5 vulnerabilities across 5 products scored HIGH or above on October 06, 2026.
- π HIGH: 5
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) β F1: exploitable β functional, AAS: 10.9 β 13.4 (HIGH β CRITICAL). Originally in 2026-09-30 bulletin.
π [HIGH] amentotech/doctreat_core
1 CVE | CVSS 3.1: 10.0 | AAS 11.2
cpe:2.3:a:amentotech:doctreat_core:*:*:*:*:*:*:*:*
Amentotech Doctreat Core plugin for WordPress versions 1.7.0 and earlier is affected by one critical vulnerability (CVE-2026-39773, CVSS 10.0) that allows unauthenticated privilege escalation, meaning an attacker with no credentials can elevate their access to administrative levels on a targeted site. Any organization running the Doctreat Core plugin on their WordPress installation should treat this as an immediate priority, as the flaw requires no authentication and is considered exploitable.
Site administrators should update the Doctreat Core plugin to a patched version as soon as one is available, or disable the plugin entirely until a fix is confirmed. Review the Patchstack advisory at the vendor link for remediation details and check server logs for signs of unauthorized account creation or role changes.
- π CVE-2026-39773 (CVSS 3.1: 10.0)
π [HIGH] craftcms/cms
1 CVE | CVSS 4.0: 8.7 | AAS 10.3
cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*
Craft CMS version 5.10.13.2 and likely earlier releases are affected by one critical vulnerability (CVE-2026-105985, CVSS 8.7) that enables authenticated remote code execution through the Control Panel’s render-components action. Any authenticated user with basic Control Panel access can exploit this flaw by manipulating component classes and property overrides to inject arbitrary Twig template code, potentially achieving full server compromise.
Organizations running Craft CMS should check the vendor’s GitHub repository for a patched release and update immediately. Until a fix is applied, consider restricting Control Panel access to only essential administrative accounts and monitoring for unusual requests to the app/render-components endpoint.
- π CVE-2026-105985 (CVSS 4.0: 8.7)
π [HIGH] twentyhq/twenty
1 CVE | CVSS 3.1: 9.6 | AAS 9.9
cpe:2.3:a:twentyhq:twenty:*:*:*:*:*:*:*:*(>= 1.20.10, < 2.7.0)
Twenty CRM versions 1.20.10 through 2.7.0 are affected by one high-severity vulnerability (CVE-2026-105763, CVSS 9.6) that exposes plaintext credentials for connected IMAP, SMTP, and CalDAV accounts to any workspace member. The /metadata GraphQL endpoint returned connection parameters including passwords for all connected accounts in a workspace without enforcing user identity or access controls, allowing any normal member to harvest other members’ external service credentials.
Organizations running affected versions of Twenty should update to version 2.7.0 or later immediately and rotate all IMAP, SMTP, and CalDAV passwords that were configured as connected accounts, as those credentials should be considered compromised. The fix is available in the vendor’s GitHub commit linked in the advisory.
- π CVE-2026-105763 (CVSS 3.1: 9.6)
π [HIGH] immich-app/immich
1 CVE | CVSS 4.0: 7.7 | AAS 9.7
cpe:2.3:a:immich-app:immich:*:*:*:*:*:*:*:*(< 3.2.4)
Immich self-hosted photo and video management software prior to version 3.2.4 is affected by one high-severity vulnerability (CVE-2026-105764, CVSS 7.7) that allows any authenticated non-admin user to achieve server-side exploitation through crafted SVG file uploads. The thumbnail generation pipeline can fall through from libvips to ImageMagick, where attacker-controlled image references reach unrestricted MSL and VIDEO coder operations, enabling further exploitation through chained asset uploads.
Organizations running Immich should update to version 3.2.4 or later immediately. Until patched, consider restricting SVG upload permissions or disabling SVG thumbnail generation to reduce exposure.
- π CVE-2026-105764 (CVSS 4.0: 7.7)
π [HIGH] laurent22/joplin
1 CVE | CVSS 4.0: 8.5 | AAS 9.6
cpe:2.3:a:laurent22:joplin:*:*:*:*:*:*:*:*(< 3.7.13)
Joplin Server prior to version 3.7.13 is affected by one high-severity vulnerability (CVE-2026-105786, CVSS 8.5) that allows an attacker to hijack application authorization tokens and gain access to another user’s account. The flaw stems from the application authentication flow accepting caller-chosen authorization identifiers and failing to authenticate or bind the redeemer when creating app passwords, enabling an attacker to intercept and redeem a consent grant initiated by a different logged-in user.
Organizations running Joplin Server should update to version 3.7.13 or later immediately and review application authorization logs for any suspicious token redemptions. Until patched, consider restricting access to the server’s public API endpoints to trusted networks.
- π CVE-2026-105786 (CVSS 4.0: 8.5)