Executive assessment
Today's brief leads with Multiple vulnerabilities in FreeIPMI. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Patch order: Finding 03 (Critical VIVOTEK camera firmware has PoC exploitation; minimise internet exposure and isolate camera systems while no fixed version is listed); Finding 06 (Critical path traversal in @xhmikosr/decompress has fixed versions 11.1.4 and 10.2.2; avoid extracting untrusted archives until upgraded); Finding 04 (Critical Toptech TMS7 and TopHAT has a fixed 7.8 release listed and network exposure controls are specified); Finding 09 (High-severity libevent vulnerabilities have PoC exploitation and fixed upstream versions are listed).
Finding 01 — Multiple vulnerabilities in FreeIPMI
What changed: It was discovered that FreeIPMI incorrectly handled certain malformed Fujitsu SEL long-text responses, leading to a stack-based buffer overflow. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service, or possibly execute arbitrary code.
Technical evidence: CVE-2026-85504; CVSS v3.1 9.8; weakness CWE-121; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-85504 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8843-1)
Finding 02 — Multiple vulnerabilities in Anjvision YSSD-RTMP-H5
What changed: Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device. CVE coverage: CVE-2026-100291, CVE-2026-100292, CVE-2026-100293, CVE-2026-100294, CVE-2026-100295, CVE-2026-100296, CVE-2026-100297, CVE-2026-100298, CVE-2026-100299.
Technical evidence: CVE-2026-100291; CVSS v3.1 9.8; weakness CWE-1188; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Keep control system devices and systems off the internet. Place control system networks and remote devices behind firewalls and isolate them from business networks. CISA reports that no known public exploitation specifically targeting these vulnerabilities has been reported to it. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05))
Affected: Anjvision YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05))
Fix: No fix planned. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05))
Action: Map CVE-2026-100291 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05)
Finding 03 — VIVOTEK Camera Firmware: Command Injection
What changed: Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system.
Technical evidence: CVE-2026-22755; CVSS v4.0 9.3; weakness CWE-77; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Minimise network exposure so camera systems are not accessible from the internet; place remote devices behind firewalls and isolate them from business networks. If remote access is required, use an up-to-date VPN. CISA reports a public proof of concept authored by indoushka. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-22755))
Affected: Firmware versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, 012501, 012502 and 0125c. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-22755))
Action: Map CVE-2026-22755 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03)
Finding 04 — Multiple vulnerabilities in Toptech TMS7 and TopHAT
What changed: Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code. CVE coverage: CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189.
Technical evidence: CVE-2026-71379; CVSS v3.1 10; weakness CWE-552; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Minimise network exposure for control-system devices and systems, ensuring they are not accessible from the internet. Place control-system networks and remote devices behind firewalls and isolate them from business networks. CISA reports no known public exploitation specifically targeting these vulnerabilities. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02))
Fix: TMS7 and TopHAT release 7.8. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02))
Action: Map CVE-2026-71379 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02)
Finding 05 — Multiple vulnerabilities in PyJWT BOM
What changed: PyJWT BOM carries 12 CVEs across 3 advisories: Improper Verification of Cryptographic Signature; Malformed RSA JWK aborts parsing of an entire JWK Set; PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation; Uncaught RecursionError in jwt.decode on deeply nested token header; Non-canonical signature segments enable raw-token revocation bypass; Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard; PyJWKClient follows redirects when fetching JWKS; Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2; PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values. CVE coverage: CVE-2026-102274, CVE-2026-102266, CVE-2026-102265, CVE-2026-102269, CVE-2026-102268, CVE-2026-102267, CVE-2026-102271, CVE-2022-29217, CVE-2026-101917, CVE-2026-48524, CVE-2026-102272, CVE-2026-102273.
Technical evidence: CVE-2026-102274; CVSS v3.1 5.9; weakness CWE-755; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-102274 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-w6j9-cwv2-h6wq)
Finding 06 — @xhmikosr/decompress: Path traversal via symlink chain
What changed: GitHub Advisory Database published GHSA-hrh2-vp3x-79xf for CVE-2026-101894 (@xhmikosr/decompress): Path Traversal, CVSS v3.1 9.1; affected: @xhmikosr/decompress >= 11.0.0 through 11.1.3, and <= 10.2.1.
Technical evidence: CVE-2026-101894; CVSS v3.1 9.1; weakness CWE-22, CWE-59; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Do not extract untrusted archives on affected versions. If you cannot upgrade, validate entries out of band and reject any whose resolved path escapes the target directory. ([github.com](https://github.com/advisories/GHSA-hrh2-vp3x-79xf))
Affected: @xhmikosr/decompress >= 11.0.0 through 11.1.3, and <= 10.2.1. ([github.com](https://github.com/advisories/GHSA-hrh2-vp3x-79xf))
Fix: @xhmikosr/decompress 11.1.4 and 10.2.2. ([github.com](https://github.com/advisories/GHSA-hrh2-vp3x-79xf))
Action: Map CVE-2026-101894 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-hrh2-vp3x-79xf)
Finding 07 — Apple macOS: Out-of-bounds Read
What changed: Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7.
Technical evidence: CVE-2026-84549; CVSS v3.1 7.5; weakness CWE-125; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patching is possible, block unpatched Macs from connecting to untrusted NFS servers and allow NFS only to approved servers. ([support.apple.com](https://support.apple.com/en-us/149042), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-84549))
Affected: Apple lists affected macOS ranges as below 15.8, below 26.7, and below 27. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-84549))
Action: Map CVE-2026-84549 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-84549)
Finding 08 — Multiple vulnerabilities in Moquette
What changed: CVE coverage: CVE-2026-95847, CVE-2026-95844. The cited advisories disclose: Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta; Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations.
Technical evidence: CVE-2026-95847; CVSS v4.0 8.8; weakness CWE-99; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until upgrading, reject durable-session client IDs ending in _meta, and block excessively deep MQTT topic names and filters at PUBLISH and SUBSCRIBE ingress. The CISA Coordinator reports proof-of-concept exploitation for both CVEs. ([github.com](https://github.com/moquette-io/moquette/commit/72d6c8257191d2e4b2e3aa11ab25fd09f88c6cb7), [github.com](https://github.com/moquette-io/moquette/releases/tag/v0.18.1), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-95847), +1 more)
Affected: Moquette versions before 0.18.1. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-95847), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-95844))
Fix: Moquette 0.18.1. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-95847), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-95844))
Action: Map CVE-2026-95847 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-95847)
Finding 09 — Multiple vulnerabilities in libevent
What changed: Michał Majchrowicz and Marcin Wyczechowski discovered that libevent incorrectly handled certain DNS responses. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code.
Technical evidence: CVE-2026-63387; CVSS v3.1 7; weakness CWE-121, CWE-193, CWE-787; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Where patching is delayed, disable DNS response generation through libevent's evdns_server_ APIs where feasible, and restrict access to libevent AF_UNIX listeners to trusted local processes. The libevent project's GitHub Security Advisories publish PoC reproduction instructions for both vulnerabilities. ([github.com](https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47), [github.com](https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338))
Affected: Upstream libevent versions <= 2.1.12 and <= 2.2.1-alpha. ([github.com](https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47))
Fix: Upstream libevent versions 2.1.13 and 2.2.2-alpha. ([github.com](https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47))
Action: Map CVE-2026-63387 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8840-1)
Finding 10 — Vulnerability in Baicells Nova 430H
What changed: Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition. The following versions of Baicells Nova 430H are affected: Nova 430H eNodeB (model pBS3101SH) <=BaiBLQ_3.0.12 (CVE-2026-96274).
Technical evidence: CVE-2026-96274; CVSS v3.1 7.4; weakness CWE-248; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-96274 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04)
Finding 11 — Multiple vulnerabilities in Lantronix G520 Series Cellular Gateway
What changed: Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular Gateway are affected: G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191).
Technical evidence: CVE-2026-84409; CVSS v3.1 7.5; weakness CWE-79; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-84409 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01)
Finding 12 — Multiple vulnerabilities in Electron
What changed: Electron carries 6 CVEs across 2 advisories: Origin Validation Error; Local race condition in Squirrel.Mac update installation on macOS; can enable Node.js integration in Web Workers despite embedd; Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions; Sandboxed preload code cache can be poisoned by a compromised renderer; File and HTTP protocol handlers allow cross-origin reads without corsEnabled. CVE coverage: CVE-2026-102672, CVE-2026-102676, CVE-2026-102674, CVE-2026-102677, CVE-2026-102675, CVE-2026-102673.
Technical evidence: CVE-2026-102672; CVSS v3.1 6.7; weakness CWE-367; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.
Action: Map CVE-2026-102672 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation reported by the source, not independently corroborated
fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-vv43-5jgx-7qv8)
Finding 13 — MongoDB Laravel: Improper Neutralization of Special Elements in Data Query Logic
What changed: Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence such an identifier may delete all embedded documents in a targeted record or overwrite an embedded document other than the intended target.
Technical evidence: CVE-2026-88027; CVSS v4.0 7.1; weakness CWE-943; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Add application validation that recursively rejects MongoDB operator documents containing $-prefixed keys wherever only a scalar identifier or relation key is valid. CISA Coordinator reports no exploitation. ([jira.mongodb.org](https://jira.mongodb.org/rest/api/2/issue/PHPLARA-265?fields=summary%2Cdescription%2CfixVersions%2Cstatus%2Cresolution), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-88027), [github.com](https://github.com/mongodb/laravel-mongodb/security/advisories/GHSA-jxxg-hqjr-9h33))
Affected: MongoDB Laravel integration versions >= 4.0.0 and < 5.11.0. ([github.com](https://github.com/mongodb/laravel-mongodb/security/advisories/GHSA-jxxg-hqjr-9h33))
Fix: 5.11.0. ([github.com](https://github.com/mongodb/laravel-mongodb/security/advisories/GHSA-jxxg-hqjr-9h33))
Panel assessment: Patch affected MongoDB Laravel integrations this week: authentication and no reported exploitation reduce emergency pressure, but the blast radius is direct application data integrity, including deletion of all embedded documents in a targeted record or overwriting the wrong embedded document. (priority: this week)
Action: Map CVE-2026-88027 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-88027)
Finding 14 — Multiple vulnerabilities in Okta Access Gateway
What changed: Okta Access Gateway carries 2 CVEs across 2 advisories: Eval Injection; Code Injection. CVE coverage: CVE-2026-78550, CVE-2026-78545.
Technical evidence: CVE-2026-78545; CVSS v3.1 6.6; weakness CWE-94; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Until upgraded, restrict application create or update functionality to essential administrators only. The CISA Coordinator's SSVC assessment reports no exploitation. ([trust.okta.com](https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-application-label-configuration-cve-2026-78545/), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-78545), [trust.okta.com](https://trust.okta.com/security-advisories/improper-input-handling-in-okta-access-gateway-management-console-exception-handler-cve-2026-78550), +1 more)
Affected: Okta Access Gateway appliance versions prior to 2026.9.1 ([trust.okta.com](https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-application-label-configuration-cve-2026-78545/), [trust.okta.com](https://trust.okta.com/security-advisories/improper-input-handling-in-okta-access-gateway-management-console-exception-handler-cve-2026-78550))
Fix: Okta Access Gateway appliance version 2026.9.1 ([trust.okta.com](https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-application-label-configuration-cve-2026-78545/), [trust.okta.com](https://trust.okta.com/security-advisories/improper-input-handling-in-okta-access-gateway-management-console-exception-handler-cve-2026-78550))
Action: Map CVE-2026-78545 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-78545)
Finding 15 — Multiple vulnerabilities in OpenSSL
What changed: It was discovered that OpenSSL incorrectly handled certain certificate revocation list distribution point names. An attacker could possibly use this issue to cause OpenSSL to consume excessive memory, resulting in a denial of service.
Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Keep QUIC client address validation enabled. If operationally acceptable, temporarily stop TLS servers soliciting client certificates. ([openssl-library.org](https://openssl-library.org/news/secadv/20260929.txt))
Affected: CVE-2026-35189: OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2; CVE-2026-35191: OpenSSL 4.0, 3.6 and 3.5. ([openssl-library.org](https://openssl-library.org/news/secadv/20260929.txt))
Fix: CVE-2026-35189: OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8; premium-support versions 3.0.23, 1.1.1zj and 1.0.2zs. CVE-2026-35191: OpenSSL 4.0.3, 3.6.5 and 3.5.9. ([openssl-library.org](https://openssl-library.org/news/secadv/20260929.txt))
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits:** grounded severity unavailable
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8847-1)