2 vulnerabilities across 1 product scored HIGH or above on September 20, 2026.

  • ๐ŸŸ  HIGH: 2

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-84383 (strukturag/libheif) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 12.9 (HIGH โ†’ CRITICAL). Originally in 2026-09-18 bulletin.
  • [UPGRADED] CVE-2026-12793 (jetmonsters/jetformbuilder_โ€”_dynamic_blocks_form_builder) โ€” F1: exploitable โ†’ functional, AAS: 10.1 โ†’ 12.1 (HIGH โ†’ CRITICAL). Originally in 2026-09-16 bulletin.

๐ŸŸ  [HIGH] oisf/suricata

2 CVEs | CVSS 3.1: 9.4 | AAS 10.9

  • cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* (>= 8.0.0, < 8.0.7)

OISF Suricata versions prior to 8.0.7 are affected by 2 vulnerabilities, including at least one rated CVSS 9.4 HIGH. The most severe issue is a use-after-free in the HTTP/2 multi-buffer handling that can be triggered when transaction inspection rules use http.response_header with and without a transform, potentially allowing an attacker to compromise the integrity of network security monitoring or achieve code execution on the sensor. Organizations running Suricata as an IDS/IPS should treat this as a high-priority update, as exploitation could allow adversaries to evade detection or disable network defenses entirely.

All Suricata deployments running versions before 8.0.7 should upgrade immediately. Review the vendor advisory at forum.suricata.io for full details and confirm that updated rule sets are deployed alongside the patched engine.

Vendor Advisory