Executive assessment
Today's brief leads with Ivanti Neurons: 2 further CVEs in the advisory covered on 2026-09-20. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 01 leads because it is the only critical finding, with fixes listed for on-premises and cloud deployments and an interim exposure-reduction control for unpatched on-premises systems; no exploitation is reported. Patch order: Finding 01 (It is the only critical finding, with listed fixes and a specific interim control for unpatched on-premises deployments); Finding 05 (It is high severity with PoC exploitation and no listed fix, with controls focused on trusted Redis connections and monitoring for the specified RangeError); Finding 10 (It is high severity with PoC exploitation and no listed fix, with controls to remove CSRF exemptions and unsafe handling of user-supplied input); Finding 11 (It is high severity and described as exploitable by an unauthenticated attacker, with no fixed version or controls listed); Finding 02 (It is high severity improper authentication, has a fixed @openclaw/voice-call version, and legacy users must migrate because no patched legacy package is published).
Also today: 5 more n8n CVEs (CVE-2026-72772, CVE-2026-85169, CVE-2026-72769, CVE-2026-72767, CVE-2026-72762) in the same disclosure wave as the n8n cards of 2026-09-11 and 2026-09-20; none reported exploited; carried as a note rather than a finding.
Finding 01 — Ivanti Neurons: 2 further CVEs in the advisory covered on 2026-09-20
What changed: Follow-up to the 2026-09-20 card. CVE coverage: CVE-2026-12647, CVE-2026-12650. A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Technical evidence: CVE-2026-12647; CVSS v3.1 9.9; weakness CWE-862; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: For on-premises deployments that cannot patch, remove Ivanti Neurons for ITSM from direct internet exposure. ([hub.ivanti.com](https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US), [cisecurity.org](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-ivanti-products-could-allow-for-arbitrary-code-execution_2026-093))
Affected: On-premises: 2025.2, 2025.3, 2025.4 and 2026.1. Cloud/SaaS: 2026.2. ([hub.ivanti.com](https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US))
Fix: On-premises: the September 2026 Security Patch for 2025.2, 2025.3, 2025.4 or 2026.1, or version 2026.2. Cloud/SaaS: 2026.2, applied across all cloud landscapes on 9 August 2026. ([hub.ivanti.com](https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US))
Action: Map CVE-2026-12647 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-12647)
Finding 02 — OpenClaw: Authentication Bypass by Spoofing
What changed: OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded- headers in reverse-proxy configurations that implicitly trust these headers.
Technical evidence: CVE-2026-28465; CVSS v4.0 8.2; weakness CWE-290; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is not immediately possible, strip Forwarded and X-Forwarded- headers at the edge so clients cannot supply them directly. TridentStack reports no known active exploitation and says the CVE is not in CISA's Known Exploited Vulnerabilities catalogue. ([github.com](https://github.com/openclaw/openclaw/security/advisories/GHSA-3m3q-x3gj-f79x), [tridentstack.com](https://tridentstack.com/cve/CVE-2026-28465))
Affected: @openclaw/voice-call versions before 2026.2.3; legacy @clawdbot/voice-call versions through 2026.1.24. ([github.com](https://github.com/openclaw/openclaw/security/advisories/GHSA-3m3q-x3gj-f79x))
Fix: @openclaw/voice-call 2026.2.3 and later; no patched legacy @clawdbot/voice-call version is published, so migrate to @openclaw/voice-call. ([github.com](https://github.com/openclaw/openclaw/security/advisories/GHSA-3m3q-x3gj-f79x))
Action: Map CVE-2026-28465 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-28465)
Finding 03 — Multiple vulnerabilities in Archer BE230
What changed: CVE coverage: CVE-2026-22221, CVE-2026-22223. An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code.
Technical evidence: CVE-2026-22221; CVSS v4.0 8.5; weakness CWE-78; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until firmware can be updated, disable VPN functionality if it is not required and isolate the router's administrative interface from untrusted network segments. CISA records exploitation as none for both CVEs. ([tp-link.com](https://www.tp-link.com/us/support/faq/4935/), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-22223/), [raw.githubusercontent.com](https://raw.githubusercontent.com/cisagov/vulnrichment/develop/2026/22xxx/CVE-2026-22221.json), +1 more)
Fix: Archer BE230: 1.2.4 Build 20251218 rel.70420 or later. Archer BE3600: (KR)_V1_1.2.2 Build 20260903, (EU)_V1_1.2.6 Build 20260617, or (USW)_V1.26_1.2.6 Build 20260617. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-22223/), [tp-link.com](https://www.tp-link.com/us/support/faq/4935/))
Action: Map CVE-2026-22221 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-22221)
Finding 04 — Keycloak: Authentication Bypass by Capture-replay
What changed: A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection.
Technical evidence: CVE-2026-90997; CVSS v3.1 7.4; weakness CWE-294; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Set the MySQL/MariaDB JDBC connection string to useAffectedRows=true and restart Keycloak for the change to take effect. Alternatively, disable Keycloak's stateless feature. ([access.redhat.com](https://access.redhat.com/security/cve/CVE-2026-90997), [github.com](https://github.com/keycloak/keycloak/security/advisories/GHSA-xpwp-2pcm-8xq3), [tri.opswat.com](https://tri.opswat.com/vulnerabilities/CVE-2026-90997))
Affected: Keycloak versions >= 26.7.0 and < 26.7.4. ([github.com](https://github.com/keycloak/keycloak/security/advisories/GHSA-xpwp-2pcm-8xq3))
Fix: Keycloak 26.7.4. ([github.com](https://github.com/keycloak/keycloak/security/advisories/GHSA-xpwp-2pcm-8xq3))
Action: Map CVE-2026-90997 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-90997)
Finding 05 — redis-parser: Uncontrolled Recursion
What changed: redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.
Technical evidence: CVE-2026-93435; CVSS v4.0 8.7; weakness CWE-674; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict clients to trusted Redis servers and protect Redis connections from on-path interference. Monitor for RangeError: Maximum call stack size exceeded and associated Node.js process termination. ([github.com](https://github.com/redis/ioredis/issues/2108))
Panel assessment: Patch this week if redis-parser is in use, because a proof-of-concept exists and the blast radius is application availability: crafted Redis responses can terminate the dependent Node.js process rather than returning a handled client error. (priority: this week)
Action: Map CVE-2026-93435 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-93435)
Finding 06 — Multiple vulnerabilities in Concrete CMS
What changed: Concrete CMS carries 3 CVEs across 2 advisories: SQL Injection; 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action. CVE coverage: CVE-2026-81901, CVE-2026-81902, CVE-2026-81895.
Technical evidence: CVE-2026-81901; CVSS v4.0 7.2; weakness CWE-862; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: If patching is delayed, block PUT requests to /ccm/api/1.0/pages/{cID} where operationally feasible, disable the pages:update scope on integrations that do not require it, and review block-removal permissions and logging. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-81901), [documentation.concretecms.org](https://documentation.concretecms.org/developers/rest-api/concrete-cms-rest-api-scopes), [cvefeed.io](https://cvefeed.io/vuln/detail/CVE-2026-81901), +3 more)
Affected: CVE-2026-81901 affects Concrete CMS 9.2.0 through 9.5.2; CVE-2026-81902 affects 9.0.0 through 9.5.2; Concrete CMS 5.0.0 through 9.5.2 ([cvefeed.io](https://cvefeed.io/vuln/detail/CVE-2026-81901), [cvefeed.io](https://cvefeed.io/vuln/detail/CVE-2026-81902), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-81895))
Fix: Concrete CMS 9.5.3 or later ([cvefeed.io](https://cvefeed.io/vuln/detail/CVE-2026-81901), [cvefeed.io](https://cvefeed.io/vuln/detail/CVE-2026-81902), [secalerts.co](https://secalerts.co/vulnerability/CVE-2026-81895))
Action: Map CVE-2026-81901 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-81901)
Finding 07 — Apple macOS: Out-of-bounds Write
What changed: Connecting to a malicious afpfs server may lead to kernel memory corruption. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6.
Technical evidence: CVE-2026-43815; CVSS v3.1 8.8; weakness CWE-787; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Block outbound TCP port 548 from unpatched Macs except to explicitly approved AFP servers, and monitor denied connection attempts. ([support.apple.com](https://support.apple.com/en-us/103229), [vi.strobes.co](https://vi.strobes.co/cve/CVE-2026-43815), [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-43815))
Affected: macOS 14.0 to before 14.8.8, 15.0 to before 15.7.8, and 26.0 to before 26.6. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-43815))
Action: Map CVE-2026-43815 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-43815)
Finding 08 — Apple iOS, iPadOS and macOS: Improper Restriction of Operations within the Bounds of a Memory Buffer
What changed: A local attacker may be able to cause unexpected system termination or corrupt kernel memory. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7.
Technical evidence: CVE-2026-84566; CVSS v3.1 8.4; weakness CWE-119; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is delayed, use application allowlisting to block unauthorised applications and audit system logs for signs of attempted exploitation. CISA-ADP reports exploitation as 'none'. ([vuldb.com](https://vuldb.com/cve/CVE-2026-84566), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-84566), [developer.apple.com](https://developer.apple.com/news/releases/), +1 more)
Affected: iOS/iPadOS: 0 to <26.7 and 0 to <27. macOS: 0 to <15.8, 0 to <26.7 and 0 to <27. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-84566))
Action: Map CVE-2026-84566 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-84566)
Finding 09 — vLLM: Missing Release of Memory after Effective Lifetime
What changed: vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
Technical evidence: CVE-2026-93436; CVSS v4.0 8.7; weakness CWE-401; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Rate-limit or reject requests specifying max_tokens=0 at a reverse proxy or gateway, and restrict inference API access to trusted networks or clients. If filtering is not feasible, temporarily avoid disaggregated NIXL mode; monitor decode-worker memory and configure alerting or automatic restart on abnormal growth. ([ionix.io](https://www.ionix.io/threat-center/cve-2026-93436/))
Affected: vLLM versions through 0.29.0 inclusive when deployed in disaggregated prefill/decode mode using the NIXL KV connector. ([ionix.io](https://www.ionix.io/threat-center/cve-2026-93436/))
Action: Map CVE-2026-93436 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-93436)
Finding 10 — django-page-cms: Cross-Site Request Forgery
What changed: django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks.
Technical evidence: CVE-2026-93456; CVSS v4.0 8.4; weakness CWE-352; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Remove @csrf_exempt from the five mutation views, sanitise content before storage, and remove mark_safe() from user-supplied input. ([github.com](https://github.com/batiste/django-page-cms/issues/244), [vulncheck.com](https://www.vulncheck.com/advisories/django-page-cms-through-2.0.13-csrf-via-admin-mutation-views))
Affected: django-page-cms versions up to and including 2.0.13. ([vulncheck.com](https://www.vulncheck.com/advisories/django-page-cms-through-2.0.13-csrf-via-admin-mutation-views))
Action: Map CVE-2026-93456 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-93456)
Finding 11 — Quarkus HTTP security: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
What changed: A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers.
Technical evidence: CVE-2026-87743; CVSS v3.1 7.5; weakness CWE-551; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Affected: Quarkus 3.27 and 3.33. ([bugzilla.redhat.com](https://bugzilla.redhat.com/show_bug.cgi?id=2530523))
Action: Map CVE-2026-87743 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-87743)
Finding 12 — ArcadeDB: Incorrect Authorization
What changed: ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privilege user can read or insert TimeSeries samples despite explicit deny rules by exploiting the missing type-name-based access check that causes permission lookups to fail open.
Technical evidence: CVE-2026-93593; CVSS v4.0 8.6; weakness CWE-863; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-93593 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-93593)
Finding 13 — IBM Cloud Pak for Data: Path Traversal
What changed: IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing dot-dot sequences (/../) to view arbitrary files on the system.
Technical evidence: CVE-2025-14753; CVSS v3.1 7.5; weakness CWE-22; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Affected: IBM Cloud Pak for Data 5.1.2 ([ibm.com](https://www.ibm.com/support/pages/node/7287141))
Fix: IBM Cloud Pak for Data 5.2.2 ([ibm.com](https://www.ibm.com/support/pages/node/7287141))
Action: Map CVE-2025-14753 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-14753)
Finding 14 — Multiple vulnerabilities in Google Chrome
What changed: CVE coverage: CVE-2026-91732, CVE-2026-91719.
Technical evidence: CVE-2026-91719; CVSS v3.1 4.3; weakness CWE-94; technical confidence Medium.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Restrict browsing to trusted destinations using enterprise web filtering until patches are deployed. Advise users to avoid clicking unsolicited links and to report suspicious pages that trigger browser errors or unexpected prompts. SentinelOne reports no public exploitation or proof of concept for CVE-2026-91719, and no publicly referenced proof of concept or CISA KEV listing for CVE-2026-91732. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-91732), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-91719), [hkcert.org](https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260916), +2 more)
Affected: Google Chrome prior to 153.0.8010.47. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-91732), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-91719))
Fix: Google Chrome 153.0.8010.47 or later on Linux, and 153.0.8010.47/.48 or later on macOS and Windows. ([hkcert.org](https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260916))
Action: Map CVE-2026-91719 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-91732)
Finding 15 — vm2: Improper Access Control
What changed: vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto']). The builtin sanitizer (sanitizeCryptoModule in lib/builtin.js) replaces crypto.setEngine but leaves crypto.setFips callable, and the readonly wrapper used to expose the host module does not localize side effects of forwarded host functions.
Technical evidence: CVE-2026-93604; CVSS v4.0 6.9; weakness CWE-284; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Remove crypto from NodeVM require.builtin allowlists wherever untrusted guest code is executed. ([github.com](https://github.com/patriksimek/vm2/security/advisories/GHSA-x3v6-43hc-82mc))
Affected: vm2 versions through 3.12.0. ([github.com](https://github.com/patriksimek/vm2/security/advisories/GHSA-x3v6-43hc-82mc))
Fix: vm2 3.12.1. ([github.com](https://github.com/patriksimek/vm2/security/advisories/GHSA-x3v6-43hc-82mc))
Action: Map CVE-2026-93604 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-93604)