17 vulnerabilities across 8 products scored HIGH or above on September 28, 2026.
- π΄ CRITICAL: 1
- π HIGH: 16
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-09-26 bulletin.
- [UPGRADED] CVE-2026-93577 (gitlab/gitlab) β F1: exploitable β functional, AAS: 11.9 β 13.9 (HIGH β CRITICAL). Originally in 2026-09-24 bulletin.
- [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-09-24 bulletin.
- [UPGRADED] CVE-2026-28325 (solarwinds/observability_self-hosted) β F1: exploitable β functional, AAS: 9.6 β 11.6 (HIGH β HIGH). Originally in 2026-09-22 bulletin.
- [UPGRADED] CVE-2026-77521 (1panel-dev/maxkb) β F1: exploitable β functional, AAS: 11.2 β 13.2 (HIGH β CRITICAL). Originally in 2026-09-21 bulletin.
π΄ [CRITICAL] apache_software_foundation/apache_roller
5 CVEs | CVSS 3.1: 9.9 | AAS 13.4
cpe:2.3:a:apache:apache_roller:*:*:*:*:*:*:*:*
Apache Roller is affected by five vulnerabilities, including at least one critical-severity issue (CVSS 9.9) involving deserialization of untrusted data at the XML-RPC endpoint, which allows unauthenticated remote code execution without any non-default configuration. A functional exploit exists, significantly raising the urgency for remediation. Organizations running Apache Roller 6.1.5 or earlier should immediately review the vendor advisory at the linked GitHub pull request, apply available patches, and consider disabling or restricting access to the XML-RPC servlet as an interim mitigation until updates are fully deployed.
- π΄ CVE-2026-82384 (CVSS 3.1: 9.8)
- π CVE-2026-82377 (CVSS 3.1: 9.9)
- π CVE-2026-82378 (CVSS 3.1: 9.0)
- π CVE-2026-82383 (CVSS 3.1: 8.2)
- π CVE-2026-82380 (CVSS 3.1: 8.1)
π [HIGH] apple/ios_and_ipados
1 CVE | CVSS 3.1: 8.8 | AAS 11.1
cpe:2.3:a:apple:ios_and_ipados:*:*:*:*:*:*:*:*
Apple iOS and iPadOS are affected by a high-severity out-of-bounds write vulnerability (CVSS 8.8) that allows arbitrary code execution when a user processes a maliciously crafted file. Apple has confirmed this flaw has been exploited in the wild as part of a sophisticated targeted attack against specific individuals, and the issue also affects macOS Sequoia and macOS Tahoe. All organizations and individuals running affected Apple devices should immediately update to iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1 by reviewing the vendor advisory at the linked Apple support page.
- π CVE-2026-86950 (CVSS 3.1: 8.8)
π [HIGH] canonical/lxd
3 CVEs | CVSS 3.1: 9.9 | AAS 11.1
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
Canonical LXD versions 4.0 and later are affected by three vulnerabilities, including at least one critical-severity issue (CVSS 9.9) that allows an authenticated client to exploit improper symlink resolution in the migration receive path to write attacker-controlled files to arbitrary locations on the host as root, resulting in full host compromise. These flaws are considered exploitable and impact any environment using LXD for container or virtual machine management where project-level instance or storage volume creation is permitted. Administrators should immediately upgrade to LXD 4.0.14, 5.0.10, 5.21.8, or 6.10 and review the vendor advisory at the linked GitHub security page for additional hardening guidance.
- π CVE-2026-87799 (CVSS 3.1: 9.9)
- π CVE-2026-85526 (CVSS 3.1: 9.9)
- π CVE-2026-85185 (CVSS 3.1: 9.6)
π [HIGH] rancher/rancher
1 CVE | CVSS 3.1: 9.6 | AAS 10.7
cpe:2.3:a:rancher:rancher:*:*:*:*:*:*:*:*
SUSE Rancher is affected by a critical-severity vulnerability (CVSS 9.6) that allows unauthenticated remote attackers to modify public UI settings and execute a stored cross-site scripting attack through the Rancher management interface. This flaw impacts Rancher versions 2.11 through 2.15, affecting any organization using Rancher for Kubernetes cluster management. Administrators should upgrade immediately to Rancher 2.15.2, 2.14.6, 2.13.10, 2.12.14, or 2.11.18 depending on their release track, and review the vendor advisory at the linked GitHub security page for further details.
- π CVE-2026-88804 (CVSS 3.1: 9.6)
π [HIGH] axios/axios
4 CVEs | CVSS 4.0: 8.3 | AAS 10.4
cpe:2.3:a:axios:axios:*:*:*:*:*:*:*:*
Axios, the widely used promise-based HTTP client for browsers and Node.js, is affected by four vulnerabilities, including at least one high-severity issue (CVSS 8.3) involving prototype pollution that allows attackers to manipulate serialization options in the toFormData function, potentially altering request behavior, forcing request failures, or enabling server-side request forgery. These flaws are considered exploitable and impact Axios versions 0.28.0 through 0.33.x and 1.15.1 through 1.19.x, affecting a vast number of applications given the library’s widespread adoption across JavaScript ecosystems. Development and security teams should immediately update to Axios 0.34.0 or 1.20.0 and review the linked commit for details on the fixes applied.
- π CVE-2026-101909 (CVSS 4.0: 8.3)
- π CVE-2026-101901 (CVSS 4.0: 8.2)
- π CVE-2026-101903 (CVSS 4.0: 8.2)
- π CVE-2026-101906 (CVSS 4.0: 8.2)
π [HIGH] nestjs/nest
1 CVE | CVSS 3.1: 7.5 | AAS 9.3
cpe:2.3:a:nestjs:nest:*:*:*:*:*:*:*:*(< 11.2.4)cpe:2.3:a:nestjs:nest:*:*:*:*:*:*:*:*(>= 12.0.0, < 12.0.2)
NestJS, a popular Node.js server-side application framework, is affected by a high-severity denial-of-service vulnerability (CVSS 7.5) where a single message containing a deeply nested object pattern can crash microservices using TCP or RabbitMQ transports by triggering an unhandled stack overflow during JSON.stringify processing. This flaw is considered exploitable and impacts any NestJS microservice prior to versions 11.2.4 and 12.0.2 that accepts external messages on these transports. Teams running NestJS microservices should upgrade immediately to version 11.2.4 or 12.0.2 and review the linked commit for details on the fix.
- π CVE-2026-102281 (CVSS 3.1: 7.5)
π [HIGH] ordasoft.com/real_estate_manager_(free)_extension_for_joomla
1 CVE | CVSS 4.0: 9.3 | AAS 9.2
cpe:2.3:a:ordasoft.com:real_estate_manager_free_extension_for_joomla:*:*:*:*:*:*:*:*(< 6.7.9)
The Real Estate Manager (Free) extension for Joomla by OrdaSoft is affected by a critical-severity unauthenticated SQL injection vulnerability (CVSS 9.3) where the order_field request parameter is concatenated directly into ORDER BY clauses across multiple frontend property-listing queries without any input validation or allow-listing. This flaw is considered exploitable and requires no authentication, putting any Joomla site running this extension at risk of full database compromise. Site administrators should immediately update to Real Estate Manager version 6.7.9 or later and review the vendor’s website for additional guidance.
- π CVE-2026-100752 (CVSS 4.0: 9.3)
π [HIGH] suse/rancher
1 CVE | CVSS 3.1: 8.8 | AAS 9.1
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
SUSE Rancher is affected by a high-severity vulnerability (CVSS 8.8) in Rancher Fleet where the Fleet agent writes resources to downstream clusters using its own cluster-admin credentials instead of the intended pinned ServiceAccount, allowing tenants in shared multi-cluster environments to overwrite configuration files beyond their authorized scope. This flaw is particularly concerning for organizations operating multi-tenancy Rancher deployments where different privileged or untrusted teams share downstream clusters. Administrators should upgrade SUSE Rancher Fleet from version 0.16 to the latest patched release and review the vendor advisory at the linked GitHub security page for remediation details.
- π CVE-2026-88808 (CVSS 3.1: 8.8)