1 vulnerability across 1 product scored HIGH or above on September 25, 2026.
- ๐ HIGH: 1
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-09-24 bulletin.
- [UPGRADED] CVE-2026-28325 (solarwinds/observability_self-hosted) โ F1: exploitable โ functional, AAS: 9.6 โ 11.6 (HIGH โ HIGH). Originally in 2026-09-22 bulletin.
- [UPGRADED] CVE-2026-77521 (1panel-dev/maxkb) โ F1: exploitable โ functional, AAS: 11.2 โ 13.2 (HIGH โ CRITICAL). Originally in 2026-09-21 bulletin.
- [UPGRADED] CVE-2026-93603 (patriksimek/vm2) โ F1: exploitable โ functional, AAS: 12.7 โ 14.7 (CRITICAL โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-93605 (patriksimek/vm2) โ F1: exploitable โ functional, AAS: 12.7 โ 14.7 (CRITICAL โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-93606 (patriksimek/vm2) โ F1: theoretical โ functional, AAS: 11.7 โ 14.7 (HIGH โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-82340 (ibm/guardium_data_protection) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-81657 (ibm/guardium_data_protection) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-09-18 bulletin.
- [UPGRADED] CVE-2026-84383 (strukturag/libheif) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-09-18 bulletin.
๐ [HIGH] netgate/pfsense_plus
1 CVE | CVSS 3.1: 8.5 | AAS 9.5
cpe:2.3:a:netgate:pfsense_plus:*:*:*:*:*:*:*:*(< 26.07)
Netgate pfSense Plus (before 26.07) and pfSense CE (before 2.9.0) are affected by one high-severity vulnerability (CVE-2026-97730, CVSS 8.5) involving a local file inclusion flaw in the web GUI Dashboard. An authenticated attacker who can modify Dashboard widget settings and write files to the system can exploit path traversal in the widget sequence handler to achieve arbitrary PHP code execution, potentially leading to full firewall compromise.
Network and security teams running pfSense in any capacity should prioritize this update immediately, as pfSense appliances typically sit at critical network boundaries. Upgrade to pfSense Plus 26.07 or pfSense CE 2.9.0 or later, and review the vendor advisory at docs.netgate.com for additional details.
- ๐ CVE-2026-97730 (CVSS 3.1: 8.5)