CRITICAL 11 min read 29 Sep 2026

Multiple vulnerabilities in Citrix NetScaler: CERT-EU advisory 2026-014 Leads Today's Security Review

Threat Level: Critical Tags: cve-2026-88771, cve-2026-88778, cve-2026-88772, cve-2026-88773, cve-2026-88774, cve-2026-88775, cve-2026-88776, cve-2026-88777, cwe-20, cve-2026-6730

Key findings
01
Multiple vulnerabilities in Citrix NetScaler: CERT-EU advisory 2026-014
CRITICAL
Follow-up to the 2026-09-28 card. CERT-EU published advisory 2026-014. CVE coverage: CVE-2026-88771, CVE-2026-88778, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777.
02
IBM Concert: Buffer Copy without Checking Size of Input
CRITICAL
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system. The assigned identifier is CVE-2026-6730.
03
Apple iOS 26, macOS 26 and macOS 15: Out-of-bounds Write
HIGH
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The assigned identifier is CVE-2026-86950.
04
Multiple vulnerabilities in pdfminer
HIGH
It was discovered that pdfminer did not safely parse specially crafted PDF files. An attacker could possibly use these issues to execute arbitrary code. The assigned identifier is CVE-2025-64512.
05
Plasma Workspace: Insufficient Session Expiration
HIGH
Fabian Vogt discovered that Plasma Workspace did not properly authenticate local clients connecting to the session manager. A local attacker could possibly use this issue to execute arbitrary code as another user. The assigned identifier is CVE-2024-36041.
06
Knowns: Path Traversal
HIGH
GitHub Advisory Database published GHSA-9gfj-28hw-jchp for CVE-2026-86439 (Knowns): Path Traversal, CVSS v4.0 8.7; affected: Knowns versions from 0 up to, but excluding, 0.30.0.
07
CliInvoke: Argument Injection in Extensibility Runner Factory
HIGH
GitHub Advisory Database published GHSA-j73w-8hfr-4gc9 for CVE-2026-100369 (CliInvoke): Argument Injection, CVSS v3.1 8.4; affected: CliInvoke 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3.0.0-alpha.1 through 3.0.0-beta.1; AlastairLundy.CliInvoke 2.0.0-alpha.1 through 2.0.0.
08
CliInvoke.Specializations: OS Command Injection
HIGH
GitHub Advisory Database published GHSA-wrvw-254r-wpmv for CVE-2026-100368 (CliInvoke.Specializations): OS Command Injection, CVSS v3.1 8.4; affected: AlastairLundy.CliInvoke.Specializations >= 1.0.0-rc.1 and <= 1.6.1.1.
09
SCBE-AETHERMOORE: Missing Authentication for Critical Function
HIGH
GitHub Advisory Database published GHSA-q986-4x7x-gx39 for CVE-2026-57443 (SCBE-AETHERMOORE): Missing Authentication for Critical Function, CVSS v3.1 7.5; affected: SCBE-AETHERMOORE 4.2.1.
10
Multiple vulnerabilities in catdoc
HIGH
It was discovered that catdoc had an integer overflow when processing shared string tables in malformed spreadsheet files. An attacker could possibly use this issue to cause catdoc to crash or execute arbitrary code. The assigned identifier is CVE-2024-48877.
11
Multiple vulnerabilities in Angular SSR
HIGH
CVE coverage: CVE-2026-101895, CVE-2026-88058. The cited advisories disclose: Denial of Service via Infinite Loop on Malformed DOCTYPE; XSS via Unescaped Processing Instruction Nodes in Fallback Raw-Content Elements.
12
@openclaw/whatsapp: Missing Authorization
HIGH
@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced.
13
MCP Atlassian: Path Traversal
HIGH
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts a request without an Authorization identity and permits attacker-controlled Atlassian service headers, including X-Atlassian-Confluence-Url, to select a public attacker hostname or one allowed by MCP_ALLOWED_URL_DOMAINS.
14
Multiple vulnerabilities in OpenClaw
HIGH
OpenClaw carries 2 CVEs across 2 advisories: Incorrect Authorization. CVE coverage: CVE-2026-100541, CVE-2026-100535.
15
Adobe Connect: Improper Certificate Validation
MEDIUM
Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. The assigned identifier is CVE-2026-83964.

Executive assessment

Today's brief leads with Multiple vulnerabilities in Citrix NetScaler: CERT-EU advisory 2026-014. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Panel synthesis: Finding 01 leads because it is CRITICAL, exploitation is confirmed in the wild, and fixed NetScaler ADC and Gateway releases plus interim isolation controls are listed. Finding 03 is the closest follow-up because it is also exploited in the wild and has emergency Apple fixes available. Themes: In-the-wild exploitation; PoC-backed server and parser flaws; MCP and agent-tool exposure. Patch order: Finding 01 (CRITICAL with in-the-wild exploitation, named fixed NetScaler ADC and Gateway versions, and isolation or access-restriction controls available); Finding 03 (HIGH with in-the-wild exploitation and fixed iOS, iPadOS and macOS versions listed); Finding 02 (CRITICAL IBM Concert buffer overflow affecting versions 1.0.0 through 3.0.0, with IBM Concert Software 3.0.1.1 listed as fixed); Finding 13 (HIGH MCP Atlassian issue with PoC exploitation and immediate controls listed for READ_ONLY_MODE and stricter SSRF URL validation); Finding 06 (HIGH Knowns path traversal with PoC exploitation, a fixed version in 0.30.0, and controls to require a password and block MCP calls until patched).

Finding 01 — Multiple vulnerabilities in Citrix NetScaler: CERT-EU advisory 2026-014

What changed: Follow-up to the 2026-09-28 card. CERT-EU published advisory 2026-014. CVE coverage: CVE-2026-88771, CVE-2026-88778, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777. Citrix released NetScaler ADC and Gateway fixes for CVE-2026-88771 through CVE-2026-88778.

Technical evidence: CVE-2026-88771; CVSS v4.0 9.5; weakness CWE-20; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Analyst note: Isolate affected systems; temporarily disable service access with upstream firewalls, disable vulnerable components, or restrict access to organisational IP ranges. Continuously hunt for compromise and use NetScaler Console File Integrity Monitoring to detect unauthorised or unexpected file changes. CISA reports that threat actors are actively exploiting the vulnerabilities globally. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway), [rapid7.com](https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/), [cisa.gov](https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway))

Affected: NetScaler ADC and Gateway 14.1 before 14.1-73.37; NetScaler ADC and Gateway 13.1 before 13.1-64.23; NetScaler ADC FIPS before 14.1-73.37 FIPS; NetScaler ADC FIPS and NDcPP before 13.1-37.279. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway))

Fix: NetScaler ADC and Gateway 14.1-73.37 or later; NetScaler ADC and Gateway 13.1-64.23 or later in the 13.1 branch; NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS or later. ([rapid7.com](https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/))

Action: Map CVE-2026-88771 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: theregister.com](https://www.theregister.com/security/2026/09/28/certainties-in-life-death-taxes-and-critical-citrix-vulns-under-attack/5299369)

Finding 02 — IBM Concert: Buffer Copy without Checking Size of Input

What changed: IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

Technical evidence: CVE-2026-6730; CVSS v3.1 9.8; weakness CWE-120; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: CISA reports exploitation as none in its SSVC assessment. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-6730), [ibm.com](https://www.ibm.com/support/pages/node/7288830))

Fix: IBM Concert Software 3.0.1.1 ([ibm.com](https://www.ibm.com/support/pages/node/7288830))

Action: Map CVE-2026-6730 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-6730)

Finding 03 — Apple iOS 26, macOS 26 and macOS 15: Out-of-bounds Write

What changed: Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix.

Technical evidence: CVE-2026-86950; CVSS v3.1 8.8; weakness CWE-787; technical confidence Medium.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Analyst note: Apple reports that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals using iOS versions before iOS 27. ([support.apple.com](https://support.apple.com/en-us/149226), [app.opencve.io](https://app.opencve.io/cve/CVE-2026-86950), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-86950))

Affected: iOS and iPadOS versions before 26.7.1; macOS Sequoia 15 versions before 15.8.1; macOS Tahoe versions before 26.7.1. ([app.opencve.io](https://app.opencve.io/cve/CVE-2026-86950))

Fix: iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-86950))

Action: Map CVE-2026-86950 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation reported by the source, not independently corroborated

[Evidence source: isc.sans.edu](https://isc.sans.edu/diary/rss/33376)

Finding 04 — Multiple vulnerabilities in pdfminer

What changed: It was discovered that pdfminer did not safely parse specially crafted PDF files. An attacker could possibly use these issues to execute arbitrary code.

Technical evidence: CVE-2025-64512; CVSS v3.1 8.6; weakness CWE-502; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Restrict write access to every CMAP_PATH and default CMap directory so none is user- or world-writable. On Windows PDF-processing systems, block outbound SMB and WebDAV. CISA ADP Vulnrichment classifies exploitation as "poc" for both CVEs. ([github.com](https://github.com/pdfminer/pdfminer.six/security/advisories/GHSA-wf5f-4jwr-ppcp), [github.com](https://github.com/pdfminer/pdfminer.six/security/advisories/GHSA-f83h-ghpp-7wcc), [raw.githubusercontent.com](https://raw.githubusercontent.com/cisagov/vulnrichment/develop/2025/64xxx/CVE-2025-64512.json), +2 more)

Affected: Upstream pdfminer.six versions earlier than 20251230 are affected for both CVEs. ([github.com](https://github.com/pdfminer/pdfminer.six/security/advisories/GHSA-wf5f-4jwr-ppcp), [github.com](https://github.com/pdfminer/pdfminer.six/security/advisories/GHSA-f83h-ghpp-7wcc))

Fix: Patched versions >=20251230 ([github.com](https://github.com/pdfminer/pdfminer.six/security/advisories/GHSA-wf5f-4jwr-ppcp), [github.com](https://github.com/pdfminer/pdfminer.six/security/advisories/GHSA-f83h-ghpp-7wcc), [ubuntu.com](https://ubuntu.com/security/notices/USN-8837-1))

Action: Map CVE-2025-64512 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8837-1)

Finding 05 — Plasma Workspace: Insufficient Session Expiration

What changed: Fabian Vogt discovered that Plasma Workspace did not properly authenticate local clients connecting to the session manager. A local attacker could possibly use this issue to execute arbitrary code as another user.

Technical evidence: CVE-2024-36041; CVSS v3.1 7.3; weakness CWE-613; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Until remediation, restrict use of affected hosts to trusted local users. The CISA Coordinator's SSVC assessment reports exploitation as "none". ([kde.org](https://kde.org/info/security/advisory-20240531-1.txt), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2024-36041), [ubuntu.com](https://ubuntu.com/security/notices/USN-8829-1))

Affected: Plasma Workspace versions before 5.27.11.1 and Plasma 6.x versions before 6.0.5.1. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2024-36041))

Fix: Update plasma-workspace to 6.0.5.1; Update plasma-workspace to 5.27.11.1; 4:5.5.5.2-0ubuntu1.1+esm1 ([kde.org](https://kde.org/info/security/advisory-20240531-1.txt), [ubuntu.com](https://ubuntu.com/security/notices/USN-8829-1))

Action: Map CVE-2024-36041 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8829-1)

Finding 06 — Knowns: Path Traversal

What changed: GitHub Advisory Database published GHSA-9gfj-28hw-jchp for CVE-2026-86439 (Knowns): Path Traversal, CVSS v4.0 8.7; affected: Knowns versions from 0 up to, but excluding, 0.30.0.

Technical evidence: CVE-2026-86439; CVSS v4.0 8.7; weakness CWE-22; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Require a password and block MCP calls to the docs and memory tools until patched. Monitor for traversal sequences in path, folder, newPath and id arguments. GitHub Advisory Database publishes example traversal requests, including a docs.get path that escapes the project root. ([github.com](https://github.com/advisories/GHSA-9gfj-28hw-jchp), [vulncheck.com](https://www.vulncheck.com/advisories/knowns-before-0.30.0-path-traversal-via-mcp-doc-and-memory-tools))

Affected: Knowns versions from 0 up to, but excluding, 0.30.0. ([vulncheck.com](https://www.vulncheck.com/advisories/knowns-before-0.30.0-path-traversal-via-mcp-doc-and-memory-tools))

Fix: Knowns 0.30.0. ([github.com](https://github.com/advisories/GHSA-9gfj-28hw-jchp))

Action: Map CVE-2026-86439 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-9gfj-28hw-jchp)

Finding 07 — CliInvoke: Argument Injection in Extensibility Runner Factory

What changed: GitHub Advisory Database published GHSA-j73w-8hfr-4gc9 for CVE-2026-100369 (CliInvoke): Argument Injection, CVSS v3.1 8.4; affected: CliInvoke 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3.0.0-alpha.1 through 3.0.0-beta.1; AlastairLundy.CliInvoke 2.0.0-alpha.1 through 2.0.0.

Technical evidence: CVE-2026-100369; CVSS v3.1 8.4; weakness CWE-88; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Remove double quotes from targets and arguments; for shell runners, also remove shell metacharacters. Alternatively, bypass the vulnerable factory and construct ProcessConfiguration with an explicit ArgumentList. CISA ADP Vulnrichment reports exploitation as 'none'. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-100369))

Affected: CliInvoke 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3.0.0-alpha.1 through 3.0.0-beta.1; AlastairLundy.CliInvoke 2.0.0-alpha.1 through 2.0.0. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-100369))

Fix: CliInvoke 2.8.5, 2.9.4, 2.10.5, and 3.0.0-beta.2; AlastairLundy.CliInvoke 2.0.2. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-100369))

Action: Map CVE-2026-100369 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-j73w-8hfr-4gc9)

Finding 08 — CliInvoke.Specializations: OS Command Injection

What changed: GitHub Advisory Database published GHSA-wrvw-254r-wpmv for CVE-2026-100368 (CliInvoke.Specializations): OS Command Injection, CVSS v3.1 8.4; affected: AlastairLundy.CliInvoke.Specializations >= 1.0.0-rc.1 and <= 1.6.1.1. CliInvoke.Specializations >= 2.2.0 and <= 2.8.4, >= 2.9.0 and <= 2.9.3, >= 2.10.0 and <= 2.10.4.

Technical evidence: CVE-2026-100368; CVSS v3.1 8.4; weakness CWE-78; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Reject or strip double quotes from any target path or argument passed to the PowerShell/Cmd wrappers. On versions 2.2.0–2.9.2 and 3.0.0-alpha.1–alpha.4, also reject shell metacharacters including semicolons, pipes, ampersands, dollar signs, backticks and parentheses. ([github.com](https://github.com/advisories/GHSA-wrvw-254r-wpmv))

Affected: AlastairLundy.CliInvoke.Specializations >= 1.0.0-rc.1 and <= 1.6.1.1. CliInvoke.Specializations >= 2.2.0 and <= 2.8.4, >= 2.9.0 and <= 2.9.3, >= 2.10.0 and <= 2.10.4. ([github.com](https://github.com/advisories/GHSA-wrvw-254r-wpmv))

Fix: AlastairLundy.CliInvoke.Specializations 2.0.2; CliInvoke.Specializations 2.8.5, 2.9.4, 2.10.5 and 3.0.0-beta.1. ([github.com](https://github.com/advisories/GHSA-wrvw-254r-wpmv))

Action: Map CVE-2026-100368 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-wrvw-254r-wpmv)

Finding 09 — SCBE-AETHERMOORE: Missing Authentication for Critical Function

What changed: GitHub Advisory Database published GHSA-q986-4x7x-gx39 for CVE-2026-57443 (SCBE-AETHERMOORE): Missing Authentication for Critical Function, CVSS v3.1 7.5; affected: SCBE-AETHERMOORE 4.2.1.

Technical evidence: CVE-2026-57443; CVSS v3.1 7.5; weakness CWE-306; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Bind the API to 127.0.0.1 instead of 0.0.0.0 and restrict TCP/8100 to trusted management networks. Monitor access logs for unauthenticated POST /api/ops/check-email requests returning HTTP 200. SCBE-AETHERMOORE's GitHub Security Advisory includes a runnable PoC for the unauthenticated endpoint. ([github.com](https://github.com/issdandavis/SCBE-AETHERMOORE/security/advisories/GHSA-q986-4x7x-gx39))

Affected: SCBE-AETHERMOORE 4.2.1. ([github.com](https://github.com/issdandavis/SCBE-AETHERMOORE/security/advisories/GHSA-q986-4x7x-gx39))

Fix: SCBE-AETHERMOORE 4.3.0 and later. ([github.com](https://github.com/issdandavis/SCBE-AETHERMOORE/security/advisories/GHSA-q986-4x7x-gx39))

Action: Map CVE-2026-57443 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-q986-4x7x-gx39)

Finding 10 — Multiple vulnerabilities in catdoc

What changed: It was discovered that catdoc had an integer overflow when processing shared string tables in malformed spreadsheet files. An attacker could possibly use this issue to cause catdoc to crash or execute arbitrary code.

Technical evidence: CVE-2024-48877; CVSS v3.1 8.4; weakness CWE-680; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If patching must be deferred, block or quarantine untrusted spreadsheet and Office document files before catdoc or xls2csv processes them, and disable automated processing of such files. CISA ADP Vulnrichment reports proof-of-concept exploitation for both CVEs. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2024-48877), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2024-52035), [ubuntu.com](https://ubuntu.com/security/notices/USN-8838-1?format=md))

Affected: xls2csv 0.95 is affected by CVE-2024-48877; catdoc 0.95 is affected by CVE-2024-52035. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2024-48877), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2024-52035))

Fix: Ubuntu fixes are catdoc 1:0.95-5ubuntu0.24.04.1~esm1 for 24.04 LTS, 1:0.95-5ubuntu0.22.04.1~esm1 for 22.04 LTS, 1:0.95-4.1ubuntu0.20.04.1~esm1 for 20.04 LTS. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8838-1?format=md))

Action: Map CVE-2024-48877 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8838-1)

Finding 11 — Multiple vulnerabilities in Angular SSR

What changed: CVE coverage: CVE-2026-101895, CVE-2026-88058. The cited advisories disclose: Denial of Service via Infinite Loop on Malformed DOCTYPE; XSS via Unescaped Processing Instruction Nodes in Fallback Raw-Content Elements.

Technical evidence: CVE-2026-88058; CVSS v4.0 8.6; weakness CWE-79, CWE-116; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Strip or reject strings matching /^<!DOCTYPE/i before passing input to [innerHTML] during server-side rendering. Sanitise untrusted processing-instruction data by replacing < with &lt;. ([github.com](https://github.com/advisories/GHSA-f67j-2jqw-jpq7), [github.com](https://github.com/angular/angular/security/advisories/GHSA-j3r3-mxqp-r2p4))

Affected: CVE-2026-101895 affects @angular/platform-server <=19.2.25, >=20.0.0 <20.3.31, >=21.0.0 <21.2.23 and >=22.0.0 <22.1.6. CVE-2026-88058 affects <=19.2.25, >=20.0.0 <20.3.30. ([github.com](https://github.com/advisories/GHSA-f67j-2jqw-jpq7), [github.com](https://github.com/angular/angular/security/advisories/GHSA-j3r3-mxqp-r2p4))

Fix: CVE-2026-101895 is fixed in 20.3.31, 21.2.23 and 22.1.6. CVE-2026-88058 is fixed in 20.3.30, 21.2.22 and 22.1.4. ([github.com](https://github.com/advisories/GHSA-f67j-2jqw-jpq7), [github.com](https://github.com/angular/angular/security/advisories/GHSA-j3r3-mxqp-r2p4))

Action: Map CVE-2026-88058 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-f67j-2jqw-jpq7)

Finding 12 — @openclaw/whatsapp: Missing Authorization

What changed: @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR code for a configured account, disconnecting the Gateway's WhatsApp account and causing loss of availability.

Technical evidence: CVE-2026-100532; CVSS v4.0 7.2; weakness CWE-862; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Until upgraded, disable the WhatsApp login tool after setup, restrict agent access to owner-controlled conversations, and avoid exposing tool-capable agents to non-owner senders. ([github.com](https://github.com/openclaw/openclaw/security/advisories/GHSA-9m4p-cqp4-jppq))

Affected: @openclaw/whatsapp versions earlier than 2026.8.1. ([github.com](https://github.com/openclaw/openclaw/security/advisories/GHSA-9m4p-cqp4-jppq))

Fix: 2026.8.1 and later. ([github.com](https://github.com/openclaw/openclaw/security/advisories/GHSA-9m4p-cqp4-jppq))

Action: Map CVE-2026-100532 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-100532)

Finding 13 — MCP Atlassian: Path Traversal

What changed: MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts a request without an Authorization identity and permits attacker-controlled Atlassian service headers, including X-Atlassian-Confluence-Url, to select a public attacker hostname or one allowed by MCP_ALLOWED_URL_DOMAINS.

Technical evidence: CVE-2026-77246; CVSS v3.1 7.4; weakness CWE-22, CWE-200, CWE-441; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Set READ_ONLY_MODE=true on remotely reachable deployments. Reject header-based service URLs before fetcher construction using validate_url_for_ssrf with a strict allowlist. CISA ADP Vulnrichment reports proof-of-concept availability. ([github.com](https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-wv8v-v4c5-v75j), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/77xxx/CVE-2026-77246.json))

Action: Map CVE-2026-77246 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-77246)

Finding 14 — Multiple vulnerabilities in OpenClaw

What changed: OpenClaw carries 2 CVEs across 2 advisories: Incorrect Authorization. CVE coverage: CVE-2026-100541, CVE-2026-100535.

Technical evidence: CVE-2026-100535; CVSS v4.0 7.7; weakness CWE-863; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-100535 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-100535)

Finding 15 — Adobe Connect: Improper Certificate Validation

What changed: Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information.

Technical evidence: CVE-2026-83964; CVSS v3.1 6.2; weakness CWE-295; technical confidence Medium.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Analyst note: Adobe reports it is not aware of any exploits in the wild for any issue addressed by this update. ([helpx.adobe.com](https://helpx.adobe.com/security/products/connect/apsb26-150.html))

Affected: Adobe Connect 12.11 and earlier on Windows and macOS; Adobe Connect Android Mobile App 4.4 and earlier on Android. ([helpx.adobe.com](https://helpx.adobe.com/security/products/connect/apsb26-150.html))

Fix: Adobe Connect 12.12 for Windows and macOS; Adobe Connect Android Mobile App 4.5 for Android. ([helpx.adobe.com](https://helpx.adobe.com/security/products/connect/apsb26-150.html))

Action: Map CVE-2026-83964 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-83964)

cve-2024-36041cve-2024-48877cve-2025-64512cve-2026-100368cve-2026-100369cve-2026-100532cve-2026-100541cve-2026-101895cve-2026-57443cve-2026-6730

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.