Executive assessment
Today's brief leads with N-able N-central: Deserialization of Untrusted Data. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: N-able N-central (Finding 01) leads: CRITICAL severity with in-the-wild exploitation and no available patch—immediate investigation and containment required. Patch order: Finding 01 (CRITICAL, in-the-wild, no patch available. Apply network restrictions and MFA to N-central immediately); Finding 11 (HIGH, in-the-wild GitHub Actions tj-actions; fix available (v46+). Upgrade or pin to commit hash per controls); Finding 12 (HIGH, in-the-wild Roundcube code injection; patches available (1.6.16, 1.7.1). Disable virtuser_query plugin or upgrade); Finding 02 (CRITICAL TeamCity RCE, unknown exploitation, no patch available. Restrict HTTP(S) access to trusted networks immediately); Finding 06 (CRITICAL Octavia, no exploitation reported, patches available (Ubuntu packages). Apply security updates).
Also today: 2 more ZITADEL CVEs (CVE-2026-85056, CVE-2026-85057) in the same disclosure wave as the ZITADEL card of 2026-09-12; none reported exploited; carried as a note rather than a finding.
Finding 01 — N-able N-central: Deserialization of Untrusted Data
What changed: Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code. This issue affects N-central: before 2025.3.1.
Technical evidence: CVE-2025-8875; CVSS v4.0 9.4; weakness CWE-502; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Restrict network access to N-central servers to trusted networks only using firewall rules; implement multi-factor authentication for all accounts with elevated privileges and isolate N-central infrastructure from broader client networks using strict network segmentation. CISA added CVE-2025-8875 to the Known Exploited Vulnerabilities catalogue on August 13, 2025, confirming active exploitation. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-8875), [status.n-able.com](https://status.n-able.com/2025/08/13/announcing-the-ga-of-n-central-2025-3-1/), [status.n-able.com](https://status.n-able.com/2025/08/13/n-central-2024-6-hf2/), +2 more)
Affected: N-central versions before 2025.3.1 ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-8875))
Action: Map CVE-2025-8875 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-8875)
Finding 02 — CISA: Ransomware gangs now exploiting critical TeamCity flaw
What changed: CISA now flags CVE-2026-63077 as used in ransomware campaigns. The critical TeamCity On-Premises authentication bypass permits unauthenticated operating-system command execution and can expose credentials or compromise downstream build artifacts.
Technical evidence: CVE-2026-63077; CVSS v3.1 9.8; weakness CWE-502; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Restrict HTTP(S) access to TeamCity servers to trusted networks only, or require VPN connections as an immediate compensating control while patches are applied.[2][4] Consider implementing WAF or firewall rules to limit exposure to the agent polling endpoints. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw), [blog.jetbrains.com](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077), [rapid7.com](https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077), +1 more)
Affected: All TeamCity On-Premises versions released before the patched versions.[2] ([blog.jetbrains.com](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077))
Panel assessment: Patch immediately: CISA confirms active ransomware exploitation of an unauthenticated remote-code-execution flaw affecting all TeamCity On-Premises versions. Unauthenticated HTTP requests trigger remote code execution, exposing CI/CD credentials and compromising build artefacts. First: verify whether the instance is internet-reachable; if yes, apply immediate network restrictions (VPN, trusted-network access only) as a temporary control. (priority: patch now)
Action: Map CVE-2026-63077 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/)
Finding 03 — Moodle: Cross-Site Request Forgery
What changed: It was discovered that Moodle did not properly restrict URLs. An authenticated user could possibly use this issue to perform a server-side request forgery attack and expose sensitive information.
Technical evidence: CVE-2019-3809; CVSS v3.1 10.0; weakness CWE-352; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Ensure firewall rules effectively protect other internal hosts and ports from unauthorised access.[3] Strobes VI reports: 'No known public exploits'.[4] ([ubuntu.com](https://ubuntu.com/security/notices/USN-8805-1), [cve.mitre.org](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3809), [moodle.org](https://moodle.org/mod/forum/discuss.php?d=381229#p1536766), +2 more)
Affected: Moodle versions 3.1 to 3.1.15 and earlier unsupported versions.[3] ([moodle.org](https://moodle.org/mod/forum/discuss.php?d=381229#p1536766))
Fix: Moodle 3.1.16; Ubuntu: moodle 3.0.3+dfsg-0ubuntu1+esm1 for bionic and xenial.[1] ([moodle.org](https://moodle.org/mod/forum/discuss.php?d=381229#p1536766), [ubuntu.com](https://ubuntu.com/security/notices/USN-8805-1))
Action: Map CVE-2019-3809 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8805-1)
Finding 04 — Multiple vulnerabilities in RTI Connext Professional
What changed: CVE coverage: CVE-2025-1252, CVE-2025-1254, CVE-2026-2467, CVE-2026-2674, CVE-2026-30799. Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.
Technical evidence: CVE-2026-2467; CVSS v4.0 9.2; weakness CWE-122; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Protect access to the file system from which Connext applications are loading license files.[1] ([community.rti.com](https://community.rti.com/static/documentation/connext-dds/current/doc/vulnerabilities/))
Affected: Connext Professional 7.4.0 before 7.5.0, 7.0.0 before 7.3.0.7, 6.1.0 before 6.1.2.23, 6.0.0 before 6.0.1.42, 5.3.0 before 5.3.x, 5.2.0 before 5.2.x, 4.4d before 5.1.x[1] ([community.rti.com](https://community.rti.com/static/documentation/connext-dds/current/doc/vulnerabilities/))
Action: Map CVE-2026-2467 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-1252)
Finding 05 — SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
What changed: The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication. (Unconfirmed, single-source.)
Technical evidence: CVE-2026-28324; CVSS v3.1 9.8; weakness CWE-345; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict network access to SolarWinds management services using firewalls and allowlists.[2] Remove unnecessary internet exposure from SolarWinds servers and audit configurations using non-default or less secure communication settings.[2] SecurityWeek reports: 'SolarWinds makes no mention of any of these security defects being exploited in the wild.'[1] ([securityweek.com](https://www.securityweek.com/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted/), [gbhackers.com](https://gbhackers.com/solarwinds-observability-flaws/), [cybersecuritynews.com](https://cybersecuritynews.com/solarwinds-flaws-execute-code-on-observability-servers/), +1 more)
Action: Map CVE-2026-28324 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: securityweek.com](https://www.securityweek.com/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted/)
Finding 06 — Multiple vulnerabilities in Octavia
What changed: It was discovered that Octavia did not properly validate TLS cipher string fields in the Amphora provider driver. An authenticated attacker who owns a TLS-enabled load balancer could possibly use this issue to inject arbitrary HAProxy configuration directives.
Technical evidence: CVE-2026-94572; CVSS v4.0 9.4; weakness CWE-94; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict API access to trusted IP ranges and enforce least-privilege for load balancer management; deploy Web Application Firewalls or custom OpenStack middleware to inspect configuration payloads. No public exploit code confirmed; not listed in CISA Known Exploited Vulnerabilities catalogue as of 24 September 2026. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8814-1), [vuldb.com](https://vuldb.com/cve/CVE-2026-94572), [thehackerwire.com](https://www.thehackerwire.com/vulnerability/CVE-2026-94572/), +2 more)
Affected: Ubuntu 26.04 (before 1:18.0.0-0ubuntu2.1); Ubuntu 24.04 (before 1:14.0.0-0ubuntu1.6); Ubuntu 22.04 (before 1:10.1.1-0ubuntu1.5). OpenStack Octavia: >=0.8.0 <16.1.0, ==17.0.0, ==18.0.0 ([ubuntu.com](https://ubuntu.com/security/notices/USN-8814-1), [security.openstack.org](https://security.openstack.org/ossa/OSSA-2026-039.html))
Fix: Ubuntu 26.04: 1:18.0.0-0ubuntu2.1; Ubuntu 24.04: 1:14.0.0-0ubuntu1.6; Ubuntu 22.04: 1:10.1.1-0ubuntu1.5 ([ubuntu.com](https://ubuntu.com/security/notices/USN-8814-1))
Action: Map CVE-2026-94572 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8814-1)
Finding 07 — SunEditor: Critical XSS vulnerability - sanitizer bypass
What changed: GitHub Advisory Database published GHSA-6rf4-v2fh-m6p4 for CVE-2026-59167 (SunEditor): Cross-site Scripting, CVSS v3.1 10; affected: SunEditor versions <= 2.47.10.
Technical evidence: CVE-2026-59167; CVSS v3.1 10; weakness CWE-79; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Normalize DOM elements before sanitisation; explicitly reject or unwrap unknown/namespaced tags; strip all event-handler attributes from all elements.[1] Re-validate sanitised output after browser DOM parsing; add regression tests for namespaced/custom tag payloads.[1] One proof-of-concept exploit is available on GitHub; no evidence of proof of exploitation at the moment.[2] ([github.com](https://github.com/advisories/GHSA-6rf4-v2fh-m6p4), [feedly.com](https://feedly.com/cve/CVE-2026-59167))
Affected: SunEditor versions <= 2.47.10 ([github.com](https://github.com/advisories/GHSA-6rf4-v2fh-m6p4))
Fix: 2.47.11 ([github.com](https://github.com/advisories/GHSA-6rf4-v2fh-m6p4))
Action: Map CVE-2026-59167 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-6rf4-v2fh-m6p4)
Finding 08 — http4s-scala-xml has an XML External Entity (XXE) processing issue
What changed: GitHub Advisory Database published GHSA-cjx3-73hr-rpw7 for CVE-2026-61741 (http4s-scala-xml): Improper Restriction of XML External Entity Reference, CVSS v3.1 9.3.
Technical evidence: CVE-2026-61741; CVSS v3.1 9.3; weakness CWE-611; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-61741 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-cjx3-73hr-rpw7)
Finding 09 — ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass.
What changed: GitHub Advisory Database published GHSA-w3rp-4cm2-4wgc for CVE-2026-61604 (ixo Blockchain x/bonds): Improper Authorization, CVSS v4.0 9.3.
Technical evidence: CVE-2026-61604; CVSS v4.0 9.3; weakness CWE-285, CWE-862; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-61604 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-w3rp-4cm2-4wgc)
Finding 10 — Decepticon: Improper Neutralization of Special Elements in Output
What changed: GitHub Advisory Database published GHSA-g5f9-3xfg-p9mf for CVE-2026-61732 (Decepticon): Improper Neutralization of Special Elements in Output, CVSS v3.1 10.
Technical evidence: CVE-2026-61732; CVSS v3.1 10; weakness CWE-74; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-61732 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-g5f9-3xfg-p9mf)
Finding 11 — tj-actions changed-files: Embedded Malicious Code
What changed: tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
Technical evidence: CVE-2025-30066; CVSS v3.1 8.6; weakness CWE-506; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Pin all GitHub Actions to specific commit hashes instead of version tags.[3] Audit past workflow runs; delete affected workflow logs to remove secrets and consider rotating any credentials used by affected workflows.[3] ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-30066), [blog.gitguardian.com](https://blog.gitguardian.com/compromised-tj-actions/), [wiz.io](https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066))
Affected: All versions before 46 were affected on 2025-03-14 and 2025-03-15; tags v1 through v45.0.7 were modified by the threat actor to point to malicious commit 0e58ed8.[1] ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-30066))
Fix: Version 46 and later; fixed commit ed68ef82c095e0d48ec87eccea555d944a631a4c.[1] ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-30066))
Panel assessment: Patch immediately: actively-exploited supply-chain attack (CVSS 8.6, CISA KEV) affecting all changed-files versions before 46; exfiltration proven across public repositories. Malicious code injected into version tags v1–v45.0.7 on 2025-03-14 and 2025-03-15 reads GitHub Actions logs during workflow execution and exfiltrates AWS keys, GitHub PATs, and npm tokens. (priority: patch now)
Action: Map CVE-2025-30066 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-30066)
Finding 12 — Hackers now exploit critical Roundcube flaw in code injection attacks
What changed: The Canadian Centre for Cyber Security says CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin, is now exploited in the wild; fixed versions are 1.6.16 and 1.7.1. (Unconfirmed, single-source.)
Technical evidence: CVE-2026-48842; CVSS v3.1 8.1; weakness CWE-89; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Disable or remove the virtuser_query plugin to eliminate the attack vector.[1] Apply the security update to versions 1.6.16 and 1.7.1. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/), [cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503), [roundcube.net](https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1))
Affected: Roundcube Webmail versions prior to 1.6.16 and 1.7.1.[2] ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503))
Fix: Roundcube Webmail 1.6.16 and 1.7.1.[2][3] ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503), [roundcube.net](https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1))
Action: Map CVE-2026-48842 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/)
Finding 13 — OpenStack Swift: Loop with Unreachable Exit Condition
What changed: It was discovered that OpenStack Swift incorrectly handled truncated aws-chunked PUT request bodies in its s3api middleware. An authenticated attacker could possibly use this issue to cause OpenStack Swift to use excessive resources, leading to a denial of service.
Technical evidence: CVE-2026-49017; CVSS v4.0 7.1; weakness CWE-835; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: No public PoC or in-the-wild exploitation reported. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8821-1), [app.opencve.io](https://app.opencve.io/cve/CVE-2026-49017), [github.com](https://github.com/advisories/GHSA-g7jq-j257-rww2), +1 more)
Fix: 2.36.2 and 2.37.2 ([ubuntu.com](https://ubuntu.com/security/notices/USN-8821-1), [github.com](https://github.com/advisories/GHSA-g7jq-j257-rww2))
Action: Map CVE-2026-49017 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8821-1)
Finding 14 — Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
What changed: CVE coverage: CVE-2026-63498, CVE-2026-63493. GitHub Advisory Database published GHSA-396x-xmvh-p563 for CVE-2026-63498 (Snipe-IT): Cross-site Scripting, CVSS v3.1 8.7; affected: Snipe-IT versions before 8.7.0.
Technical evidence: CVE-2026-63498; CVSS v3.1 8.7; weakness CWE-79; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict XML uploads via config/filesystems.php or remove 'unsafe-inline' and 'unsafe-eval' from the default CSP in SecurityHeaders middleware. Monitor API requests to GET /api/v1//files/ with ?inline=true parameter. ([github.com](https://github.com/advisories/GHSA-396x-xmvh-p563), [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-63493))
Affected: Snipe-IT versions before 8.7.0 ([github.com](https://github.com/advisories/GHSA-396x-xmvh-p563))
Fix: 8.7.0 ([github.com](https://github.com/advisories/GHSA-396x-xmvh-p563))
Action: Map CVE-2026-63498 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-396x-xmvh-p563)
Finding 15 — MongoDB C Driver: Improper Validation of Specified Index, Position, or Offset in Input
What changed: The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).
Technical evidence: CVE-2026-9100; CVSS v4.0 6; weakness CWE-1285; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-9100 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-9100)