3 vulnerabilities across 3 products scored HIGH or above on September 29, 2026.

  • 🟠 HIGH: 3

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) β€” F1: exploitable β†’ functional, AAS: 10.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-09-26 bulletin.
  • [UPGRADED] CVE-2026-93577 (gitlab/gitlab) β€” F1: exploitable β†’ functional, AAS: 11.9 β†’ 13.9 (HIGH β†’ CRITICAL). Originally in 2026-09-24 bulletin.
  • [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) β€” F1: exploitable β†’ functional, AAS: 10.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-09-24 bulletin.
  • [UPGRADED] CVE-2026-28325 (solarwinds/observability_self-hosted) β€” F1: exploitable β†’ functional, AAS: 9.6 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-09-22 bulletin.

🟠 [HIGH] hitachi_energy/rtu500_series_cmu_firmware

1 CVE | CVSS 3.1: 9.1 | AAS 10.0

  • cpe:2.3:a:hitachi_energy:rtu500_series_cmu_firmware:*:*:*:*:*:*:*:*

Hitachi Energy RTU500 Series CMU firmware is affected by one critical-severity vulnerability (CVE-2026-8066, CVSS 9.1) involving a directory traversal flaw in the file upload functionality that allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system, potentially leading to unauthorized data modification or disruption of device operations. Organizations deploying RTU500 series remote terminal units in operational technology and industrial control system environments should treat this as a high-priority patching item, as the vulnerability requires no authentication to exploit. Administrators should review the vendor advisory at publisher.hitachienergy.com and apply available firmware updates immediately, restricting network access to affected devices in the interim.

Vendor Advisory


🟠 [HIGH] gitlab/gitlab

1 CVE | CVSS 3.1: 8.7 | AAS 10.0

  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

GitLab CE/EE is affected by one high-severity vulnerability (CVE-2026-84739, CVSS 8.7) that allows an authenticated user to execute arbitrary JavaScript in another user’s browser session through improper sanitization of path components in the merge request diff viewer, impacting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. Any organization running a self-managed GitLab instance should prioritize this update, as the stored cross-site scripting flaw could be leveraged to hijack sessions, steal credentials, or perform actions on behalf of privileged users. Administrators should upgrade immediately to GitLab 19.4.1, 19.3.3, or 19.2.7 as appropriate, and review the vendor advisory for additional detail.

Vendor Advisory


🟠 [HIGH] flowring_technology_corp/agentflow_4.0

1 CVE | CVSS 4.0: 9.3 | AAS 9.2

  • cpe:2.3:a:flowring_technology_corp:agentflow_4.0:*:*:*:*:*:*:*:* (>= 4.0, < 2025-08-08)

Flowring Technology Agentflow 4.0 is affected by one critical-severity vulnerability (CVE-2026-96429, CVSS 9.3) that allows remote attackers to execute arbitrary SQL commands via the id parameter in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint, potentially leading to unauthorized data access, modification, or full database compromise. Organizations using Agentflow 4.0 for business process management should treat this as an urgent priority, as the SQL injection flaw is remotely exploitable and requires no authentication. Administrators should update to the patched version released on or after 2025/08/08 and review the vendor advisory for further guidance.

Vendor Advisory