Executive assessment
Today's brief leads with Multiple vulnerabilities in Ivanti Neurons. All 7 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 01 leads because it is critical, has fixed versions listed for Cloud/SaaS and on-premises deployments, and includes an explicit interim control to remove internet exposure until patched. Patch order: Finding 01 (Critical Ivanti Neurons vulnerabilities with listed fixed versions and a clear control to remove on-premises internet exposure until a resolved version is installed); Finding 05 (High EMX Tecnologia Gestao X vulnerabilities with proof-of-concept exploitation and no fixed version listed, making the stated CSP and cookie controls the immediate action); Finding 04 (High SolarWinds ARM hard-coded key flaw enabling unauthenticated RCE, with version 2026.2.1 listed as fixed and network restriction controls provided); Finding 02 (High InDesign heap-based vulnerability with fixed Windows and macOS releases and controls for blocking or quarantining untrusted InDesign documents).
Also today: 5 more n8n CVEs (CVE-2026-72762, CVE-2026-72772, CVE-2026-72767, CVE-2026-72769, CVE-2026-85169) in the same disclosure wave as the n8n card of 2026-09-11; none reported exploited; carried as a note rather than a finding.
Finding 01 — Multiple vulnerabilities in Ivanti Neurons
What changed: CVE coverage: CVE-2026-12645, CVE-2026-12646. A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Technical evidence: CVE-2026-12645; CVSS v3.1 9.9; weakness CWE-862; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: For on-premises deployments, remove internet exposure until a resolved version is installed. ([hub.ivanti.com](https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US))
Fix: Cloud/SaaS 2026.2; on-premises the September 2026 Security Patch for 2025.2, 2025.3, 2025.4 or 2026.1, or version 2026.2. ([hub.ivanti.com](https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US))
Action: Map CVE-2026-12645 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-12645)
Finding 02 — InDesign Desktop: Heap-based Buffer Overflow
What changed: InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Technical evidence: CVE-2026-27238; CVSS v3.1 7.8; weakness CWE-122; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Block or quarantine InDesign documents from untrusted external sources, and filter .indd, .indt and .idml email attachments. Run InDesign as a non-privileged user. Adobe reports that it is not aware of any exploits in the wild for the issues addressed by APSB26-32. ([helpx.adobe.com](https://helpx.adobe.com/security/products/indesign/apsb26-32.html), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27238/), [cisecurity.org](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2026-034))
Affected: Adobe InDesign ID21.2 and earlier, and ID20.5.2 and earlier, on Windows and macOS. ([helpx.adobe.com](https://helpx.adobe.com/security/products/indesign/apsb26-32.html))
Fix: Adobe InDesign ID21.3 and ID20.5.3 for Windows and macOS. ([helpx.adobe.com](https://helpx.adobe.com/security/products/indesign/apsb26-32.html))
Panel assessment: Patch this week where InDesign is in use: exploitation needs a user to open a malicious file, but successful code execution runs as that user, so the blast radius is the user’s accessible documents, credentials and publishing assets rather than the application alone. (priority: this week)
Action: Map CVE-2026-27238 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-27238)
Finding 03 — Multiple vulnerabilities in Bransys ELD
What changed: Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960).
Technical evidence: CVE-2026-86520; CVSS v3.1 7.5; weakness CWE-798; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: CISA recommends minimising network exposure, placing systems and remote devices behind firewalls, and isolating them from business networks. Where remote access is required, use an up-to-date VPN. CISA reports that no known public exploitation specifically targeting these vulnerabilities has been reported to it. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01))
Fix: Android 11.00.00 or newer; iOS 1.1.54 or newer. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01))
Panel assessment: Patch this week: the issue is high severity because hard-coded credentials and cleartext transmission can enable unauthorised access, but the record says there is no known public exploitation, so this is not an emergency patch-now case. The likely path is use of embedded credentials or interception of sensitive traffic to reach telemetry data and firmware, making this a fleet-data and device-integrity risk rather than a generic enterprise compromise finding. (priority: this week)
Action: Map CVE-2026-86520 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01)
Finding 04 — SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
What changed: SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system.
Technical evidence: CVE-2026-28326; CVSS v3.1 8.8; weakness CWE-321; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Use IP whitelisting to restrict ARM ports, and keep ARM on a dedicated server that is neither public nor internet-facing. The Hacker News reports that SolarWinds makes no mention of the vulnerability being exploited in the wild. ([documentation.solarwinds.com](https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm), [thehackernews.com](https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html), [solarwinds.com](https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326))
Fix: SolarWinds Access Rights Manager 2026.2.1 ([solarwinds.com](https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326))
Action: Map CVE-2026-28326 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html)
Finding 05 — Multiple vulnerabilities in EMX Tecnologia Gestao X
What changed: CVE coverage: CVE-2026-79418, CVE-2026-79419. The cited advisories disclose: Business Suite 8.4 and earlier.
Technical evidence: CVE-2026-79418; CVSS v3.1 8.7; weakness CWE-79; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Apply Content Security Policy (CSP) to restrict unwanted script execution, and enable Secure and HttpOnly cookie flags. Miggo reports proof-of-concept exploitation for both CVEs. ([drive.google.com](https://drive.google.com/file/d/1mp-uS-tAthH9FAObfx1D3lOM7IIjRsmE/view?usp=sharing), [drive.google.com](https://drive.google.com/file/d/1QVH1MRo3G4KqmBORkhXITzcYmO_BDjWc/view), [miggo.io](https://www.miggo.io/vulnerability-database/cve/CVE-2026-79418), +1 more)
Action: Map CVE-2026-79418 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-79418)
Finding 06 — n8n: Exposure of Resource to Wrong Sphere
What changed: n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability.
Technical evidence: CVE-2026-72764; CVSS v4.0 5.8; weakness CWE-668; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Restrict n8n access to fully trusted users and disable built-in and external modules by unsetting NODE_FUNCTION_ALLOW_BUILTIN and NODE_FUNCTION_ALLOW_EXTERNAL. Where supported, use external runner mode with a dedicated runner per user or project. ([github.com](https://github.com/n8n-io/n8n/security/advisories/GHSA-9cmh-xcqm-5hqr), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-72764/))
Affected: n8n versions earlier than 1.123.67, 2.31.5, and 2.32.1. ([github.com](https://github.com/n8n-io/n8n/security/advisories/GHSA-9cmh-xcqm-5hqr))
Fix: n8n versions 1.123.67, 2.31.5, and 2.32.1. ([github.com](https://github.com/n8n-io/n8n/security/advisories/GHSA-9cmh-xcqm-5hqr))
Action: Map CVE-2026-72764 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-72764)
Finding 07 — Intel Transfer Learning Tool: Protection Mechanism Failure
What changed: Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege.
Technical evidence: CVE-2026-39452; CVSS v4.0 6.3; weakness CWE-693; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Uninstall Intel Transfer Learning Tool or discontinue its use as soon as possible. ([intel.com](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01499.html))
Fix: No fixed version is available; Intel is not releasing updates to mitigate the vulnerability. ([intel.com](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01499.html))
Action: Map CVE-2026-39452 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-39452)