1 vulnerability across 1 product scored HIGH or above on October 05, 2026.

  • 🟠 HIGH: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) β€” F1: exploitable β†’ functional, AAS: 10.9 β†’ 13.4 (HIGH β†’ CRITICAL). Originally in 2026-09-30 bulletin.
  • [UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-09-28 bulletin.

🟠 [HIGH] zephyrproject/zephyr

1 CVE | CVSS 3.1: 8.4 | AAS 9.2

  • cpe:2.3:a:zephyrproject:zephyr:*:*:*:*:*:*:*:*

Zephyr RTOS β€” NXP GAU ADC Driver Heap Buffer Overflow

One high-severity vulnerability (CVE-2026-19184, CVSS 8.4) affects the Zephyr real-time operating system prior to version 4.5.0. The NXP GAU ADC driver incorrectly validates buffer sizes in bytes against channel counts expressed as sample counts, resulting in a unit mismatch that allows conversion results to be written beyond the allocated buffer β€” potentially up to twice its actual size. This heap buffer overflow is considered exploitable and could lead to memory corruption, denial of service, or code execution on affected embedded devices.

Teams deploying Zephyr-based firmware on NXP platforms using the GAU ADC driver should prioritize upgrading to Zephyr 4.5.0 or later. The fix is available in the vendor’s commit linked in the advisory. Given the prevalence of Zephyr in IoT and embedded environments where remote updates can be difficult, organizations should inventory affected devices and plan firmware updates accordingly.

Vendor Advisory