CRITICAL 12 min read 9 Oct 2026

Multiple vulnerabilities in Cisco Meraki Leads Today's Security Review

Threat Level: Critical Tags: cve-2026-76463, cve-2026-76464, cve-2026-76467, cve-2026-76468, cve-2026-76469, cve-2026-76470, cve-2026-76472, cwe-119, cve-2014-6278, cve-2015-3306

Key findings
01
Multiple vulnerabilities in Cisco Meraki
CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
02
Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8.
CRITICAL
Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors.
03
Multiple vulnerabilities in fast-jwt
CRITICAL
fast-jwt carries 7 CVEs across 4 advisories: Improper Verification of Cryptographic Signature; Insufficient Session Expiration; Improper Validation of Specified Type of Input; createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set; Incomplete patch of Non-whitespace key-prefix re-enables RSA: HS256 algorithm confusion; Verifier cache accepts expired JWTs without iat.
04
PraisonAI: 13 further CVEs in the advisory covered on 2026-10-08
CRITICAL
Follow-up to the 2026-10-08 card. CVE coverage: CVE-2026-61426, CVE-2026-61434, CVE-2026-61445, CVE-2026-61427, CVE-2026-61440, CVE-2026-60085, CVE-2026-60091, CVE-2026-60086, CVE-2026-61433, CVE-2026-61435, CVE-2026-61431, CVE-2026-60088, CVE-2026-61442.
05
Multiple vulnerabilities in Handlebars
CRITICAL
CVE coverage: CVE-2026-106444, CVE-2026-106446, CVE-2026-33937, CVE-2026-106445. The cited advisories disclose: Unsafe Inline Embedding of Precompiled Templates; Own Property Check Bypass.
06
Multiple vulnerabilities in Hazelcast
CRITICAL
Hazelcast carries 2 CVEs across 2 advisories: Arbitrary member memory access by low-privileged client; An authorization bypass in IMap Predicates API. CVE coverage: CVE-2026-107726, CVE-2026-107725.
07
Microsoft Patch Tuesday, October 2026: 7 CVEs across 7 advisories
CRITICAL
Microsoft's October 2026 security update fixes 7 CVEs across 7 advisories (5 critical, 2 high CVEs). Products with the most fixes: Azure API Center (1); Azure App Service (1); Azure Event Grid (1); Azure SRE Agent (1); Microsoft Bookings (1); Microsoft Dataverse (1).
08
Commvault Web Server: Code Injection
HIGH
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.
09
Multiple vulnerabilities in GStreamer Ugly Plugins
HIGH
Michael Randrianantenaina discovered that GStreamer's Ugly Plugins incorrectly handled certain malformed RealMedia files. If a user were tricked into opening a crafted media file, an attacker could possibly use this issue to execute arbitrary code. The notice covers 2 CVEs, including CVE-2023-38103.
10
Multiple vulnerabilities in MariaDB Connector/Node.js
HIGH
MariaDB Connector/Node.js carries 2 CVEs across 2 advisories: Exposure of Sensitive Information to an Unauthorized Actor; Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS. CVE coverage: CVE-2026-107383, CVE-2026-107382.
11
Multiple vulnerabilities in Satel Netco Design
HIGH
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary scripts in a user's browser, consume excessive system resources, enumerate files, create or modify files, and potentially execute arbitrary code.
12
High-severity Nvidia bug could crash GPU monitoring on exposed servers
HIGH
The GPU giant released a fix for the flaw, tracked as CVE-2026-47483 (Unconfirmed, single-source.)
13
libde265: NULL Pointer Dereference
HIGH
It was discovered that libde265 did not properly validate certain crafted H.265 bitstreams, leading to a NULL pointer dereference. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. The assigned identifier is CVE-2026-88373.
14
libgit2: Improper Certificate Validation
MEDIUM
It was discovered that libgit2 incorrectly handled IP address SubjectAltName verification in TLS certificate validation. A remote attacker with a CA-trusted certificate could possibly use this issue to perform a machine-in-the-middle attack, leading to the exposure of sensitive information.
15
SonicWall Releases Critical Security Advisory for SMA1000 Series Appliances
INFO
Security updates address four vulnerabilities, including a maximum severity unauthenticated SSRF vulnerability.

Executive assessment

Today's brief leads with Multiple vulnerabilities in Cisco Meraki. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Panel synthesis: Finding 08 should lead today because it is the only item with in-the-wild exploitation reported and it lists fixed Commvault versions. The nominal first finding, Finding 01, is critical but reports no exploitation. Themes: Exposed management and monitoring interfaces; PoC-backed library and platform flaws; Vendor hardening with available fixes. Patch order: Finding 08 (In-the-wild exploitation is reported, and fixed Commvault versions are listed); Finding 04 (Critical PraisonAI vulnerabilities have PoC exploitation and fixed versions across npm praisonai, PraisonAI, and PraisonAI Platform); Finding 05 (Critical Handlebars vulnerabilities have PoC exploitation and fixed 4.7.9 and 4.7.10 releases listed); Finding 01 (Critical Cisco Meraki hardening release lists fixed versions across multiple product families, although exploitation is none reported); Finding 12 (High-severity NVIDIA issue has PoC exploitation and updated DCGM and DCGM Exporter versions listed).

Also today: 4 more Chromium CVEs (CVE-2025-11215, CVE-2025-11219, CVE-2025-0611, CVE-2025-0612) in the same disclosure wave as the Chromium card of 2026-09-26; none reported exploited; carried as a note rather than a finding.

Finding 01 — Multiple vulnerabilities in Cisco Meraki

What changed: As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

Technical evidence: CVE-2026-76464; CVSS v3.1 9.6; weakness CWE-119; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Analyst note: Cisco PSIRT reports no public announcements or malicious use. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH))

Affected: Cisco Meraki Campus Gateway 32.2 and 33.1; MG Cellular Gateway 26.1; MR Wireless Access Point 30.7, 31.1, 32.2 and 33.1; MS Series Switch 18.1, IOS XE 17.15, 17.18 and 26.1; MV Smart Camera 7. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH))

Fix: Campus Gateway: 32.2.5 (late Oct 2026), 33.1.4 (mid-Nov 2026); MG: 26.1.4; MR: 30.7.3, 31.1.8.1, 32.2.5 (late Oct 2026), 33.1.3; MS: 18.1.9 (mid-Oct 2026), IOS XE 17.15.6, 17.18.4.1 and 26.1.2. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH))

Action: Map CVE-2026-76464 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation reported by the source, not independently corroborated

[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Meraki%20Security%20Hardening%20Release:%20October%202026%26vs_k=1)

Finding 02 — Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8.

What changed: Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors. CVE coverage: CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894.

Technical evidence: CVE-2015-3306; CVSS v3.1 10; weakness CWE-284; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Panel assessment: Patch now where any affected product is externally reachable: KEV-confirmed exploitation, 100th-percentile EPSS and automated scanning mean old CVEs should be treated as live entry points, not backlog hygiene. The likely path is broad discovery and exploitation, followed by hands-on activity to expand access and steal credentials or sensitive data from reachable systems. (priority: patch now)

Action: Map CVE-2015-3306 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: cisa.gov](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a)

Finding 03 — Multiple vulnerabilities in fast-jwt

What changed: fast-jwt carries 7 CVEs across 4 advisories: Improper Verification of Cryptographic Signature; Insufficient Session Expiration; Improper Validation of Specified Type of Input; createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set; Incomplete patch of Non-whitespace key-prefix re-enables RSA: HS256 algorithm confusion; Verifier cache accepts expired JWTs without iat. CVE coverage: CVE-2026-107720, CVE-2026-107722, CVE-2026-34950, CVE-2026-107719, CVE-2026-107724, CVE-2026-107721, CVE-2026-107723.

Technical evidence: CVE-2026-107720; CVSS v3.1 7.4; weakness CWE-20, CWE-347; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-107720 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-8wpc-h4q6-8fxv)

Finding 04 — PraisonAI: 13 further CVEs in the advisory covered on 2026-10-08

What changed: Follow-up to the 2026-10-08 card. CVE coverage: CVE-2026-61426, CVE-2026-61434, CVE-2026-61445, CVE-2026-61427, CVE-2026-61440, CVE-2026-60085, CVE-2026-60091, CVE-2026-60086, CVE-2026-61433, CVE-2026-61435, CVE-2026-61431, CVE-2026-60088, CVE-2026-61442. The cited advisories disclose: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure; Shell command allowlist bypass via find -exec built-in action; AICoder Arbitrary File Write and Command Execution via LLM Tool Calls; MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface; Platform members can rewrite shared labels and owner issue labels without owner/admin authorization; SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend; Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF; Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked; API deploy code generator embeds unescaped YAML fields into Python source; Call API localhost-only authentication bypass via spoofed Host header; ContextGatherer include resolution permits absolute and traversal reads outside the workspace; Project custom command templates can read outside-workspace files into model prompts; Platform member PATCH routes allow owner resource rewrites and project lead reassignment delete bypass.

Technical evidence: CVE-2026-61445; CVSS v4.0 9.4; weakness CWE-22; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Bind AgentOS to 127.0.0.1, require an API key for non-loopback use, remove wildcard CORS with credentials, and do not expose full instructions through unauthenticated endpoints. For untrusted code, use the native Landlock/Seatbelt backend instead of the unenforced subprocess backend. ([github.com](https://github.com/advisories/GHSA-6wjp-v33h-5cvq), [github.com](https://github.com/advisories/GHSA-cv3g-hj65-pcfh), [github.com](https://github.com/advisories/GHSA-5r6c-gj4g-r697), +1 more)

Affected: npm praisonai <1.7.3; PraisonAI <=4.6.77; PraisonAI Platform <=0.1.8. ([github.com](https://github.com/advisories/GHSA-6wjp-v33h-5cvq), [github.com](https://github.com/advisories/GHSA-cv3g-hj65-pcfh), [github.com](https://github.com/advisories/GHSA-xxgv-vgvj-qvxh))

Fix: npm praisonai 1.7.3; PraisonAI 4.6.78; PraisonAI Platform 0.1.9. ([github.com](https://github.com/advisories/GHSA-6wjp-v33h-5cvq), [github.com](https://github.com/advisories/GHSA-cv3g-hj65-pcfh), [github.com](https://github.com/advisories/GHSA-xxgv-vgvj-qvxh))

Action: Map CVE-2026-61445 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-6wjp-v33h-5cvq)

Finding 05 — Multiple vulnerabilities in Handlebars

What changed: CVE coverage: CVE-2026-106444, CVE-2026-106446, CVE-2026-33937, CVE-2026-106445. The cited advisories disclose: Unsafe Inline Embedding of Precompiled Templates; Own Property Check Bypass.

Technical evidence: CVE-2026-106446; CVSS v3.1 9.8; weakness CWE-94, CWE-843; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Require template inputs to Handlebars.compile() and Handlebars.precompile() to be strings; where templates are precompiled at build time, use the runtime-only build so compile() is unavailable. Do not enable allowProtoMethodsByDefault for untrusted templates and data, and do not inline precompiled output from untrusted templates into HTML; serve it as external JavaScript where practical. ([github.com](https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-xw65-4hp5-5hc7), [github.com](https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-8r5x-fm3f-whwj), [github.com](https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-2w6w-674q-4c4q), +1 more)

Affected: Handlebars >=4.0.0 and <=4.7.9 for CVE-2026-106444, CVE-2026-106445 and CVE-2026-106446; >=4.0.0 and <=4.7.8 for CVE-2026-33937. ([github.com](https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-8r5x-fm3f-whwj), [github.com](https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-2w6w-674q-4c4q))

Fix: Handlebars 4.7.10 for CVE-2026-106444, CVE-2026-106445 and CVE-2026-106446; 4.7.9 for CVE-2026-33937. ([github.com](https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-8r5x-fm3f-whwj), [github.com](https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-2w6w-674q-4c4q))

Action: Map CVE-2026-106446 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-xw65-4hp5-5hc7)

Finding 06 — Multiple vulnerabilities in Hazelcast

What changed: Hazelcast carries 2 CVEs across 2 advisories: Arbitrary member memory access by low-privileged client; An authorization bypass in IMap Predicates API. CVE coverage: CVE-2026-107726, CVE-2026-107725.

Technical evidence: CVE-2026-107726; CVSS v4.0 9.3; weakness CWE-20; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-107726 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-6v25-8wq6-xq4j)

Finding 07 — Microsoft Patch Tuesday, October 2026: 7 CVEs across 7 advisories

What changed: Microsoft's October 2026 security update fixes 7 CVEs across 7 advisories (5 critical, 2 high CVEs). Products with the most fixes: Azure API Center (1); Azure App Service (1); Azure Event Grid (1); Azure SRE Agent (1); Microsoft Bookings (1); Microsoft Dataverse (1).

Technical evidence: CVE-2026-77900; CVSS v3.1 9.8; weakness CWE-306; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-77900 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77900)

Finding 08 — Commvault Web Server: Code Injection

What changed: Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.

Technical evidence: CVE-2025-3928; CVSS v3.1 8.8; weakness CWE-94; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Analyst note: Restrict Commvault management interfaces to trusted networks and administrative systems, and remove external access. Deploy a web application firewall to block path-traversal attempts and suspicious file uploads; monitor unexpected activity in web-accessible directories. Commvault reports that its forensic investigation found a threat actor had exploited a zero-day vulnerability. ([cisa.gov](https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud-application-metallic), [commvault.com](https://www.commvault.com/blogs/security-advisory-march-7-2025), [documentation.commvault.com](https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html))

Affected: Commvault on Linux and Windows: 11.36.0–11.36.45, 11.32.0–11.32.88, 11.28.0–11.28.140 and 11.20.0–11.20.216. ([documentation.commvault.com](https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html))

Fix: 11.36.46 or higher, 11.32.89 or higher, 11.28.141 or higher and 11.20.217 or higher. ([documentation.commvault.com](https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html))

Action: Map CVE-2025-3928 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-3928)

Finding 09 — Multiple vulnerabilities in GStreamer Ugly Plugins

What changed: Michael Randrianantenaina discovered that GStreamer's Ugly Plugins incorrectly handled certain malformed RealMedia files. If a user were tricked into opening a crafted media file, an attacker could possibly use this issue to execute arbitrary code.

Technical evidence: CVE-2023-38103; CVSS v3.1 8.8; weakness CWE-190; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Affected: GStreamer gst-plugins-ugly 1.x before 1.22.5, 1.x before 1.20.7, and 0.10.x. ([gstreamer.freedesktop.org](https://gstreamer.freedesktop.org/security/sa-2023-0004.html), [gstreamer.freedesktop.org](https://gstreamer.freedesktop.org/security/sa-2023-0005.html))

Fix: Upstream: gst-plugins-ugly 1.22.5 or 1.20.7. Ubuntu: 1.20.1-1ubuntu0.1~esm1 (22.04 LTS), 1.16.2-2ubuntu0.1~esm1 (20.04 LTS), 1.14.5-0ubuntu1~18.04.1+esm1 (18.04 LTS). ([gstreamer.freedesktop.org](https://gstreamer.freedesktop.org/security/sa-2023-0004.html), [gstreamer.freedesktop.org](https://gstreamer.freedesktop.org/security/sa-2023-0005.html), [ubuntu.com](https://ubuntu.com/security/CVE-2023-38103))

Action: Map CVE-2023-38103 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8896-1)

Finding 10 — Multiple vulnerabilities in MariaDB Connector/Node.js

What changed: MariaDB Connector/Node.js carries 2 CVEs across 2 advisories: Exposure of Sensitive Information to an Unauthorized Actor; Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS. CVE coverage: CVE-2026-107383, CVE-2026-107382.

Technical evidence: CVE-2026-107383; CVSS v3.1 7.5; weakness CWE-200; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-107383 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-48qf-xh34-q73r)

Finding 11 — Multiple vulnerabilities in Satel Netco Design

What changed: Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary scripts in a user's browser, consume excessive system resources, enumerate files, create or modify files, and potentially execute arbitrary code. CVE coverage: CVE-2026-105269, CVE-2026-104628, CVE-2026-105275, CVE-2026-101024.

Technical evidence: CVE-2026-105269; CVSS v4.0 8.5; weakness CWE-79; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Block internet access to all control-system devices and systems. Place control-system networks and remote devices behind firewalls and isolate them from business networks. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03))

Affected: Satel Netco Design versions prior to v2.1.7. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03))

Fix: Satel Netco Design v2.1.7. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03))

Action: Map CVE-2026-105269 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03)

Finding 12 — High-severity Nvidia bug could crash GPU monitoring on exposed servers

What changed: The GPU giant released a fix for the flaw, tracked as CVE-2026-47483 (Unconfirmed, single-source.)

Technical evidence: CVE-2026-47483; CVSS v3.1 8.2; weakness CWE-770; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Bind exporters to loopback or private interfaces and restrict access so only monitoring infrastructure can reach them. If profiling is not explicitly required, disable --enable-pprof. Lava reports testing the resource-exhaustion exploit in a controlled environment, not against public deployments. ([lava.security](https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability), [nvidia.custhelp.com](https://nvidia.custhelp.com/app/answers/detail/a_id/5857))

Affected: NVIDIA lists DCGM 0.0 to 4.5.2 and DCGM Exporter 0.0 to 4.8.2 as affected on all platforms. ([nvidia.custhelp.com](https://nvidia.custhelp.com/app/answers/detail/a_id/5857))

Fix: NVIDIA lists DCGM 4.5.3 and DCGM Exporter 4.8.2 as the updated versions. ([nvidia.custhelp.com](https://nvidia.custhelp.com/app/answers/detail/a_id/5857))

Action: Map CVE-2026-47483 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: theregister.com](https://www.theregister.com/security/2026/10/08/high-severity-nvidia-bug-could-crash-gpu-monitoring-on-exposed-servers/5302077)

Finding 13 — libde265: NULL Pointer Dereference

What changed: It was discovered that libde265 did not properly validate certain crafted H.265 bitstreams, leading to a NULL pointer dereference. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service.

Technical evidence: CVE-2026-88373; CVSS v3.1 7.5; weakness CWE-476; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Drop zero-length H.265 NAL inputs before passing them to libde265. CISA's ADP record reports proof-of-concept exploitation. ([github.com](https://github.com/strukturag/libde265/issues/534), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-88373), [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-88373), +1 more)

Affected: libde265 HEAD build 4d45a6b. ([github.com](https://github.com/strukturag/libde265/issues/534))

Fix: Fixed by: https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea (v1.1.2) ([security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-88373), [ubuntu.com](https://ubuntu.com/security/notices/USN-8909-1?format=md))

Action: Map CVE-2026-88373 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8909-1)

Finding 14 — libgit2: Improper Certificate Validation

What changed: It was discovered that libgit2 incorrectly handled IP address SubjectAltName verification in TLS certificate validation. A remote attacker with a CA-trusted certificate could possibly use this issue to perform a machine-in-the-middle attack, leading to the exposure of sensitive information.

Technical evidence: CVE-2026-53583; CVSS v3.1 6.5; weakness CWE-295, CWE-297; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Analyst note: Prevent libgit2 connections to IP-literal HTTPS URLs and require DNS-name URLs instead. Alternatively, use a non-OpenSSL TLS backend such as SecureTransport, Schannel/WinHTTP or mbedTLS. ([github.com](https://github.com/libgit2/libgit2/security/advisories/GHSA-h7gc-w2gg-p9xp), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-53583), [ubuntu.com](https://ubuntu.com/security/notices/USN-8907-1))

Affected: "version":">= 1.9.0, < 1.9.5","status":"affected" ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-53583))

Fix: Upstream libgit2 1.8.6 and 1.9.5; Ubuntu 1.9.1+ds-1ubuntu1.3 for 26.04 LTS and 1.7.2+ds-1ubuntu3.3 for 24.04 LTS. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-53583), [ubuntu.com](https://ubuntu.com/security/notices/USN-8907-1))

Panel assessment: Patch this week: the issue has PoC-level exploitability, but the practical exposure is narrow because it requires OpenSSL-backed libgit2 making HTTPS connections to IP-literal URLs and a CA-trusted certificate. The likely attack path is an on-path attacker presenting a certificate for the wrong IP that libgit2 accepts, exposing Git credentials and repository data in clone, fetch or push traffic using those IP-addressed endpoints. (priority: this week)

Action: Map CVE-2026-53583 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8907-1)

Finding 15 — SonicWall Releases Critical Security Advisory for SMA1000 Series Appliances

What changed: Security updates address four vulnerabilities, including a maximum severity unauthenticated SSRF vulnerability.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

fixed version or patch state unknown

[Evidence source: digital.nhs.uk](https://digital.nhs.uk/cyber-alerts/2026/cc-4863)

cve-2014-6278cve-2015-3306cve-2023-38103cve-2025-3928cve-2026-105269cve-2026-106444cve-2026-107383cve-2026-107720cve-2026-107726cve-2026-47483

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.