3 vulnerabilities across 2 products scored HIGH or above on September 24, 2026.

  • ๐ŸŸ  HIGH: 3

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-28325 (solarwinds/observability_self-hosted) โ€” F1: exploitable โ†’ functional, AAS: 9.6 โ†’ 11.6 (HIGH โ†’ HIGH). Originally in 2026-09-22 bulletin.
  • [UPGRADED] CVE-2026-77521 (1panel-dev/maxkb) โ€” F1: exploitable โ†’ functional, AAS: 11.2 โ†’ 13.2 (HIGH โ†’ CRITICAL). Originally in 2026-09-21 bulletin.
  • [UPGRADED] CVE-2026-93603 (patriksimek/vm2) โ€” F1: exploitable โ†’ functional, AAS: 12.7 โ†’ 14.7 (CRITICAL โ†’ CRITICAL). Originally in 2026-09-18 bulletin.
  • [UPGRADED] CVE-2026-93605 (patriksimek/vm2) โ€” F1: exploitable โ†’ functional, AAS: 12.7 โ†’ 14.7 (CRITICAL โ†’ CRITICAL). Originally in 2026-09-18 bulletin.
  • [UPGRADED] CVE-2026-93606 (patriksimek/vm2) โ€” F1: theoretical โ†’ functional, AAS: 11.7 โ†’ 14.7 (HIGH โ†’ CRITICAL). Originally in 2026-09-18 bulletin.
  • [UPGRADED] CVE-2026-81657 (ibm/guardium_data_protection) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 12.9 (HIGH โ†’ CRITICAL). Originally in 2026-09-18 bulletin.
  • [UPGRADED] CVE-2026-84383 (strukturag/libheif) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 12.9 (HIGH โ†’ CRITICAL). Originally in 2026-09-18 bulletin.
  • [UPGRADED] CVE-2026-28326 (solarwinds/access_rights_manager) โ€” F1: exploitable โ†’ functional, AAS: 10.1 โ†’ 12.1 (HIGH โ†’ CRITICAL). Originally in 2026-09-17 bulletin.

๐ŸŸ  [HIGH] gitlab/gitlab

2 CVEs | CVSS 3.1: 9.9 | AAS 11.9

  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

GitLab CE/EE versions 19.2 through 19.2.6, 19.3 through 19.3.2, and 19.4.0 are affected by 2 vulnerabilities, including at least one critical-severity flaw rated CVSS 9.9 that allows an authenticated user to achieve arbitrary code execution on the GitLab server via a double-free triggered by specially crafted regular expressions in CI/CD configurations. Organizations running self-managed GitLab instances should treat this as high priority, as the exploitability of the RCE issue poses significant risk to source code integrity and infrastructure security. Upgrade immediately to GitLab 19.4.1, 19.3.3, or 19.2.7 per the vendor advisory at docs.gitlab.com.

Vendor Advisory


๐ŸŸ  [HIGH] signoz/signoz

1 CVE | CVSS 4.0: 9.2 | AAS 9.5

  • cpe:2.3:a:signoz:signoz:*:*:*:*:*:*:*:* (>= 0.8.0, < 0.143.0)

SigNoz versions 0.8.0 through 0.142.x are affected by a high-severity vulnerability (CVSS 9.2) in which the JWT signing secret defaults to an empty string when not explicitly configured, allowing an unauthenticated attacker to forge valid session tokens and gain unauthorized access to the platform. Teams running self-hosted SigNoz deployments should immediately verify whether the SIGNOZ_TOKENIZER_JWT_SECRET environment variable is set to a strong, non-empty value, and upgrade to version 0.143.0 or later, which addresses the issue. Even after upgrading, any deployment that previously ran with the default empty secret should rotate the signing key and invalidate all existing sessions.

Vendor Advisory