Executive assessment
Today's brief leads with Multiple vulnerabilities in Linux kernel. All 10 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 02 should lead today because it is critical, spans eight Atlassian products, allows unauthenticated attackers to read known files, and has both fixed versions and interim exposure/WAF controls listed. Finding 01 is also critical, but the listing does not provide fixed-version or control detail. Themes: Critical enterprise-platform flaws; PoC-backed code execution and parser risks; Isolation or disabling as interim control. Patch order: Finding 02 (Critical unauthenticated file-read across eight Atlassian products, with fixed versions and interim remove-from-internet or WAF/proxy controls listed); Finding 04 (Critical Langflow unsandboxed Python execution with PoC; fixed versions and flags to disable the interpreter are listed); Finding 03 (Critical Hitachi Energy vulnerabilities with PoC; RTU500 firmware fixes and Asset Suite servlet-disabling controls are listed); Finding 01 (Critical Linux kernel vulnerabilities, but exploitation, fixed-version and control details are not provided in the listing); Finding 05 (High LibreOffice vulnerabilities with PoC and listed upstream and Ubuntu fixed builds).
Finding 01 — Multiple vulnerabilities in Linux kernel
What changed: It was discovered that the i.MX clock driver in the Linux kernel did not properly handle certain memory allocation failure conditions, leading to a null pointer dereference vulnerability. A local attacker could possibly use this to cause a denial of service (system crash).
Technical evidence: CVE-2026-53399; CVSS v3.1 9.8; weakness CWE-476; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Affected: Ubuntu 22.04 LTS (Jammy) and Ubuntu 20.04 LTS (Focal). ([ubuntu.com](https://ubuntu.com/security/notices/USN-8875-1))
Action: Map CVE-2026-53399 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8875-1)
Finding 02 — Atlassian: Files or Directories Accessible to External Parties
What changed: A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds.
Technical evidence: CVE-2026-21589; CVSS v4.0 9.3; weakness CWE-552; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Remove the instance from the internet until it can be patched or mitigated. Apply Atlassian's regex-filtering WAF or proxy rule to block URLs where '..' is immediately adjacent to '/', '\' or '::', including encoded forms. ([confluence.atlassian.com](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/21xxx/CVE-2026-21589.json))
Affected: All versions before the applicable fixed version for each listed product. ([confluence.atlassian.com](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html))
Fix: Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1; Confluence Data Center: 9.2.26, 10.2.19; Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12. ([confluence.atlassian.com](https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html))
Action: Map CVE-2026-21589 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: thehackernews.com](https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html)
Finding 03 — Multiple vulnerabilities in Hitachi Energy
What changed: CVE coverage: CVE-2026-8065, CVE-2026-8066, CVE-2026-8067, CVE-2010-2965, CVE-2014-9195, CVE-2023-46143, CVE-2026-7395, CVE-2026-11796. The cited advisories disclose: Missing Authentication for Critical Function; Relative Path Traversal; Missing Authorization; Incorrect Authorization; Download of Code Without Integrity Check.
Technical evidence: CVE-2026-8065; CVSS v3.1 9.1; weakness CWE-306; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: For Asset Suite, disable the affected servlet and evaluate whether PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet are needed in production. Restrict UDP/17185 to trusted sources, keep control networks behind firewalls and isolate them from business networks. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-06), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-03), [kb.cert.org](https://www.kb.cert.org/vuls/id/362332/), +1 more)
Affected: RTU500 series CMU Firmware 11.x and prior (end-of-life); Asset Suite 9.9.0 and prior. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-06), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-03))
Fix: RTU500 series CMU Firmware 12.7.8, 13.9.1 or latest; Asset Suite 9.9.1 when available. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-06), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-03))
Action: Map CVE-2026-8065 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-06)
Finding 04 — Langflow: Code Injection
What changed: GitHub Advisory Database published GHSA-8qpj-27x8-pwpq for CVE-2026-10561 (Langflow): Code Injection, CVSS v3.1 10; affected: Langflow versions earlier than 1.10.1.
Technical evidence: CVE-2026-10561; CVSS v3.1 10; weakness CWE-94; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Set LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false or LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS=true to disable the interpreter. If untrusted code must run, configure LANGFLOW_SANDBOX_BACKEND for microVM isolation. GitHub's Langflow advisory reports a PoC that opens a database session and sets is_superuser to true. ([github.com](https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq))
Affected: Langflow versions earlier than 1.10.1. ([github.com](https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq))
Fix: Langflow 1.10.1 contains the core fix; version 1.12.3 or later includes the complete hardening series. ([github.com](https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq))
Action: Map CVE-2026-10561 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-8qpj-27x8-pwpq)
Finding 05 — Multiple vulnerabilities in LibreOffice
What changed: It was discovered that LibreOffice incorrectly handled WMF image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code.
Technical evidence: CVE-2026-50593; CVSS v3.1 7.3; weakness CWE-191; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: The Document Foundation's CVE record for CVE-2026-63272 reports proof-of-concept exploit maturity. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-63272), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-63273), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-63274), +8 more)
Affected: "status":"affected","version":"26.2","lessThan":"< 26.2.5" ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-63272), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-63273), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-63274), +5 more)
Fix: LibreOffice 26.2.5 and Graphite 1.3.15. Ubuntu's fixed LibreOffice builds are 4:26.2.6.3-0ubuntu0.26.04.2 for 26.04 LTS, 4:24.2.7-0ubuntu0.24.04.7 for 24.04 LTS. ([libreoffice.org](https://www.libreoffice.org/security/#cve-2026-63272), [ubuntu.com](https://ubuntu.com/security/notices/USN-8868-1), [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-50593))
Action: Map CVE-2026-50593 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8868-1)
Finding 06 — Ceph: Improper Verification of Cryptographic Signature
What changed: It was discovered that the Ceph Object Gateway (RGW) SigV4 handler did not reject requests carrying x-amz- headers that were absent from the signed header set. An attacker holding a presigned URL could possibly use this issue to attach arbitrary unsigned x-amz- headers that RGW would honor, allowing them to escalate their privileges beyond what the URL's signer intended.
Technical evidence: CVE-2026-54330; CVSS v3.1 8.1; weakness CWE-347; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Disable the Ceph RGW pre-signed URL feature until the update is applied. CISA ADP Vulnrichment reports no exploitation. ([docs.ceph.com](https://docs.ceph.com/en/latest/security/CVE-2026-54330/), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-54330))
Affected: All prior versions of Ceph RGW SigV4 improperly verify cryptographic signatures ([docs.ceph.com](https://docs.ceph.com/en/latest/security/CVE-2026-54330/))
Fix: Tentacle 20.2.4 and later; Squid 19.2.6 and later. ([docs.ceph.com](https://docs.ceph.com/en/latest/security/CVE-2026-54330/))
Action: Map CVE-2026-54330 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8867-1)
Finding 07 — Multiple vulnerabilities in Tesseract
What changed: It was discovered that Tesseract incorrectly handled crafted .traineddata models. An attacker could possibly use this issue to cause Tesseract to crash, resulting in a denial of service.
Technical evidence: CVE-2026-88047; CVSS v4.0 8.6; weakness CWE-121; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patched, use only .traineddata files from trusted sources. CISA ADP Vulnrichment records exploitation as 'poc' for CVE-2026-88048. ([github.com](https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-2hm8-q5c7-c373), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/88xxx/CVE-2026-88048.json), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/73xxx/CVE-2026-73066.json), +9 more)
Affected: CVE-2026-73066 and CVE-2026-73067: versions before 5.5.3. CVE-2026-88047 through CVE-2026-88054: version 5.5.3 and earlier. ([raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/73xxx/CVE-2026-73066.json), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/73xxx/CVE-2026-73067.json), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/88xxx/CVE-2026-88047.json), +7 more)
Fix: Ubuntu fixed tesseract source packages: 14.04 3.03.02-3ubuntu0.1~esm1; 16.04 3.04.01-4ubuntu0.1~esm1; 18.04 4.00~git2288-10f4998a-2ubuntu0.1~esm1; 20.04 4.1.1-2ubuntu0.1~esm1. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8882-1.json))
Action: Map CVE-2026-88047 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8882-1)
Finding 08 — openapi-python-client: Code Injection
What changed: GitHub Advisory Database published GHSA-5293-mq8x-g3xj for CVE-2026-105801 (openapi-python-client): Code Injection, CVSS v4.0 8.4; affected: Versions earlier than 0.29.1.
Technical evidence: CVE-2026-105801; CVSS v4.0 8.4; weakness CWE-94, CWE-116, CWE-150; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Do not generate clients from OpenAPI documents that are not completely trusted. Carefully verify existing generated code derived from untrusted documents. ([github.com](https://github.com/openapi-generators/openapi-python-client/security/advisories/GHSA-5293-mq8x-g3xj))
Affected: Versions earlier than 0.29.1. ([github.com](https://github.com/openapi-generators/openapi-python-client/security/advisories/GHSA-5293-mq8x-g3xj))
Fix: Version 0.29.1. ([github.com](https://github.com/openapi-generators/openapi-python-client/security/advisories/GHSA-5293-mq8x-g3xj))
Action: Map CVE-2026-105801 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-5293-mq8x-g3xj)
Finding 09 — Multiple vulnerabilities in Johnson Controls EasyIO FG
What changed: Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device.
Technical evidence: CVE-2026-27872; CVSS v4.0 5.6; weakness CWE-269; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Isolate devices in BAS/OT networks with no direct internet exposure, disable Telnet and unnecessary services or ports, and restrict communications to required protocols. Monitor repeated login attempts, unauthorised or root-level access, and anomalous network traffic. CISA reports that no known public exploitation specifically targeting these vulnerabilities has been reported. ([tyco.widen.net](https://tyco.widen.net/s/shhcwh9bzm/jci-psa-2026-12), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-01))
Fix: No firmware fix is available, and no firmware patch or code-level fix will be issued. ([tyco.widen.net](https://tyco.widen.net/s/shhcwh9bzm/jci-psa-2026-12))
Action: Map CVE-2026-27872 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-01)
Finding 10 — FreeType: Uncontrolled Resource Consumption
What changed: It was discovered that FreeType had a flaw in its CID font loader. An attacker could possibly use this issue to cause FreeType to consume excessive memory and CPU resources, leading to a denial of service.
Technical evidence: CVE-2026-95512; CVSS v3.1 5.5; weakness CWE-400; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Until patched, prevent users and services from opening untrusted content that embeds or references CID-keyed fonts. CISA ADP Vulnrichment reports exploitation as 'none'. ([ubuntu.com](https://ubuntu.com/security/CVE-2026-95512?format=md), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-95512), [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-95512))
Affected: Debian lists freetype 2.12.1+dfsg-5+deb12u4 (bookworm), 2.13.3+dfsg-1+deb13u1 (trixie), and 2.14.3+dfsg-2 (forky) as vulnerable. ([security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-95512))
Fix: Ubuntu lists fixed freetype builds 2.14.2+dfsg-1ubuntu0.2 for 26.04 LTS, 2.13.2+dfsg-1ubuntu0.2 for 24.04 LTS, and 2.11.1+dfsg-1ubuntu0.4 for 22.04 LTS. ([ubuntu.com](https://ubuntu.com/security/CVE-2026-95512?format=md))
Action: Map CVE-2026-95512 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8881-1)