3 vulnerabilities across 2 products scored HIGH or above on September 22, 2026.
- ๐ HIGH: 3
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-93603 (patriksimek/vm2) โ F1: exploitable โ functional, AAS: 12.7 โ 14.7 (CRITICAL โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-93605 (patriksimek/vm2) โ F1: exploitable โ functional, AAS: 12.7 โ 14.7 (CRITICAL โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-93606 (patriksimek/vm2) โ F1: theoretical โ functional, AAS: 11.7 โ 14.7 (HIGH โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-84383 (strukturag/libheif) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-12793 (jetmonsters/jetformbuilder_โ_dynamic_blocks_form_builder) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-09-16 bulletin.
๐ [HIGH] qualcomm,_inc./snapdragon
1 CVE | CVSS 3.1: 9.8 | AAS 10.9
cpe:2.3:a:qualcomm:snapdragon:*:*:*:*:*:*:*:*
Qualcomm Snapdragon chipsets are affected by one critical vulnerability (CVE-2026-25254, CVSS 9.8) involving improper authorization that enables remote code execution via the SocketIO interface. Organizations deploying devices powered by Snapdragon processors, including mobile handsets, IoT devices, and embedded platforms, should treat this as a high-priority issue given the severity and exploitability of the flaw. Administrators should consult the Qualcomm May 2026 security bulletin at https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html for affected chipset details and apply available firmware updates immediately.
- ๐ CVE-2026-25254 (CVSS 3.1: 9.8)
๐ [HIGH] erlang/otp
2 CVEs | CVSS 4.0: 9.3 | AAS 10.6
cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= 25.0, < 25.3.2.21)cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= 26.0, < 26.2.5.12)cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= 27.0, < 27.3.4)cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= 28.0, < 28.0.1)
Erlang/OTP is affected by two high-severity vulnerabilities, including at least one (CVE-2026-89422, CVSS 9.3) that allows an attacker to impersonate a TLS 1.3 server by injecting a pre_shared_key extension the client never offered, causing the handshake to complete without certificate validation. Teams running Erlang/OTP-based infrastructure, particularly systems relying on TLS 1.3 for secure communications such as RabbitMQ, ejabberd, or custom BEAM applications, should prioritize remediation. Review the vendor advisory at https://cna.erlef.org/cves/CVE-2026-89422.html and upgrade to a patched OTP release immediately.
- ๐ CVE-2026-89422 (CVSS 4.0: 9.3)
- ๐ CVE-2026-65634 (CVSS 4.0: 8.2)