4 vulnerabilities across 3 products scored HIGH or above on October 09, 2026.
- ๐ HIGH: 4
๐ [HIGH] zephyrproject/zephyr
2 CVEs | CVSS 3.1: 8.8 | AAS 10.1
cpe:2.3:a:zephyrproject:zephyr:*:*:*:*:*:*:*:*(< 3.6.0)
Zephyr RTOS Bluetooth LE Audio Stack โ 2 Vulnerabilities (CVSS 8.8 HIGH)
Two vulnerabilities have been disclosed in the Zephyr real-time operating system affecting the Bluetooth Low Energy Audio subsystem. The most severe issue is a buffer overflow in the LE Audio Broadcast Sink, where subgroup metadata from a received Basic Audio Announcement is copied into a fixed-size structure without bounds checking, allowing an attacker within Bluetooth range to overwrite adjacent memory. These flaws are considered exploitable and could enable denial of service or potentially remote code execution on affected devices. Teams deploying Zephyr-based firmware with Bluetooth LE Audio functionality, including IoT devices, wearables, and embedded systems using the BAP Broadcast Sink feature, should prioritize patching. Apply the vendor-provided commits from the Zephyr project GitHub repository immediately and review device configurations for unnecessary Bluetooth audio subsystem exposure.
- ๐ CVE-2026-19570 (CVSS 3.1: 8.8)
- ๐ CVE-2026-19569 (CVSS 3.1: 8.8)
๐ [HIGH] wpdreams/ajax_search_pro
1 CVE | CVSS 3.1: 9.3 | AAS 9.6
cpe:2.3:a:wpdreams:ajax_search_pro:*:*:*:*:*:*:*:*(< 4.29.2)
WPDreams Ajax Search Pro WordPress Plugin โ 1 Vulnerability (CVSS 9.3 HIGH)
A blind SQL injection vulnerability has been disclosed in the Ajax Search Pro plugin for WordPress, affecting all versions through 4.29.1. The flaw allows an attacker to manipulate database queries through improperly sanitized input, potentially enabling extraction of sensitive data including user credentials, configuration secrets, and other stored content. WordPress site administrators running Ajax Search Pro should update the plugin beyond version 4.29.1 immediately, consult the Patchstack advisory for further details, and review database logs for any signs of exploitation.
- ๐ CVE-2026-96331 (CVSS 3.1: 9.3)
๐ [HIGH] fifu.app/featured_image_from_url
1 CVE | CVSS 3.1: 8.8 | AAS 9.1
cpe:2.3:a:fifu.app:featured_image_from_url:*:*:*:*:*:*:*:*(< 6.0.8)
Featured Image from URL (FIFU) WordPress Plugin โ 1 Vulnerability (CVSS 8.8 HIGH)
A cross-site request forgery vulnerability has been disclosed in the Featured Image from URL plugin for WordPress, affecting all versions through 6.0.7. The flaw allows an attacker to trick an authenticated administrator into performing unintended actions by visiting a malicious page, potentially leading to unauthorized changes to site configuration or content. WordPress administrators using this plugin should update beyond version 6.0.7 immediately and review the Patchstack advisory for additional mitigation guidance.
- ๐ CVE-2026-96671 (CVSS 3.1: 8.8)