ELEVATED 8 min read 3 Oct 2026

MikroTik RouterOS: Integer Underflow Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-84411, cwe-191, cve-2026-95102, cve-2026-97363, cve-2026-97212, cve-2026-93474, cwe-306, cve-2026-90970, cwe-1336, cve-2026-73802

Key findings
01
MikroTik RouterOS: Integer Underflow
CRITICAL
Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS <7.24 (CVE-2026-84411).
02
Multiple vulnerabilities in Monta monta.app
CRITICAL
Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. CVE coverage: CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474.
03
GitLab: Improper Neutralization of Special Elements Used in a Template Engine
CRITICAL
CVE-2026-90970 is a CVSS 9.9 prompt-template sandbox escape in self-hosted GitLab AI Gateway. An authenticated user with Duo Agent Platform access can execute arbitrary commands; GitLab fixed the affected 18.1.6 through 19.4 lines in 19.2.4, 19.3.2, and 19.4.1.
04
gitea-runner: Improper Privilege Management
CRITICAL
GitHub Advisory Database published GHSA-x4q3-gcj3-m6cf for CVE-2026-73802 (gitea-runner): Improper Privilege Management, CVSS v3.1 9.9; affected: < 1.0.9-0.20260731160927-34bfa1915022.
05
Multiple vulnerabilities in Zammad
HIGH
CVE coverage: CVE-2026-102490, CVE-2026-102489. The cited advisories disclose: Improper Privilege Management Vulnerability — Zammad; Session Fixation Vulnerability — Zammad.
06
Multiple vulnerabilities in Meari IoT Cloud Platform OpenAPI Service
HIGH
Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization.
07
Microsoft Exchange Server: Elevation of Privilege
HIGH
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. The assigned identifier is CVE-2026-96940.
08
copernik-xml-factory: Improper Restriction of XML External Entity Reference
HIGH
GitHub Advisory Database published GHSA-xm28-xvqc-gxxg for CVE-2026-61586 (Copernik XML Factory): Improper Restriction of XML External Entity Reference, CVSS v4.0 8.2; affected: Versions earlier than 0.1.2 are affected.
09
aws-smithy-json: Uncontrolled Recursion
HIGH
GitHub Advisory Database published GHSA-8ffr-xgwf-xj56 for CVE-2026-18140 (aws-smithy-json): Uncontrolled Recursion, CVSS v3.1 7.5; affected: aws-smithy-json versions 0.62.6 and earlier.
10
probe-image-size: Quadratic-time Denial of Service in the SVG Parser
HIGH
GitHub Advisory Database published GHSA-gjj5-9665-rwrc for CVE-2026-104861 (probe-image-size): Uncontrolled Resource Consumption, CVSS v3.1 7.5; affected: Versions earlier than 7.4.0.
11
Multiple vulnerabilities in @fastify/busboy
HIGH
@fastify/busboy carries 2 CVEs across 2 advisories: Loop with Unreachable Exit Condition; Improper Check for Unusual or Exceptional Conditions. CVE coverage: CVE-2026-19484, CVE-2026-19481.
12
figlet: Loop with Unreachable Exit Condition
HIGH
GitHub Advisory Database published GHSA-62ch-8vmq-8xm7 for CVE-2026-96780 (figlet): Loop with Unreachable Exit Condition, CVSS v4.0 8.2; affected: figlet versions before 1.11.3.
13
Multiple vulnerabilities in ABB Protection and Control IED Manager PCM600
MEDIUM
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953).
14
libXpm: Excessive Platform Resource Consumption within a Loop
MEDIUM
It was discovered that libXpm did not correctly handle XPM images with zero-dimension values. A local attacker could possibly use this issue to cause libXpm to use excessive resources, leading to a denial of service. The assigned identifier is CVE-2026-94287.
15
Anubis: Policy bypass via client controlled X-Original-URI header
MEDIUM
GitHub Advisory Database published GHSA-6wcg-mqvh-fcvg for CVE-2026-62314 (Anubis): Improper Access Control, CVSS v3.1 5.8; affected: Anubis v1.22.0 through v1.25.0.

Executive assessment

Today's brief leads with MikroTik RouterOS: Integer Underflow. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — MikroTik RouterOS: Integer Underflow

What changed: Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS <7.24 (CVE-2026-84411).

Technical evidence: CVE-2026-84411; CVSS v3.1 9.8; weakness CWE-191; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Keep RouterOS management inaccessible from the internet; place devices behind firewalls and isolate them from business networks. CISA reports no known public exploitation specifically targeting this vulnerability. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06))

Fix: RouterOS 7.24 or later. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06))

Action: Map CVE-2026-84411 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06)

Finding 02 — Multiple vulnerabilities in Monta monta.app

What changed: Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. CVE coverage: CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474.

Technical evidence: CVE-2026-95102; CVSS v3.1 9.4; weakness CWE-306; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-95102 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02)

Finding 03 — GitLab: Improper Neutralization of Special Elements Used in a Template Engine

What changed: CVE-2026-90970 is a CVSS 9.9 prompt-template sandbox escape in self-hosted GitLab AI Gateway. An authenticated user with Duo Agent Platform access can execute arbitrary commands; GitLab fixed the affected 18.1.6 through 19.4 lines in 19.2.4, 19.3.2, and 19.4.1.

Technical evidence: CVE-2026-90970; CVSS v3.1 9.9; weakness CWE-1336; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: CISA's CVE record assessment lists exploitation as none. ([thehackernews.com](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html))

Action: Map CVE-2026-90970 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/)

Finding 04 — gitea-runner: Improper Privilege Management

What changed: GitHub Advisory Database published GHSA-x4q3-gcj3-m6cf for CVE-2026-73802 (gitea-runner): Improper Privilege Management, CVSS v3.1 9.9; affected: < 1.0.9-0.20260731160927-34bfa1915022.

Technical evidence: CVE-2026-73802; CVSS v3.1 9.9; weakness CWE-269; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Reject or strip workflow-controlled container.options when privileged mode is disabled. ([github.com](https://github.com/advisories/GHSA-x4q3-gcj3-m6cf))

Affected: < 1.0.9-0.20260731160927-34bfa1915022 ([github.com](https://github.com/advisories/GHSA-x4q3-gcj3-m6cf))

Fix: 1.0.9-0.20260731160927-34bfa1915022 ([github.com](https://github.com/advisories/GHSA-x4q3-gcj3-m6cf))

Action: Map CVE-2026-73802 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-x4q3-gcj3-m6cf)

Finding 05 — Multiple vulnerabilities in Zammad

What changed: CVE coverage: CVE-2026-102490, CVE-2026-102489. The cited advisories disclose: Improper Privilege Management Vulnerability — Zammad; Session Fixation Vulnerability — Zammad.

Technical evidence: CVE-2026-102490; CVSS v4.0 8.5; weakness CWE-269; technical confidence Medium.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Analyst note: Take the Zammad instance offline. Run DIVD's log-check script against Zammad log files for indicators of compromise. DIVD reports that the vulnerabilities were abused to breach DIVD. ([csirt.divd.nl](https://csirt.divd.nl/cases/DIVD-2026-00015/), [community.zammad.org](https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2.md))

Affected: CVE-2026-102489: Zammad 6.3.0 to 6.5.4. CVE-2026-102490: Zammad 1.5.0 to 7.1.0-alpha. ([csirt.divd.nl](https://csirt.divd.nl/cases/DIVD-2026-00015/))

Fix: We have still hardened the affected code. The change is included in Zammad 7.2.0 ([community.zammad.org](https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2.md))

Action: Map CVE-2026-102490 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-102490)

Finding 06 — Multiple vulnerabilities in Meari IoT Cloud Platform OpenAPI Service

What changed: Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization. CVE coverage: CVE-2026-101104, CVE-2026-96613.

Technical evidence: CVE-2026-96613; CVSS v4.0 7.1; weakness CWE-862; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Keep control-system devices and systems inaccessible from the internet, and place control-system networks and remote devices behind firewalls, isolated from business networks. Where remote access is required, use an up-to-date VPN. CISA reports no known public exploitation specifically targeting these vulnerabilities. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06))

Affected: All versions (vers:all/). ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06))

Action: Map CVE-2026-96613 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06)

Finding 07 — Microsoft Exchange Server: Elevation of Privilege

What changed: Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Technical evidence: CVE-2026-96940; CVSS v3.1 8.8; weakness CWE-1390; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Affected: Microsoft Exchange Server 2016 CU23 builds 15.01.0.0 to before 15.01.2507.075; Exchange Server 2019 CU14 builds 15.02.0.0 to before 15.02.1544.048. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-96940))

Fix: Exchange Server 2016 CU23 build 15.01.2507.075 (KB5129958); Exchange Server 2019 CU14 build 15.02.1544.048 (KB5129957); Exchange Server 2019 CU15 build 15.02.1748.053 (KB5129956). ([api.msrc.microsoft.com](https://api.msrc.microsoft.com/sug/v2.0/en-US/affectedProduct?%24filter=cveNumber%20eq%20%27CVE-2026-96940%27&%24top=10))

Action: Map CVE-2026-96940 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940)

Finding 08 — copernik-xml-factory: Improper Restriction of XML External Entity Reference

What changed: GitHub Advisory Database published GHSA-xm28-xvqc-gxxg for CVE-2026-61586 (Copernik XML Factory): Improper Restriction of XML External Entity Reference, CVSS v4.0 8.2; affected: Versions earlier than 0.1.2 are affected.

Technical evidence: CVE-2026-61586; CVSS v4.0 8.2; weakness CWE-611; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Add Apache Xerces (xercesImpl) to the classpath so the library selects its unaffected Xerces provider. ([github.com](https://github.com/copernik-eu/copernik-xml-factory/security/advisories/GHSA-xm28-xvqc-gxxg))

Affected: Versions earlier than 0.1.2 are affected. ([github.com](https://github.com/copernik-eu/copernik-xml-factory/security/advisories/GHSA-xm28-xvqc-gxxg))

Fix: Version 0.1.2 fixes the defect. ([github.com](https://github.com/copernik-eu/copernik-xml-factory/security/advisories/GHSA-xm28-xvqc-gxxg))

Action: Map CVE-2026-61586 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-xm28-xvqc-gxxg)

Finding 09 — aws-smithy-json: Uncontrolled Recursion

What changed: GitHub Advisory Database published GHSA-8ffr-xgwf-xj56 for CVE-2026-18140 (aws-smithy-json): Uncontrolled Recursion, CVSS v3.1 7.5; affected: aws-smithy-json versions 0.62.6 and earlier.

Technical evidence: CVE-2026-18140; CVSS v3.1 7.5; weakness CWE-674; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: AWS states that no workaround is available besides updating to the patched version. The CISA Coordinator reports exploitation as none. ([aws.amazon.com](https://aws.amazon.com/security/security-bulletins/2026-067-aws/), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-18140))

Affected: aws-smithy-json versions 0.62.6 and earlier. ([aws.amazon.com](https://aws.amazon.com/security/security-bulletins/2026-067-aws/))

Fix: aws-smithy-json version 0.62.7. ([aws.amazon.com](https://aws.amazon.com/security/security-bulletins/2026-067-aws/))

Action: Map CVE-2026-18140 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-8ffr-xgwf-xj56)

Finding 10 — probe-image-size: Quadratic-time Denial of Service in the SVG Parser

What changed: GitHub Advisory Database published GHSA-gjj5-9665-rwrc for CVE-2026-104861 (probe-image-size): Uncontrolled Resource Consumption, CVSS v3.1 7.5; affected: Versions earlier than 7.4.0.

Technical evidence: CVE-2026-104861; CVSS v3.1 7.5; weakness CWE-400, CWE-1333; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If patching is not immediately possible, prevent untrusted SVG buffers, streams and URLs from reaching probe.sync(), probe(stream) or probe(url), particularly by disabling URL-based probing of attacker-supplied links. The CISA Coordinator reports proof-of-concept exploitation. ([api.osv.dev](https://api.osv.dev/v1/vulns/GHSA-gjj5-9665-rwrc), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-104861), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-104861))

Affected: Versions earlier than 7.4.0. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-104861))

Fix: Version 7.4.0. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-104861))

Action: Map CVE-2026-104861 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-gjj5-9665-rwrc)

Finding 11 — Multiple vulnerabilities in @fastify/busboy

What changed: @fastify/busboy carries 2 CVEs across 2 advisories: Loop with Unreachable Exit Condition; Improper Check for Unusual or Exceptional Conditions. CVE coverage: CVE-2026-19484, CVE-2026-19481.

Technical evidence: CVE-2026-19481; CVSS v3.1 7.5; weakness CWE-754; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-19481 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-x8mw-p69m-v3mx)

Finding 12 — figlet: Loop with Unreachable Exit Condition

What changed: GitHub Advisory Database published GHSA-62ch-8vmq-8xm7 for CVE-2026-96780 (figlet): Loop with Unreachable Exit Condition, CVSS v4.0 8.2; affected: figlet versions before 1.11.3.

Technical evidence: CVE-2026-96780; CVSS v4.0 8.2; weakness CWE-835; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Do not expose width to untrusted input, or leave whitespaceBreak disabled (the default). CISA ADP Vulnrichment reports exploitation as 'none'. ([api.osv.dev](https://api.osv.dev/v1/vulns/GHSA-62ch-8vmq-8xm7), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-96780))

Affected: figlet versions before 1.11.3. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-96780))

Fix: figlet 1.11.3. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-96780))

Action: Map CVE-2026-96780 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-62ch-8vmq-8xm7)

Finding 13 — Multiple vulnerabilities in ABB Protection and Control IED Manager PCM600

What changed: Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953).

Technical evidence: CVE-2026-15952; CVSS v3.1 6.4; weakness CWE-732; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-15952 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03)

Finding 14 — libXpm: Excessive Platform Resource Consumption within a Loop

What changed: It was discovered that libXpm did not correctly handle XPM images with zero-dimension values. A local attacker could possibly use this issue to cause libXpm to use excessive resources, leading to a denial of service.

Technical evidence: CVE-2026-94287; CVSS v3.1 5.5; weakness CWE-1050; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Affected: Upstream libXpm versions from 0 up to, but excluding, 3.5.19. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-94287))

Fix: Ubuntu libxpm: 1:3.5.17-1ubuntu0.26.04.2 for 26.04 LTS; 1:3.5.17-1ubuntu0.24.04.2 for 24.04 LTS; 1:3.5.12-1ubuntu0.22.04.4 for 22.04 LTS. ([ubuntu.com](https://ubuntu.com/security/CVE-2026-94287))

Action: Map CVE-2026-94287 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8862-1)

Finding 15 — Anubis: Policy bypass via client controlled X-Original-URI header

What changed: GitHub Advisory Database published GHSA-6wcg-mqvh-fcvg for CVE-2026-62314 (Anubis): Improper Access Control, CVSS v3.1 5.8; affected: Anubis v1.22.0 through v1.25.0.

Technical evidence: CVE-2026-62314; CVSS v3.1 5.8; weakness CWE-284; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Analyst note: Strip the X-Original-URI header from incoming client requests before policy evaluation. ([api.github.com](https://api.github.com/repos/TecharoHQ/anubis/security-advisories/GHSA-6wcg-mqvh-fcvg), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-62314))

Affected: Anubis v1.22.0 through v1.25.0. ([api.github.com](https://api.github.com/repos/TecharoHQ/anubis/security-advisories/GHSA-6wcg-mqvh-fcvg))

Fix: Anubis 1.26.0-pre1. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-62314))

Action:** Map CVE-2026-62314 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-6wcg-mqvh-fcvg)

cve-2026-101104cve-2026-102490cve-2026-104861cve-2026-15952cve-2026-18140cve-2026-19484cve-2026-61586cve-2026-62314cve-2026-73802cve-2026-84411

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.