2 vulnerabilities across 1 product scored HIGH or above on September 08, 2026.
- π HIGH: 2
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-85046 (google/chrome) β F1: exploitable β functional, AAS: 10.6 β 12.6 (HIGH β CRITICAL). Originally in 2026-09-03 bulletin.
- [UPGRADED] CVE-2026-20212 (cisco/cisco_nx-os_software) β F1: theoretical β poc, AAS: 10.9 β 11.6 (HIGH β HIGH). Originally in 2026-09-02 bulletin.
π [HIGH] hitachi/cosminexus_component_container
2 CVEs | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:hitachi:cosminexus_component_container:*:*:*:*:*:*:*:*(>= 11-70-01, < 11-70-03)cpe:2.3:a:hitachi:cosminexus_component_container:*:*:*:*:*:*:*:*(>= 11-60, < 11-60-03)cpe:2.3:a:hitachi:cosminexus_component_container:*:*:*:*:*:*:*:*(>= 11-50)cpe:2.3:a:hitachi:cosminexus_component_container:*:*:*:*:*:*:*:*(>= 11-40)cpe:2.3:a:hitachi:cosminexus_component_container:*:*:*:*:*:*:*:*(>= 11-30)
Hitachi Cosminexus Component Container is affected by 2 vulnerabilities, including at least one critical command argument injection flaw rated CVSS 9.8. A wide range of versions are impacted, spanning major release lines from 09-00 through 11-70, and the issues are considered exploitable. Organizations running Cosminexus Component Container in Java EE application environments should treat this as a high-priority patch cycle.
Security teams should review Hitachi’s advisory at the link above, identify all deployed versions across their environment, and upgrade to the corresponding fixed releases immediately. Given the severity and exploitability of command injection at this level, unpatched instances should be considered at significant risk of remote compromise.
- π CVE-2026-71377 (CVSS 3.1: 9.8)
- π CVE-2026-71376 (CVSS 3.1: 9.8)