⤷ Title: Apache Karaf Vulnerabilities Let Low-Privilege Users Reach Admin and Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 04:28:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Karaf #Apache Karaf vulnerabilities #CVE_2026_91012 #CVE_2026_91048 #CVE_2026_92142 #JMX #privilege escalation #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 04:28:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Karaf #Apache Karaf vulnerabilities #CVE_2026_91012 #CVE_2026_91048 #CVE_2026_92142 #JMX #privilege escalation #Remote Code Execution
Daily CyberSecurity
Apache Karaf Vulnerabilities Let Low-Privilege Users Reach Admin and Code Execution
TL;DR The Apache Karaf project has fixed four Apache Karaf vulnerabilities in version 4.4.12. Two are rated important and two moderate. Each lets a user with a low-privilege role, such as “v…
⤷ Title: Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 09:44:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_101169 #DevSecOps #Insecure Deserialization #Octopus Deploy #Octopus Server #Octopus Server vulnerability #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 09:44:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_101169 #DevSecOps #Insecure Deserialization #Octopus Deploy #Octopus Server #Octopus Server vulnerability #Remote Code Execution
Daily CyberSecurity
Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization
TL;DR Octopus Deploy has fixed a high-severity Octopus Server vulnerability, CVE-2026-101169. An authenticated user who can edit an Environment or Project can run arbitrary code in the server proc…
⤷ Title: Critical MikroTik RouterOS Flaw CVE-2026-84411 Allows Unauthenticated Root RCE
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 20:10:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_84411 #Integer Underflow #MikroTik #MikroTik RouterOS vulnerability #Remote Code Execution #RouterOS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 20:10:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_84411 #Integer Underflow #MikroTik #MikroTik RouterOS vulnerability #Remote Code Execution #RouterOS
Daily CyberSecurity
Critical MikroTik RouterOS Flaw CVE-2026-84411 Allows Unauthenticated Root RCE
TL;DR CISA published advisory ICSA-26-272-06 on September 29, 2026, for a critical MikroTik RouterOS vulnerability, CVE-2026-84411. A single crafted HTTP request can give an unauthenticated attack…
⤷ Title: JupyterLab Desktop Flaw CVE-2026-102530 Turns a Malicious Server URL Into Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 01:46:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_102530 #Electron #JupyterLab #JupyterLab Desktop #JupyterLab Desktop vulnerability #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 01:46:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_102530 #Electron #JupyterLab #JupyterLab Desktop #JupyterLab Desktop vulnerability #Remote Code Execution
Daily CyberSecurity
JupyterLab Desktop Flaw CVE-2026-102530 Turns a Malicious Server URL Into Code Execution
TL;DR A JupyterLab Desktop vulnerability, CVE-2026-102530, rated CVSS 9.4, lets a malicious server URL run code on a user’s computer. The app displayed remote server URLs without sanitizing …
⤷ Title: HPE Patches 18 Instant ON Access Point Vulnerabilities, Five Rated Critical
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 03:36:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access point security #CVE_2026_76721 #CVE_2026_76722 #HPE #HPE Instant ON vulnerabilities #HPE Networking #Instant On #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 03:36:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access point security #CVE_2026_76721 #CVE_2026_76722 #HPE #HPE Instant ON vulnerabilities #HPE Networking #Instant On #Remote Code Execution
Daily CyberSecurity
HPE Patches 18 Instant ON Access Point Vulnerabilities, Five Rated Critical
TL;DR HPE Networking disclosed 18 HPE Instant ON vulnerabilities on September 29, 2026, in its Instant ON access points. Five are rated Critical, and the two worst score CVSS 9.8 with unauthentica…
⤷ Title: WatchGuard Patches 14 Fireware OS Vulnerabilities, Including CVSS 9.2 RCE
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 02:38:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_86131 #Firebox #Fireware OS #Fireware OS vulnerabilities #Remote Code Execution #VPN security #WatchGuard
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 02:38:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_86131 #Firebox #Fireware OS #Fireware OS vulnerabilities #Remote Code Execution #VPN security #WatchGuard
Daily CyberSecurity
WatchGuard Patches 14 Fireware OS Vulnerabilities, Including CVSS 9.2 RCE
TL;DR WatchGuard disclosed 14 Fireware OS vulnerabilities on September 29, 2026, affecting its Firebox firewalls. The worst, CVE-2026-86131, scores CVSS 9.2 and allows remote code execution in cer…
⤷ Title: PoC Exploit Released for Next.js RCE Flaw CVE-2026-94545
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 09:54:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_94545 #Next.js #Next.js RCE #PoC #Remote Code Execution #Satori #Vercel
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 09:54:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_94545 #Next.js #Next.js RCE #PoC #Remote Code Execution #Satori #Vercel
Daily CyberSecurity
PoC Exploit Released for Next.js RCE Flaw CVE-2026-94545
TL;DR Technical details and a working proof-of-concept exploit are now public for CVE-2026-94545, a critical Next.js RCE in the next/og image API. One unauthenticated request can run commands on t…
⤷ Title: OpenBao Security Vulnerabilities Enable Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 02:05:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #OpenBao #Remote Code Execution #Secrets Management #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 02:05:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #OpenBao #Remote Code Execution #Secrets Management #Vulnerability
Daily CyberSecurity
OpenBao Security Vulnerabilities Enable Code Execution
TL;DR OpenBao maintainers issued security updates to address two critical flaws in the secrets management platform. These OpenBao security vulnerabilities allow attackers to execute arbitrary code…
⤷ Title: GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 21:42:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Gateway #AI security #CVE_2026_90970 #gitlab #GitLab Duo #Remote Code Execution #Template Injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 21:42:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Gateway #AI security #CVE_2026_90970 #gitlab #GitLab Duo #Remote Code Execution #Template Injection
Daily CyberSecurity
GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands
TL;DR GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970. The GitLab AI Gateway vulnerability scores 9.9 on CVSS 3.1. It lets a logged-in Duo Agent Platform user …
⤷ Title: Unpatched Apache OpenOffice Vulnerability Leads New Apache Advisories for LDAP API and Traffic Server
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 03 Oct 2026 05:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Apache Directory LDAP API #Apache OpenOffice #Apache Traffic Server #CVE_2026_102795 #CVE_2026_103877 #CVE_2026_59265 #LDAP #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 03 Oct 2026 05:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Apache Directory LDAP API #Apache OpenOffice #Apache Traffic Server #CVE_2026_102795 #CVE_2026_103877 #CVE_2026_59265 #LDAP #Remote Code Execution
Daily CyberSecurity
Unpatched Apache OpenOffice Vulnerability Leads New Apache Advisories for LDAP API and Traffic Server
TL;DR The Apache Software Foundation disclosed eight CVEs on October 2, 2026, across three projects. The most urgent is an Apache OpenOffice vulnerability, CVE-2026-59265, that runs attacker code …