Map CVE-2026-59151 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-h8m9-jgf8-vwvp)
Finding 04 — Multiple vulnerabilities in Central Dogma
What changed: CVE coverage: CVE-2026-11745, CVE-2026-11746, CVE-2026-11748. The cited advisories disclose: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover; LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion.
Technical evidence: CVE-2026-11746; CVSS v4.0 9.4; weakness CWE-798; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is not possible, disable git+ssh:// mirrors and ZooKeeper replication (replication.method NONE), or configure a fresh, long random replication.secret. Disable SearchFirstActiveDirectoryRealm and use the shipped DefaultLdapRealm example, which the advisory states is not affected. ([github.com](https://github.com/line/centraldogma/security/advisories/GHSA-vjfw-cpmh-xwv3), [github.com](https://github.com/line/centraldogma/security/advisories/GHSA-2j95-gqxf-v3vg), [github.com](https://github.com/line/centraldogma/security/advisories/GHSA-98q5-5qh2-7w75))
Fix: Version 0.84.0 fixes all three packages. ([github.com](https://github.com/line/centraldogma/security/advisories/GHSA-vjfw-cpmh-xwv3), [github.com](https://github.com/line/centraldogma/security/advisories/GHSA-2j95-gqxf-v3vg), [github.com](https://github.com/line/centraldogma/security/advisories/GHSA-98q5-5qh2-7w75))
Panel assessment: Treat Central Dogma as patch-now where present: all three issues are fixed in 0.84.0, PoCs are reported for each, and the hard-coded replication secret plus silent fallback makes a reachable replication deployment a cluster-takeover risk rather than a single-node bug. (priority: patch now)
Action: Map CVE-2026-11746 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-vjfw-cpmh-xwv3)
Finding 05 — Still active: Artifactory flaws chained in attacks deploying backdoor malware
Coverage status: First reported 2026-09-02; ongoing coverage.
What changed: Attackers are chaining JFrog Artifactory authentication and token-validation flaws to obtain administrator access, install malicious Groovy plugins, and deploy a Rust backdoor. CVE coverage: CVE-2026-42016, CVE-2026-42018, CVE-2026-82329.
Technical evidence: CVE-2026-82329; CVSS v3.1 9.8; weakness CWE-287; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: If immediate upgrade is not possible, generate a random hex-encoded additional join key, add it as additionalJoinKeys under shared › security, and restart Access or the JPD. Restrict network access to trusted users and systems, and review authentication and administrative activity for unexpected privileged access. Wiz Research reports confirmed in-the-wild exploitation of all three vulnerabilities across multiple environments. ([docs.jfrog.com](https://docs.jfrog.com/releases/docs/jfrog-security-advisories), [wiz.io](https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201))
Fix: CVE-2026-42016: 7.133.11. CVE-2026-42018: 7.111.20, 7.117.27, 7.125.19, 7.133.28, 7.146.8. CVE-2026-82329: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20. ([docs.jfrog.com](https://docs.jfrog.com/releases/docs/jfrog-security-advisories))
Action: Map CVE-2026-82329 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/)
Finding 06 — Multiple vulnerabilities in Sogou Input Method
What changed: CVE coverage: CVE-2021-38003, CVE-2026-51990. A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday.
Technical evidence: CVE-2021-38003; CVSS v3.1 8.8; weakness CWE-755; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Block noht1ng[.]top, mail.uaiubifas[.]top and 8.218.50[.]207; monitor attempted connections to the C2 domain on TCP port 443. ([gendigital.com](https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou))
Affected: The analysed Sogou Input Method bundled CEF 80.1.16 with Chromium 80.0.3987.163; CVE-2021-38003 affects Chrome versions before 95.0.4638.69. ([gendigital.com](https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou))
Fix: Sogou Input Method version 16.3.0.3498, deployed through automatic update. ([gendigital.com](https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou))
Action: Map CVE-2021-38003 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html)
Finding 07 — Multiple vulnerabilities in PAN-OS
What changed: CVE coverage: CVE-2026-0310, CVE-2026-0309, CVE-2026-0308. The cited advisories disclose: Buffer Overflow Vulnerability via XML Processing; Authenticated Command Injection in CLI with Luna HSM Configuration; Stored Cross-Site Scripting Vulnerability in the Web Interface.
Technical evidence: CVE-2026-0310; CVSS v4.0 7.2; weakness CWE-787; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict management-interface access to a single jump box and limit CLI access to a limited administrator group. For CVE-2026-0308, Threat Prevention subscribers can enable Threat IDs 510040 and 510041, with SSL decryption, for limited coverage. Palo Alto Networks reports that it is not aware of malicious exploitation of any of the three issues. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0310), [security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0309), [security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0308))
Affected: CVE-2026-0310: Cloud NGFW on AWS and Azure; PAN-OS 10.2, 11.1, 11.2, 12.1 and 12.2 below the branch-specific fixed builds; Prisma Access 10.2 before 10.2.10-h40, 11.2 before 11.2.7-h20 and 12.1 before ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0310), [security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0309), [security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0308))
Fix: CVE-2026-0310 and CVE-2026-0309: PAN-OS 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2 and 10.2.18-h10 or later. CVE-2026-0310 Prisma Access: 12.1.7-h5, 11.2.7-h20 or 10.2.10-h40 or later. CVE-2026-0308: PAN ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0310), [security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0309), [security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0308))
Action: Map CVE-2026-0310 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0310)
Finding 08 — @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-s
What changed: CVE coverage: CVE-2026-59148, CVE-2026-59149. @Mockoon/commons-server: Path traversal in templated filePath lets a request escape the served directory (prefix-only base check).
Technical evidence: CVE-2026-59148; CVSS v3.1 8.8; weakness CWE-306, CWE-352, CWE-732, CWE-942; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Start CLI runtimes with --disable-admin-api and block untrusted access to the mock-server port, including through public tunnels. Remove templating helpers that incorporate user-controlled body or query parameters into body or callback file paths. ([github.com](https://github.com/advisories/GHSA-rqx4-3f6q-3x2v), [github.com](https://github.com/advisories/GHSA-8wqc-v2q8-vff2), [mockoon.com](https://mockoon.com/releases/9.7.0))
Affected: Versions <= 9.6.1. ([github.com](https://github.com/advisories/GHSA-8wqc-v2q8-vff2))
Fix: Version 9.7.0 for both vulnerabilities. ([github.com](https://github.com/advisories/GHSA-rqx4-3f6q-3x2v), [github.com](https://github.com/advisories/GHSA-8wqc-v2q8-vff2))
Action: Map CVE-2026-59148 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-rqx4-3f6q-3x2v)
Finding 09 — CareCam Pro IP Cameras: Use of Hard-coded Credentials
What changed: Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083).
Technical evidence: CVE-2026-85083; CVSS v3.1 6.8; weakness CWE-798; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Restrict physical access to camera mounting locations with tamper-resistant brackets, locked enclosures and facility access controls. Segment cameras onto a dedicated IoT VLAN with no route to production subnets. CISA reports no known public exploitation specifically targeting this vulnerability. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01), [noisgate.com](https://www.noisgate.com/report/CVE-2026-85083))
Fix: No fixed version is available. ([noisgate.com](https://www.noisgate.com/report/CVE-2026-85083))
Action: Map CVE-2026-85083 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01)
Finding 10 — Cortex XDR Broker VM: Privilege Escalation Vulnerability
What changed: CVE-2026-0304 Cortex XDR Broker VM: Privilege Escalation Vulnerability. The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-0304; CVSS v4.0 4.8; weakness CWE-88; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Palo Alto Networks reports that it is not aware of any malicious exploitation. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0304))
Fix: Cortex XDR Broker VM 32.0.52 and all later versions. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0304))
Action: Map CVE-2026-0304 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0304)
Finding 11 — Multiple vulnerabilities in Prisma Access Agent
What changed: CVE coverage: CVE-2026-0305, CVE-2026-0306. The cited advisories disclose: Information Disclosure Vulnerability on Linux; EndPoint DLP Bypass Vulnerability on Windows.
Technical evidence: CVE-2026-0305; CVSS v4.0 4.3; weakness CWE-200; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Palo Alto Networks reports that it is not aware of malicious exploitation of either issue. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0305), [security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0306))
Affected: CVE-2026-0305 affects Prisma Access Agent on Linux before 26.3; CVE-2026-0306 affects Prisma Access Agent on Windows before 26.2. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0305), [security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0306))
Fix: CVE-2026-0305 is fixed in Prisma Access Agent 26.3 or later on Linux; CVE-2026-0306 is fixed in version 26.2 or later on Windows. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0305), [security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0306))
Action: Map CVE-2026-0305 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0305)
Finding 12 — PowerStore contains a Path Traversal vulnerability in the Service user
What changed: PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
Technical evidence: CVE-2026-28265; CVSS v3.1 4.4; weakness CWE-35; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Leave external SSH access disabled unless required for a remote service operation, then disable it immediately afterwards. ([dell.com](https://www.dell.com/support/manuals/en-us/powerstore-7000/pwrstr-setupgui/configure-external-ssh-access?guid=guid-e6f1d30e-7a8b-4502-9881-485922e8e07c&lang=en-us), [vuldb.com](https://vuldb.com/vuln/354614), [dell.com](https://www.dell.com/support/kbdoc/en-us/000444169/dsa-2026-157-dell-powerstore-t-security-update-for-multiple-vulnerabilities))
Fix: PowerStoreT OS version 4.3.1.1-2726662 or later. ([dell.com](https://www.dell.com/support/kbdoc/en-us/000444169/dsa-2026-157-dell-powerstore-t-security-update-for-multiple-vulnerabilities))
Action: Map CVE-2026-28265 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-28265)
Finding 13 — Multiple vulnerabilities in ZITADEL
What changed: CVE coverage: CVE-2026-56665, CVE-2026-56666. The cited advisories disclose: Missing Token Expiration Validation in JWT IdP Provider; Auto-linking by email: IdP-side email verification is not checked.
Technical evidence: CVE-2026-56665; CVSS v3.1 4.2; weakness CWE-613; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: For CVE-2026-56665, require the upstream external IdP to include the exp claim in every signed JWT. For CVE-2026-56666, disable email auto-linking with AUTO_LINKING_OPTION_UNSPECIFIED, or restrict it to trusted enterprise IdPs that enforce email verification. ([github.com](https://github.com/advisories/GHSA-v77h-2w3m-94hx), [github.com](https://github.com/advisories/GHSA-992q-9gwp-7r79))
Affected: CVE-2026-56665: ZITADEL 4.0.0 through 4.15.1 and 3.0.0 through 3.4.11, including RC versions. CVE-2026-56666: ZITADEL 4.0.0 through 4.15.2 and 3.0.0 through 3.4.12, including RC versions. ([github.com](https://github.com/advisories/GHSA-v77h-2w3m-94hx), [github.com](https://github.com/advisories/GHSA-992q-9gwp-7r79))
Action: Map CVE-2026-56665 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-v77h-2w3m-94hx)
Finding 14 — Checkov by Prisma Cloud: OS Command Injection Vulnerability
What changed: CVE-2026-0302 Checkov by Prisma Cloud: OS Command Injection Vulnerability. The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-0302; CVSS v4.0 1.1; weakness CWE-78; technical confidence High.
Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.
Analyst note: Palo Alto Networks reports that it is not aware of any malicious exploitation. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0302))
Affected: Checkov by Prisma Cloud 3.2.0 through 3.2.501. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0302))
Fix: Checkov by Prisma Cloud 3.2.502 or later. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0302))
Action: Map CVE-2026-0302 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0302)
Finding 15 — Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
What changed: CVE-2026-0303 Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File. The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-0303; CVSS v4.0 2.4; weakness CWE-829; technical confidence High.
Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-0303 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0303)