ELEVATED 11 min read 8 Oct 2026

Multiple vulnerabilities in Cisco Nexus Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-76465, cve-2026-76485, cve-2026-76486, cve-2026-76501, cve-2026-20038, cwe-590, cve-2026-76471, cve-2026-20032, cve-2026-20173, cwe-122

Key findings
01
Multiple vulnerabilities in Cisco Nexus
CRITICAL
CVE coverage: CVE-2026-76465, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, CVE-2026-20038. The cited advisories disclose: 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability; 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities; 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability.
02
Multiple vulnerabilities in Cisco NX-OS Software
CRITICAL
CVE coverage: CVE-2026-76471, CVE-2026-20032, CVE-2026-20173. The cited advisories disclose: NX-API Remote Code Execution Vulnerability; Python Sandbox Escape Vulnerability; Control Plane Denial of Service Vulnerability.
03
Multiple vulnerabilities in Cisco License (Smart Software Manager) On-Prem
CRITICAL
Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS) condition, or elevate privileges.
04
Multiple vulnerabilities in PraisonAI
CRITICAL
CVE coverage: CVE-2026-62176, CVE-2026-62179, CVE-2026-61436, CVE-2026-61428. The cited advisories disclose: Code Injection via f-string Interpolation in Deploy API Server Generation; Platform members can delete owner issue dependencies through member-owned related issues; AgentMail webhook mode accepts forged unsigned message.received events and invokes agents; AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing.
05
Multiple vulnerabilities in Payload Form Builder
CRITICAL
Payload Form Builder carries 12 CVEs across 5 advisories: A tenant authorization bypass in Multi-Tenant Plugin; Code Injection; Authentication Bypass by Spoofing; Exposure of Sensitive Information to an Unauthorized Actor; SQL injection in SQLite/Postgres; Remote Code Execution through first-register; Bypassed sanitization of user uploaded SVGs; Incomplete validation during the upload file lifecycle; Unauthenticated account-lockout denial of service; Client uploads could overwrite S3 objects; Uploaded XML files could execute same-origin JavaScript; Unauthorized update to collection documents.
06
Multiple vulnerabilities in Langflow
CRITICAL
Langflow carries 3 CVEs across 3 advisories: OS command injection (RCE) via arbitrary command in MCP stdio server c; Authenticated Cross-Project File Disclosure via Unscoped MCP Resour; Authorization Bypass Through User-Controlled Key. CVE coverage: CVE-2026-105697, CVE-2026-105699, CVE-2026-105698.
07
Actual Sync Server: Exposure of Sensitive Information to an Unauthorized Actor
HIGH
GitHub Advisory Database published GHSA-m62c-5q34-f3cf for CVE-2026-57449 (Actual Sync Server): Exposure of Sensitive Information to an Unauthorized Actor, CVSS v4.0 7.1; affected: Actual versions earlier than 26.7.0.
08
Multiple vulnerabilities in wger
HIGH
CVE coverage: CVE-2026-46434, CVE-2026-46438, CVE-2026-46437, CVE-2026-45161, CVE-2026-43976. The cited advisories disclose: Trainer Privilege Escalation - Improper Privilege Management; Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry; API credentials remain valid after logout/password change; trainer_login accepts GET - CSRF bypass enables forced session rebinding; cross-tenant admin notes/contracts leak via gym=None bypass.
09
Cisco Finesse: Server-Side Request Forgery
HIGH
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests.
10
Multiple vulnerabilities in Docling
HIGH
Docling carries 7 CVEs across 4 advisories: Arbitrary file read/write (and command execution when shell-escape i; SSRF guard bypass in remote resource fetching (DNS rebinding / multi; Before the allow_external_plugins check; enable_local_fetch is not enforced in HTML browser-rendering mode; Configured HTTP headers sent to every remote image host named by a document; Crafted DoclingDocument JSON embeds local image files into converted output; Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion.
11
librsvg: Use After Free
HIGH
It was discovered that librsvg incorrectly handled duplicate XML entity declarations while processing SVG documents containing nested XML inclusions. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. The assigned identifier is CVE-2026-96889.
12
Sudo: Incorrect Authorization
HIGH
It was discovered that Sudo did not properly handle time-based access restrictions when sudoers rules used NOTBEFORE or NOTAFTER with timestamps omitting the trailing timezone indicator.
13
Multiple vulnerabilities in yawkat LZ4 Java
HIGH
yawkat LZ4 Java carries 3 CVEs across 3 advisories: Time-of-check Time-of-use Race Condition; Allocation of Resources Without Limits or Throttling; Uncontrolled Recursion. CVE coverage: CVE-2026-106451, CVE-2026-106450, CVE-2026-106449.
14
Multiple vulnerabilities in Cisco Application Policy Infrastructure Controller
MEDIUM
CVE coverage: CVE-2026-76488, CVE-2026-20321. The cited advisories disclose: Unauthorized File Access Vulnerability; API Command Injection Vulnerability.
15
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
INFO
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx.

Executive assessment

Today's brief leads with Multiple vulnerabilities in Cisco Nexus. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Panel synthesis: Finding 04 should lead today because it is CRITICAL, has proof-of-concept exploitation listed, and includes both fixed versions and interim controls. Patch order: Finding 04 (CRITICAL with proof-of-concept exploitation listed, fixed versions available, and interim controls provided); Finding 07 (HIGH with proof-of-concept exploitation listed, a fixed version available, and controls for cases where patching is not immediate); Finding 08 (HIGH with proof-of-concept exploitation listed, wger 2.6 fixed, and interim permission/account controls provided); Finding 11 (HIGH with proof-of-concept exploitation listed and Ubuntu fixed package versions provided).

Also today: 15 more Ghost CVEs (CVE-2026-105642, CVE-2026-105677, CVE-2026-105643, CVE-2026-105645, CVE-2026-105646, CVE-2026-105647, CVE-2026-105648, CVE-2026-105649, CVE-2026-105650, CVE-2026-105651, CVE-2026-105652, CVE-2026-105675, CVE-2026-105676, CVE-2026-105678, CVE-2026-105679) in the same disclosure wave as the Ghost card of 2026-10-05; none reported exploited; carried as a note rather than a finding.

Finding 01 — Multiple vulnerabilities in Cisco Nexus

What changed: CVE coverage: CVE-2026-76465, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, CVE-2026-20038. The cited advisories disclose: 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability; 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities; 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability.

Technical evidence: CVE-2026-76465; CVSS v3.1 9.8; weakness CWE-590; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-76465 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-moam-rce-uBTzYV7?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%203000%20and%209000%20Series%20Switches%20MPLS%20OAM%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1)

Finding 02 — Multiple vulnerabilities in Cisco NX-OS Software

What changed: CVE coverage: CVE-2026-76471, CVE-2026-20032, CVE-2026-20173. The cited advisories disclose: NX-API Remote Code Execution Vulnerability; Python Sandbox Escape Vulnerability; Control Plane Denial of Service Vulnerability.

Technical evidence: CVE-2026-76471; CVSS v3.1 9.8; weakness CWE-122; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-76471 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20NX-OS%20Software%20NX-API%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1)

Finding 03 — Multiple vulnerabilities in Cisco License (Smart Software Manager) On-Prem

What changed: Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS) condition, or elevate privileges. For more information about these vulnerabilities, see the Details section of this advisory.

Technical evidence: CVE-2026-20328; CVSS v3.1 9.1; weakness CWE-862; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Cisco PSIRT reports it is not aware of public announcements or malicious use. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-access-nttb2dhE))

Affected: Cisco License On-Prem 9-202601 and earlier, and releases earlier than 10-202608. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-access-nttb2dhE))

Fix: 10-202608. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-access-nttb2dhE))

Panel assessment: Patch now, because the affected web management interface and API include critical missing-authorisation and path-traversal flaws that are remotely useful for unauthorised access, sensitive information exposure, privilege escalation or service disruption, even though Cisco reports no known public exploitation. (priority: patch now)

Action: Map CVE-2026-20328 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-access-nttb2dhE?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20License%20(Smart%20Software%20Manager)

Finding 04 — Multiple vulnerabilities in PraisonAI

What changed: CVE coverage: CVE-2026-62176, CVE-2026-62179, CVE-2026-61436, CVE-2026-61428. The cited advisories disclose: Code Injection via f-string Interpolation in Deploy API Server Generation; Platform members can delete owner issue dependencies through member-owned related issues; AgentMail webhook mode accepts forged unsigned message.received events and invokes agents; AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing.

Technical evidence: CVE-2026-62176; CVSS v3.1 9.1; weakness CWE-94; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Disable AgentMail webhook and hybrid modes in favour of the default poll mode, or restrict webhook URL reachability. Prevent untrusted users and upstream systems from controlling agents_file through CLI arguments, configuration or upstream APIs. CISA ADP reports proof-of-concept exploitation for CVE-2026-62176. ([github.com](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7c92-x8vg-4258), [github.com](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-g6j7-pffp-8whg), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-62176), +1 more)

Affected: praisonai <= 4.6.77; praisonai-platform <= 0.1.8 ([github.com](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-g6j7-pffp-8whg), [github.com](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-mxmx-rh57-jx58))

Fix: praisonai >= 4.6.78; praisonai-platform >= 0.1.9 ([github.com](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-g6j7-pffp-8whg), [github.com](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-mxmx-rh57-jx58))

Action: Map CVE-2026-62176 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-g6j7-pffp-8whg)

Finding 05 — Multiple vulnerabilities in Payload Form Builder

What changed: Payload Form Builder carries 12 CVEs across 5 advisories: A tenant authorization bypass in Multi-Tenant Plugin; Code Injection; Authentication Bypass by Spoofing; Exposure of Sensitive Information to an Unauthorized Actor; SQL injection in SQLite/Postgres; Remote Code Execution through first-register; Bypassed sanitization of user uploaded SVGs; Incomplete validation during the upload file lifecycle; Unauthenticated account-lockout denial of service; Client uploads could overwrite S3 objects; Uploaded XML files could execute same-origin JavaScript; Unauthorized update to collection documents. CVE coverage: CVE-2026-105856, CVE-2026-105858, CVE-2026-105862, CVE-2026-105865, CVE-2026-105866, CVE-2026-105867, CVE-2026-105868, CVE-2026-105859, CVE-2026-105860, CVE-2026-105857, CVE-2026-105863, CVE-2026-105861.

Technical evidence: CVE-2026-105856; CVSS v4.0 8.6; weakness CWE-89; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-105856 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-pj7x-6wpf-pgvp)

Finding 06 — Multiple vulnerabilities in Langflow

What changed: Langflow carries 3 CVEs across 3 advisories: OS command injection (RCE) via arbitrary command in MCP stdio server c; Authenticated Cross-Project File Disclosure via Unscoped MCP Resour; Authorization Bypass Through User-Controlled Key. CVE coverage: CVE-2026-105697, CVE-2026-105699, CVE-2026-105698.

Technical evidence: CVE-2026-105697; CVSS v3.1 9.9; weakness CWE-78; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-105697 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-w794-rj3p-xv45)

Finding 07 — Actual Sync Server: Exposure of Sensitive Information to an Unauthorized Actor

What changed: GitHub Advisory Database published GHSA-m62c-5q34-f3cf for CVE-2026-57449 (Actual Sync Server): Exposure of Sensitive Information to an Unauthorized Actor, CVSS v4.0 7.1; affected: Actual versions earlier than 26.7.0.

Technical evidence: CVE-2026-57449; CVSS v4.0 7.1; weakness CWE-200, CWE-284, CWE-863; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If patching is not immediately possible, disable the CORS proxy; alternatively, prevent it from attaching ACTUAL_GITHUB_TOKEN unless the requested repository exactly matches an allowlisted repository. ([github.com](https://github.com/advisories/GHSA-m62c-5q34-f3cf), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/57xxx/CVE-2026-57449.json))

Affected: Actual versions earlier than 26.7.0. ([raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/57xxx/CVE-2026-57449.json))

Fix: Version 26.7.0. ([raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/57xxx/CVE-2026-57449.json))

Panel assessment: Treat this as a this-week patch for any Actual deployment because proof-of-concept exploitation exists and the blast radius is the private repositories reachable by the server’s GitHub token, though the vulnerable CORS proxy is disabled by default. (priority: this week)

Action: Map CVE-2026-57449 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-m62c-5q34-f3cf)

Finding 08 — Multiple vulnerabilities in wger

What changed: CVE coverage: CVE-2026-46434, CVE-2026-46438, CVE-2026-46437, CVE-2026-45161, CVE-2026-43976. The cited advisories disclose: Trainer Privilege Escalation - Improper Privilege Management; Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry; API credentials remain valid after logout/password change; trainer_login accepts GET - CSRF bypass enables forced session rebinding; cross-tenant admin notes/contracts leak via gym=None bypass.

Technical evidence: CVE-2026-46434; CVSS v3.1 7.1; weakness CWE-269; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Until 2.6 can be deployed, remove gym.gym_trainer and gym.add_adminusernote from non-admin users, eliminate gym=None accounts, and manually rotate/delete DRF tokens after logout or password changes. At the reverse proxy, block GET requests matching /<lang>/user/<id>/trainer-login and POST requests to /api/v2/workoutlog/. ([github.com](https://github.com/wger-project/wger/security/advisories/GHSA-xf64-4pmc-h8qf), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-46434), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-46438), +3 more)

Affected: wger versions before 2.6. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-46434), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-46438), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-46437), +2 more)

Fix: wger 2.6. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-46434), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-46438), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-46437), +2 more)

Action: Map CVE-2026-46434 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-x249-cx55-2h87)

Finding 09 — Cisco Finesse: Server-Side Request Forgery

What changed: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests.

Technical evidence: CVE-2026-20362; CVSS v3.1 7.2; weakness CWE-918; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Cisco PSIRT reports that it is not aware of any malicious use. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS))

Affected: Cisco Finesse 12.6 and earlier and 15.0; Cisco Packaged CCE and Unified CCE earlier than 15.0 and 15.0; Cisco Unified CCX 12.5 and earlier and 15.0. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS))

Fix: Planned first fixed releases: Cisco Finesse 15.0(1) SU3 (Feb 2027); Cisco Packaged CCE and Unified CCE 15.0(1)ES202701 (Jan 2027); Cisco Unified CCX 15.0(1) SU2 (Feb 2027). ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS))

Action: Map CVE-2026-20362 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Finesse%20Server-Side%20Request%20Forgery%20Vulnerability%26vs_k=1)

Finding 10 — Multiple vulnerabilities in Docling

What changed: Docling carries 7 CVEs across 4 advisories: Arbitrary file read/write (and command execution when shell-escape i; SSRF guard bypass in remote resource fetching (DNS rebinding / multi; Before the allow_external_plugins check; enable_local_fetch is not enforced in HTML browser-rendering mode; Configured HTTP headers sent to every remote image host named by a document; Crafted DoclingDocument JSON embeds local image files into converted output; Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion. CVE coverage: CVE-2026-105744, CVE-2026-105750, CVE-2026-105742, CVE-2026-105748, CVE-2026-105749, CVE-2026-105743, CVE-2026-105745.

Technical evidence: CVE-2026-105744; CVSS v3.1 7.5; weakness CWE-22, CWE-73, CWE-1188; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-105744 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-x3q2-h9hx-4r4j)

Finding 11 — librsvg: Use After Free

What changed: It was discovered that librsvg incorrectly handled duplicate XML entity declarations while processing SVG documents containing nested XML inclusions. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code.

Technical evidence: CVE-2026-96889; CVSS v3.1 7.8; weakness CWE-416; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Red Hat Bugzilla reports that a public proof-of-concept has been released. ([bugzilla.redhat.com](https://bugzilla.redhat.com/show_bug.cgi?id=2539279), [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-96889), [ubuntu.com](https://ubuntu.com/security/notices/USN-8891-1))

Affected: Debian lists librsvg 2.54.7+dfsg-1~deb12u1 in bookworm, 2.60.0+dfsg-1 in trixie and 2.62.1+dfsg-1 in forky as vulnerable. ([security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-96889))

Fix: Ubuntu fixes are librsvg2-2 2.61.3+dfsg-3ubuntu0.1 for Ubuntu 26.04 LTS and 2.58.0+dfsg-1ubuntu0.1 for Ubuntu 24.04 LTS. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8891-1))

Action: Map CVE-2026-96889 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8891-1)

Finding 12 — Sudo: Incorrect Authorization

What changed: It was discovered that Sudo did not properly handle time-based access restrictions when sudoers rules used NOTBEFORE or NOTAFTER with timestamps omitting the trailing timezone indicator. A local attacker could possibly use this issue to execute commands outside the intended time window by manipulating the TZ environment variable.

Technical evidence: CVE-2026-96512; CVSS v3.1 7.8; weakness CWE-863; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Append the trailing 'Z' timezone suffix to every NOTBEFORE and NOTAFTER timestamp in sudoers rules. Audit /etc/sudoers and /etc/sudoers.d/ for these directives and verify that every timestamp ends in 'Z'. The CISA Coordinator's assessment reports exploitation as 'none'. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8895-1), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-96512), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-96512))

Affected: Ubuntu 26.04 LTS, 24.04 LTS and 22.04 LTS. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8895-1))

Fix: 24.04 LTS noble sudo – 1.9.15p5-3ubuntu5.24.04.4 sudo-ldap – 1.9.15p5-3ubuntu5.24.04.4; 22.04 LTS jammy sudo – 1.9.9-1ubuntu2.7 sudo-ldap – 1.9.9-1ubuntu2.7 ([ubuntu.com](https://ubuntu.com/security/notices/USN-8895-1))

Action: Map CVE-2026-96512 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8895-1)

Finding 13 — Multiple vulnerabilities in yawkat LZ4 Java

What changed: yawkat LZ4 Java carries 3 CVEs across 3 advisories: Time-of-check Time-of-use Race Condition; Allocation of Resources Without Limits or Throttling; Uncontrolled Recursion. CVE coverage: CVE-2026-106451, CVE-2026-106450, CVE-2026-106449.

Technical evidence: CVE-2026-106451; CVSS v4.0 7.3; weakness CWE-367, CWE-377; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-106451 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-mcr4-qmvw-px4g)

Finding 14 — Multiple vulnerabilities in Cisco Application Policy Infrastructure Controller

What changed: CVE coverage: CVE-2026-76488, CVE-2026-20321. The cited advisories disclose: Unauthorized File Access Vulnerability; API Command Injection Vulnerability.

Technical evidence: CVE-2026-76488; CVSS v3.1 6.5; weakness CWE-264; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Analyst note: Cisco PSIRT reports no public announcements or malicious use for either vulnerability. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-info-priv-enAdB5vD), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-cmdinj-L6VR4E7))

Affected: Cisco APIC 5.3 and earlier. For CVE-2026-76488, affected 6.0 and 6.1 releases precede 6.0(9h) and 6.1(3f). ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-info-priv-enAdB5vD), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-cmdinj-L6VR4E7))

Fix: CVE-2026-76488: 6.0(9h) and 6.1(3f); 6.2 is not vulnerable. CVE-2026-20321: 6.0(9h), 6.1(6g) and 6.2(3g). ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-info-priv-enAdB5vD), [sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-cmdinj-L6VR4E7))

Action: Map CVE-2026-76488 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-info-priv-enAdB5vD?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Application%20Policy%20Infrastructure%20Controller%20Unauthorized%20File%20Access%20Vulnerability%26vs_k=1)

Finding 15 — Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

What changed: Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: The cited source reports an active supply-chain compromise; exposure depends on use of the affected packages rather than exploitation of a single vulnerability.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

fixed version or patch state unknown

[Evidence source: thehackernews.com](https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html)

cve-2026-105697cve-2026-106451cve-2026-20032cve-2026-20038cve-2026-20173cve-2026-20328cve-2026-20362cve-2026-46434cve-2026-57449cve-2026-62176

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.