3 vulnerabilities across 2 products scored HIGH or above on September 27, 2026.
- π HIGH: 3
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-93577 (gitlab/gitlab) β F1: exploitable β functional, AAS: 11.9 β 13.9 (HIGH β CRITICAL). Originally in 2026-09-24 bulletin.
- [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-09-24 bulletin.
- [UPGRADED] CVE-2026-28325 (solarwinds/observability_self-hosted) β F1: exploitable β functional, AAS: 9.6 β 11.6 (HIGH β HIGH). Originally in 2026-09-22 bulletin.
- [UPGRADED] CVE-2026-77521 (1panel-dev/maxkb) β F1: exploitable β functional, AAS: 11.2 β 13.2 (HIGH β CRITICAL). Originally in 2026-09-21 bulletin.
π [HIGH] patriksimek/vm2
2 CVEs | CVSS 4.0: 9.5 | AAS 11.3
cpe:2.3:a:patriksimek:vm2:*:*:*:*:*:*:*:*
Two high-severity vulnerabilities have been identified in patriksimek’s vm2 JavaScript sandbox library, versions prior to 3.12.2. The flaws include multiple issues in the NodeVM external-module resolver, where insufficient path boundary validation allows untrusted guest code to bypass authorization controls and potentially escape the sandbox when custom resolvers are configured with host context. Security teams running applications that rely on vm2 for sandboxing untrusted JavaScript should update to version 3.12.2 or later immediately, noting that vm2 has been broadly deprecated in favor of alternatives; organizations still depending on it should also evaluate migration to actively maintained sandboxing solutions. Refer to the vendor’s GitHub commit for patch details.
- π CVE-2026-100721 (CVSS 4.0: 9.5)
- π CVE-2026-100722 (CVSS 4.0: 8.9)
π [HIGH] project-monai/monai
1 CVE | CVSS 4.0: 8.6 | AAS 9.0
cpe:2.3:a:project-monai:monai:*:*:*:*:*:*:*:*
A high-severity OS command injection vulnerability has been disclosed in Project MONAI’s MONAI medical imaging framework, affecting versions prior to 1.6.0. The flaw resides in the nnUNetV2Runner component, where user-controlled values from YAML configuration files and CLI arguments are passed unsanitized to shell commands, allowing an attacker who can supply a crafted configuration file to execute arbitrary operating system commands on both Linux and Windows hosts. Teams using MONAI for medical imaging AI workflows should upgrade to version 1.6.0 or later immediately and audit any untrusted configuration files previously loaded into nnUNet pipelines; see the vendor’s GitHub security advisory for full details.
- π CVE-2026-100844 (CVSS 4.0: 8.6)