CRITICAL 12 min read 15 Sep 2026

Multiple vulnerabilities in Cisco Secure Email Gateway Leads Today's Security Review

Threat Level: Critical Tags: cve-2026-20353, cve-2026-76440, cve-2026-76441, cve-2026-76442, cve-2026-76443, cve-2026-76461, cwe-664, secure-email-gateway, cve-2026-64397, cve-2025-22050

Key findings
01
Multiple vulnerabilities in Cisco Secure Email Gateway
CRITICAL
CVE coverage: CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442, CVE-2026-76443, CVE-2026-76461. The cited advisories disclose: Secure Email and Web Manager Security Hardening Release: September 2026; SQL Injection Vulnerability (2 advisories) — Secure Email Gateway.
02
Multiple vulnerabilities in Linux Kernel
CRITICAL
CVE coverage: CVE-2026-64397, CVE-2025-22050, CVE-2026-22999, CVE-2026-72196, CVE-2026-89688, CVE-2026-23413, CVE-2026-31583, CVE-2026-74465, CVE-2026-74565, CVE-2025-38416, CVE-2026-72463, CVE-2026-64265, CVE-2026-31719, CVE-2026-64046, CVE-2026-46227, CVE-2026-80994, CVE-2026-43040, CVE-2024-35887.
03
Multiple vulnerabilities in Chromium
CRITICAL
Chromium fixes 147 CVEs in one release: ANGLE (2 CVEs); DevTools (3 CVEs); WebPackaging (2 CVEs); Payments (3 CVEs); Core (2 CVEs); ANGLE (5 CVEs); Media (2 CVEs); WebRTC (2 CVEs); and 108 more.
04
USN-8749-1: CivetWeb vulnerabilities
HIGH
Ubuntu fixed two CivetWeb request-parsing vulnerabilities. CVE-2025-55763 can permit remote denial of service or arbitrary code execution on affected Ubuntu 22.04 and 24.04 systems, while CVE-2025-9648 can permit remote denial of service; updated packages are available for supported releases.
05
MISP: Uncontrolled Resource Consumption
HIGH
MISP versions through 2.5.45 permit unauthenticated or weakly constrained request paths to trigger persistent work without adequate input bounds or rate limiting.
06
Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation.
HIGH
Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5. The assigned identifier is CVE-2026-8303.
07
vLLM: Code Injection
HIGH
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes.
08
SPIP: SQL Injection
HIGH
SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unescaped when the target column is a date type and the supplied value matches the pattern of a word character followed by an open parenthesis.
09
Shopper: Authorization bypass in Filament bulk actions: Missing Authorization
HIGH
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-56827.
10
USN-8757-1: cgit vulnerability
HIGH
It was discovered that cgit incorrectly handled repository paths when HTTP cloning was enabled. A remote attacker could possibly use this issue to access files outside the repository and obtain sensitive information. The assigned identifier is CVE-2018-14912.
11
USN-8755-1: libvips vulnerability
HIGH
It was discovered that libvips incorrectly handled specially crafted TIFF images when saving them as HEIF images. An attacker could possibly use this issue to cause libvips to crash, resulting in a denial of service. The assigned identifier is CVE-2025-29769.
12
Multiple vulnerabilities in Tesseract
HIGH
CVE coverage: CVE-2026-88047, CVE-2026-88048. The cited advisories disclose: version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>> to extract a whitespace-delimited token into a fixed 61-byte stack buffer without setting a stream width; version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions.
13
Vulnerability in graphql-go
MEDIUM
graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. The assigned identifier is CVE-2026-40476.
14
Traefik: Authentication Bypass by Spoofing
MEDIUM
Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three distinct headers by Traefik, while backends that derive variable names from header names (CGI, WSGI, PHP, NGINX and others) collapse them into a single variable.
15
Multiple vulnerabilities in October CMS
LOW
CVE coverage: CVE-2026-46696, CVE-2026-49400. The cited advisories disclose: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls; PHP Object Injection via Backend Widget Session Storage.

Executive assessment

Today's brief leads with Multiple vulnerabilities in Cisco Secure Email Gateway. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Panel synthesis: Finding 01 should lead today because exploitation is in the wild, Cisco states there are no workarounds, and fixed releases are available. That makes it more urgent and actionable than the Linux Kernel item, where exploitation and fixed-version status are unknown. Themes: In-the-wild exploitation with fixes available; Critical Chromium browser-component updates; Exposure reduction where patching is incomplete. Patch order: Finding 01 (Exploitation is in the wild, Cisco states there are no workarounds, and fixed releases are available).

Also today: 4 more WordPress CVEs (CVE-2026-78175, CVE-2026-85200, CVE-2026-15451, CVE-2026-16482) in the same disclosure wave as the WordPress card of 2026-09-08; none reported exploited; carried as a note rather than a finding.

Also today: 2 more ZITADEL CVEs (CVE-2026-56668, CVE-2026-76081) in the same disclosure wave as the ZITADEL card of 2026-09-12; none reported exploited; carried as a note rather than a finding.

Finding 01 — Multiple vulnerabilities in Cisco Secure Email Gateway

What changed: CVE coverage: CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442, CVE-2026-76443, CVE-2026-76461. The cited advisories disclose: Secure Email and Web Manager Security Hardening Release: September 2026; SQL Injection Vulnerability (2 advisories) — Secure Email Gateway.

Technical evidence: CVE-2026-20353; CVSS v3.1 9.8; weakness CWE-664; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Analyst note: Cisco states there are no workarounds; until patching, prevent internet access where possible, otherwise restrict access to trusted hosts, disable HTTP/FTP and unnecessary services, and send logs externally. Review mail_logs for 'COPY.TO PROGRAM' and cross-check external network and firewall logs for suspicious activity. Cisco PSIRT reports active exploitation of CVE-2026-76461 in September 2026. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm))

Affected: CVE-2026-76461: Cisco AsyncOS for Secure Email Gateway release trains 15.5 and earlier, 16.0 and 16.5. CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442 and CVE-2026-76443: Secure Email G ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm))

Fix: CVE-2026-76461: 15.5.5-014, 16.0.4-302 and 16.5.0-780. The other five CVEs: 15.5.5-014 or 16.5.0-780; 16.0 must migrate to a fixed release. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm))

Action: Map CVE-2026-20353 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation reported by the source, not independently corroborated

[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-76461)

Finding 02 — Multiple vulnerabilities in Linux Kernel

What changed: CVE coverage: CVE-2026-64397, CVE-2025-22050, CVE-2026-22999, CVE-2026-72196, CVE-2026-89688, CVE-2026-23413, CVE-2026-31583, CVE-2026-74465, CVE-2026-74565, CVE-2025-38416, CVE-2026-72463, CVE-2026-64265, CVE-2026-31719, CVE-2026-64046, CVE-2026-46227, CVE-2026-80994, CVE-2026-43040, CVE-2024-35887. The cited advisories disclose: KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability; usbnet Driver Race Condition Privilege Escalation Vulnerability; QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability; NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability; NFSv4 Server Race Condition Remote Code Execution Vulnerability; Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability; eMPIA USB Device Driver Race Condition Code Execution Vulnerability; OpenvSwitch Race Condition Local Privilege Escalation Vulnerability; nftables Race Condition Local Privilege Escalation Vulnerability; NFC NCI UART Driver Race Condition Local Privilege Escalation Vulnerability; IPv6 VTI Subsystem Use-After-Free Local Privilege Escalation Vulnerability; FUSE Subsystem Race Condition Local Privilege Escalation Vulnerability; Crypto Subsystem Use-After-Free Local Privilege Escalation Vulnerability; TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability; SCTP Subsystem Race Condition Information Disclosure Vulnerability; Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerability; IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability; the following vulnerability has been resolved: ax25: fix use-after-free bugs caused by ax25_ds_del_timer When the ax25 device is detaching, the ax25_dev_device_down calls ax25_ds_del_timer to cleanup the slave_timer.

Technical evidence: CVE-2026-64397; CVSS v3.1 9.8; weakness CWE-416; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Disable KSMBD and nfsd where they are not required; otherwise restrict access to those services to trusted networks. ([zerodayinitiative.com](https://www.zerodayinitiative.com/advisories/ZDI-26-684/), [zerodayinitiative.com](https://www.zerodayinitiative.com/advisories/ZDI-26-695/), [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-64397), +1 more)

Affected: CVE-2026-64397: Debian bookworm linux 6.1.176-1 is vulnerable. CVE-2026-89688: Debian trixie linux 6.12.107-1 and forky/sid 7.1.13-1 are vulnerable. ([security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-64397), [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-89688))

Action: Map CVE-2026-64397 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-684/)

Finding 03 — Multiple vulnerabilities in Chromium

What changed: Chromium fixes 147 CVEs in one release: ANGLE (2 CVEs); DevTools (3 CVEs); WebPackaging (2 CVEs); Payments (3 CVEs); Core (2 CVEs); ANGLE (5 CVEs); Media (2 CVEs); WebRTC (2 CVEs); and 108 more. CVE coverage: CVE-2026-87527, CVE-2026-87529, CVE-2026-87455, CVE-2026-87470, CVE-2026-87609, CVE-2026-87526, CVE-2026-87654, CVE-2026-87646, CVE-2026-87528, CVE-2026-87494, CVE-2026-87500, CVE-2026-87650, CVE-2026-87637, CVE-2026-87616, CVE-2026-87510, CVE-2026-87553, CVE-2026-87479, CVE-2026-87480, CVE-2026-87564, CVE-2026-87612, CVE-2026-87572, CVE-2026-87636, CVE-2026-87542, CVE-2026-87460, CVE-2026-87588, CVE-2026-87433, CVE-2026-87506, CVE-2026-87585, CVE-2026-87625, CVE-2026-87657, CVE-2026-87587, CVE-2026-87569, CVE-2026-87606, CVE-2026-87601, CVE-2026-87628, CVE-2026-87608, CVE-2026-87530, CVE-2026-87578, CVE-2026-87554, CVE-2026-87443, CVE-2026-87435, CVE-2026-87429, CVE-2026-87590, CVE-2026-87565, CVE-2026-87437, CVE-2026-87513, CVE-2026-87548, CVE-2026-87600, CVE-2026-87441, CVE-2026-87472, CVE-2026-87445, CVE-2026-87535, CVE-2026-87642, CVE-2026-87541, CVE-2026-87454, CVE-2026-87550, CVE-2026-87475, CVE-2026-87632, CVE-2026-87630, CVE-2026-87635, CVE-2026-87496, CVE-2026-87631, CVE-2026-87557, CVE-2026-87469, CVE-2026-87523, CVE-2026-87511, CVE-2026-87573, CVE-2026-87449, CVE-2026-87490, CVE-2026-87593, CVE-2026-87497, CVE-2026-87546, CVE-2026-87559, CVE-2026-87538, CVE-2026-87622, CVE-2026-87495, CVE-2026-87592, CVE-2026-87462, CVE-2026-87543, CVE-2026-87653, CVE-2026-87599, CVE-2026-87655, CVE-2026-87658, CVE-2026-87605, CVE-2026-87627, CVE-2026-87563, CVE-2026-87567, CVE-2026-87568, CVE-2026-87551, CVE-2026-87615, CVE-2026-87641, CVE-2026-87571, CVE-2026-87434, CVE-2026-87456, CVE-2026-87451, CVE-2026-87521, CVE-2026-87498, CVE-2026-87647, CVE-2026-87531, CVE-2026-87525, CVE-2026-87512, CVE-2026-87648, CVE-2026-87533, CVE-2026-87617, CVE-2026-87448, CVE-2026-87634, CVE-2026-87639, CVE-2026-87558, CVE-2026-87474, CVE-2026-87581, CVE-2026-87504, CVE-2026-87524, CVE-2026-87602, CVE-2026-87604, CVE-2026-87621, CVE-2026-87586, CVE-2026-87596, CVE-2026-87638, CVE-2026-87440, CVE-2026-87430, CVE-2026-87579, CVE-2026-87487, CVE-2026-87493, CVE-2026-87603, CVE-2026-87611, CVE-2026-87537, CVE-2026-87431, CVE-2026-87514, CVE-2026-87633, CVE-2026-87457, CVE-2026-87467, CVE-2026-87439, CVE-2026-87574, CVE-2026-87556, CVE-2026-87560, CVE-2026-87458, CVE-2026-87484, CVE-2026-87507, CVE-2026-87649, CVE-2026-87532, CVE-2026-87645, CVE-2026-87656, CVE-2026-87501, CVE-2026-87624, CVE-2026-87583, CVE-2026-87461, CVE-2026-87477.

Technical evidence: CVE-2026-87455; CVSS v3.1 9.6; weakness CWE-416; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: As a temporary attack-surface reduction, enable the Disable3DAPIs policy in Chrome and Edge to prevent webpages from accessing WebGL; Edge also blocks Pepper 3D. ([chromeenterprise.google](https://chromeenterprise.google/policies/disable3-dap-is/), [learn.microsoft.com](https://learn.microsoft.com/en-us/deployedge/microsoft-edge-policies/disable3dapis), [chromereleases.googleblog.com](https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html), +27 more)

Affected: Both CVEs affect Google Chrome on Windows before 153.0.8010.36 ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-87512), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-87648), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-87634), +9 more)

Fix: Google Chrome 153.0.8010.36 or later on Linux, and 153.0.8010.36/.37 or later on Mac and Windows; Google Chrome 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac; Microsoft Edge 153.0.42 ([hkcert.org](https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260910), [chromereleases.googleblog.com](https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html), [msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87634), +3 more)

Action: Map CVE-2026-87455 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: chromereleases.googleblog.com](https://chromereleases.googleblog.com/2026)

Finding 04 — USN-8749-1: CivetWeb vulnerabilities

What changed: Ubuntu fixed two CivetWeb request-parsing vulnerabilities. CVE-2025-55763 can permit remote denial of service or arbitrary code execution on affected Ubuntu 22.04 and 24.04 systems, while CVE-2025-9648 can permit remote denial of service; updated packages are available for supported releases.

Technical evidence: CVE-2025-55763; CVSS v3.1 7.5; weakness CWE-121; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Until patching, restrict CivetWeb services to trusted networks and place them behind a WAF or reverse proxy that rejects excessively long URIs. For CVE-2025-9648, drop POST bodies containing null bytes and disable unneeded form-handling endpoints. The krispybyte GitHub repository provides a CVE-2025-55763 PoC that crashes the server. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2025-55763/), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2025-9648/), [github.com](https://github.com/krispybyte/CVE-2025-55763), +3 more)

Affected: CVE-2025-55763 affects CivetWeb 1.14 through 1.16; CVE-2025-9648 affects CivetWeb 1.10 through 1.16, but not the vendor's pre-built standalone executable. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2025-55763), [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-9648))

Fix: For civetweb, libcivetweb-dev and libcivetweb1: Ubuntu 26.04 LTS fixes are 1.16+dfsg-3ubuntu0.1; Ubuntu 24.04 LTS fixes are 1.16+dfsg-1ubuntu0.1; Ubuntu 22.04 LTS fixes are 1.15+dfsg-3ubuntu0.1~esm1 v ([linuxsecurity.com](https://linuxsecurity.com/advisories/ubuntu/ubuntu-8749-1-civetweb))

Action: Map CVE-2025-55763 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8749-1)

Finding 05 — MISP: Uncontrolled Resource Consumption

What changed: MISP versions through 2.5.45 permit unauthenticated or weakly constrained request paths to trigger persistent work without adequate input bounds or rate limiting. The fix bounds and validates email input, adds a per-source pre-authentication request budget and cooldowns, and enforces POST/CSRF controls on API-access requests.

Technical evidence: CVE-2026-86452; CVSS v4.0 8.7; weakness CWE-400; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Rate-limit requests per source IP at a reverse proxy or WAF to users/forgot and the API-access-request endpoint. Monitor abnormal request volumes to unauthenticated mail-related endpoints. ([ionix.io](https://www.ionix.io/threat-center/cve-2026-86452/), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/86xxx/CVE-2026-86452.json))

Action: Map CVE-2026-86452 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-86452)

Finding 06 — Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation.

What changed: Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.

Technical evidence: CVE-2026-8303; CVSS v3.1 7.8; weakness CWE-266; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Remove tr.org.pardus.pkexec.pardus-software-sysaction from pardus-software-group.rules until patched. Monitor logs for exploit probes, errors, authentication anomalies or suspicious child processes. SOCRadar reports six public PoC repositories, with none marked weaponised in its dataset. ([github.com](https://github.com/pardus/pardus-software/commit/dca18b8c2c2db96bd6b9a447506fa75b62451fca), [socradar.io](https://socradar.io/free-tools/cve-radar/CVE-2026-8303), [siberguvenlik.gov.tr](https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1080))

Fix: 1.0.5 and later. ([siberguvenlik.gov.tr](https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1080))

Action: Map CVE-2026-8303 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-8303)

Finding 07 — vLLM: Code Injection

What changed: vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

Technical evidence: CVE-2026-90553; CVSS v4.0 8.5; weakness CWE-94; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If upgrading cannot happen immediately, avoid loading untrusted LlavaOnevision2 models; trust_remote_code=False is not an effective mitigation for this processor loader. AI Stack Current reports that the sources it reviewed do not report exploitation in the wild. ([secalerts.co](https://secalerts.co/vulnerability/CVE-2026-90553), [aistackcurrent.com](https://aistackcurrent.com/news/vllm-0-28-security-boundary-fixes/), [github.com](https://github.com/vllm-project/vllm/security/advisories/GHSA-3c86-2m5g-59q7))

Fix: vLLM 0.28.0 and later. ([github.com](https://github.com/vllm-project/vllm/security/advisories/GHSA-3c86-2m5g-59q7))

Action: Map CVE-2026-90553 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-90553)

Finding 08 — SPIP: SQL Injection

What changed: SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unescaped when the target column is a date type and the supplied value matches the pattern of a word character followed by an open parenthesis. The cited source identifies the affected product and the available advisory or remediation status.

Technical evidence: CVE-2026-72708; CVSS v4.0 8.7; weakness CWE-89; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Restrict or disable public access to sitemap.xml.html at the web server or WAF layer. Monitor anomalous requests containing SQL injection patterns targeting the annee parameter. ([ionix.io](https://www.ionix.io/threat-center/cve-2026-72708/), [vulncheck.com](https://www.vulncheck.com/advisories/spip-unauthenticated-sql-injection-via-sitemap-annee-parameter), [blog.spip.net](https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html))

Affected: SPIP versions before 4.4.18. ([vulncheck.com](https://www.vulncheck.com/advisories/spip-unauthenticated-sql-injection-via-sitemap-annee-parameter))

Fix: SPIP 4.4.18. ([blog.spip.net](https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html))

Action: Map CVE-2026-72708 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-72708)

Finding 09 — Shopper: Authorization bypass in Filament bulk actions: Missing Authorization

What changed: Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-56827.

Technical evidence: CVE-2026-56827; CVSS v3.1 8.1; weakness CWE-862; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Remove browse-only staff roles until patched, or restrict network access to the Livewire update endpoint. The Shopper maintainer's GitHub security advisory reports a seven-test proof of concept that passed against master at commit ac9a760. ([securelayer7.net](https://securelayer7.net/lab/cve-2026-56827-shopper-filament-bulk-action-missing-authorization), [github.com](https://github.com/shopperlabs/shopper/security/advisories/GHSA-243p-f3cv-c5wh))

Affected: Versions earlier than 2.9.2. ([github.com](https://github.com/shopperlabs/shopper/security/advisories/GHSA-243p-f3cv-c5wh))

Fix: Version 2.9.2. ([github.com](https://github.com/shopperlabs/shopper/security/advisories/GHSA-243p-f3cv-c5wh))

Action: Map CVE-2026-56827 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-243p-f3cv-c5wh)

Finding 10 — USN-8757-1: cgit vulnerability

What changed: It was discovered that cgit incorrectly handled repository paths when HTTP cloning was enabled. A remote attacker could possibly use this issue to access files outside the repository and obtain sensitive information.

Technical evidence: CVE-2018-14912; CVSS v3.1 7.5; weakness CWE-22; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Disable HTTP cloning by setting enable-http-clone=0. Block or alert on cgit /objects/ requests whose path parameter contains directory-traversal sequences such as ../. ([security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2018-14912), [kevintel.com](https://kevintel.com/CVE-2018-14912), [suse.com](https://www.suse.com/security/cve/CVE-2018-14912.html), +1 more)

Affected: Upstream cgit versions before 1.2.1. ([suse.com](https://www.suse.com/security/cve/CVE-2018-14912.html))

Action: Map CVE-2018-14912 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8757-1)

Finding 11 — USN-8755-1: libvips vulnerability

What changed: It was discovered that libvips incorrectly handled specially crafted TIFF images when saving them as HEIF images. An attacker could possibly use this issue to cause libvips to crash, resulting in a denial of service.

Technical evidence: CVE-2025-29769; CVSS v4.0 8.5; weakness CWE-122; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Block the VipsForeignSaveHeif operation using vips_operation_block_set. OSS-Fuzz reports a reproducible testcase for the flaw. ([github.com](https://github.com/libvips/libvips/security/advisories/GHSA-f8r8-43hh-rghm), [issues.oss-fuzz.com](https://issues.oss-fuzz.com/issues/396460413))

Affected: libvips versions 8.16.0 and earlier. ([github.com](https://github.com/libvips/libvips/security/advisories/GHSA-f8r8-43hh-rghm))

Fix: libvips 8.16.1 and later. ([github.com](https://github.com/libvips/libvips/security/advisories/GHSA-f8r8-43hh-rghm))

Action: Map CVE-2025-29769 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8755-1)

Finding 12 — Multiple vulnerabilities in Tesseract

What changed: CVE coverage: CVE-2026-88047, CVE-2026-88048. The cited advisories disclose: version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>> to extract a whitespace-delimited token into a fixed 61-byte stack buffer without setting a stream width; version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions.

Technical evidence: CVE-2026-88047; CVSS v4.0 8.6; weakness CWE-121; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-88047 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-88047)

Finding 13 — Vulnerability in graphql-go

What changed: graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name.

Technical evidence: CVE-2026-40476; CVSS v4.0 6.9; weakness CWE-407; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-40476 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-40476)

Finding 14 — Traefik: Authentication Bypass by Spoofing

What changed: Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three distinct headers by Traefik, while backends that derive variable names from header names (CGI, WSGI, PHP, NGINX and others) collapse them into a single variable.

Technical evidence: CVE-2026-88879; CVSS v4.0 5.3; weakness CWE-290; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-88879 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-88879)

Finding 15 — Multiple vulnerabilities in October CMS

What changed: CVE coverage: CVE-2026-46696, CVE-2026-49400. The cited advisories disclose: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls; PHP Object Injection via Backend Widget Session Storage.

Technical evidence: CVE-2026-46696; CVSS v3.1 3.3; weakness CWE-269, CWE-284; technical confidence High.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-46696 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits:** fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-xv9m-fm3w-8w5x)

cve-2018-14912cve-2025-22050cve-2025-29769cve-2025-55763cve-2026-20353cve-2026-40476cve-2026-46696cve-2026-56827cve-2026-64397cve-2026-72708

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.