Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Attackers exploit a critical Gitea flaw to run code on self-hosted Git servers

CISA warned that attackers are exploiting a critical flaw in Gitea, the popular self-hosted Git service, and added it to its exploited-vulnerabilities catalog. Tracked as CVE-2026-60004 and scored 9.8, the code-injection bug lets a user with repository write access send a malicious patch to the diffpatch API endpoint, planting an executable Git hook that runs shell commands as the Gitea service account. Crucially, default installations have open self-registration, so an unauthenticated attacker can simply register, create a repository, and gain code execution. It affects versions 1.17 through 1.27.0 and was fixed in July, and reports describe attackers dropping cryptocurrency miners, with one intrusion taking about eleven seconds.

Check
Upgrade Gitea to 1.27.1 or later immediately, disable open self-registration on internet-facing instances, and treat any exposed, registration-enabled server as an incident-response case rather than just a patch.
Affected
Organizations running self-hosted Gitea 1.17 through 1.27.0 (CVE-2026-60004); an attacker with repository write access, obtainable through default open registration, can execute shell commands as the Gitea service account.
Fix
Patch to a fixed release, turn off self-registration where not needed, restrict internet exposure of Gitea, and hunt patched servers for rogue Git hooks, miner processes, and other signs of compromise.

Malicious webpage can hijack a local AI agent via NVIDIA NemoClaw and Ollama

Researchers disclosed a flaw in NVIDIA NemoClaw, a stack for running AI agents like OpenClaw with local inference through Ollama, that lets a single malicious webpage hijack the agent. Tracked as CVE-2026-65105, the issue is that NemoClaw starts Ollama bound to all network interfaces, so a DNS-rebinding attack from a page the user simply visits reaches the local model server and takes unauthenticated control. The attacker can then rewrite the model's chat template to plant hidden instructions that run on every later inference, beneath the agent's own guardrails and persisting across conversations. A fix landed in version 0.0.35 for macOS and Linux, but the Windows path remains exposed.

Check
Update NemoClaw to 0.0.35 on macOS and Linux, bind Ollama to the loopback address instead of all interfaces, and firewall port 11434, treating the local model server as a critical service.
Affected
Developers running NemoClaw with a local Ollama backend (CVE-2026-65105); a visited malicious page can hijack the model server via DNS rebinding and persistently poison the model, with the Windows path still unfixed.
Fix
Patch where a fix exists, restrict Ollama to loopback and firewall its port, monitor for chat-template changes, and limit the tools, source control, and cloud access the agent holds to reduce impact.

Unpatched Kaltura video player flaws allow unauthenticated file read and code execution

CERT/CC disclosed two unpatched flaws in Kaltura's HTML5 video player library that let a remote, unauthenticated attacker read files from a server and run code, with only network access to the endpoint required. Both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint, which takes a user-controlled ServiceUrl parameter and passes fetched data to PHP's unserialize without validating it. Supplying a file path lets an attacker read any file the web server can access, including credentials and API keys, while the deserialization also enables code execution. CERT/CC could not reach the vendor, and because the endpoint is exposed on Kaltura's shared multi-tenant infrastructure, the flaws can affect many tenants at once.

Check
Since there is no vendor patch, restrict or disable external access to the mwEmbedLoader.php endpoint and enforce a strict allow-list for the ServiceUrl parameter permitting only known backend API URLs.
Affected
Organizations running the Kaltura HTML5 player library exposing mwEmbedLoader.php (CVE-2026-19913, CVE-2026-19912); an unauthenticated attacker can read sensitive files and execute code, with shared-CDN exposure widening the impact.
Fix
Block or lock down the vulnerable endpoint, allow-list ServiceUrl values, monitor for suspicious file-read attempts, rotate any secrets that may have been exposed, and watch for a vendor fix.

Attackers chain two miniOrange WordPress SSO flaws to forge admin logins

Attackers are exploiting two critical authentication-bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, chaining them to forge login responses and sign in as an administrator. The first flaw, CVE-2026-61979, lets the plugin accept an attacker-chosen signature algorithm, so the identity provider's public key can be abused as a shared secret to forge a valid signature; the second, CVE-2026-15981, makes the plugin treat a signature-verification error as success. Both were fixed in July, but the vendor only alerted free-edition users, leaving paid editions unpatched. Security firm Patchstack traced an attack in mid-August where the two were chained to steal an administrator session cookie.

Check
Update the miniOrange SAML Single Sign On plugin on all WordPress sites, including paid editions that were not alerted, and audit for unexpected administrator accounts and sessions.
Affected
WordPress sites using the miniOrange SAML 2.0 Single Sign On plugin (CVE-2026-61979, CVE-2026-15981); chaining the two lets an unauthenticated attacker forge a SAML response and obtain an administrator session.
Fix
Patch or remove the plugin, rotate WordPress salts and admin passwords to invalidate stolen sessions, check for rogue admins, and put a web application firewall in front of login endpoints.

Critical Keycloak flaw lets attackers take over any account via password reset

A critical flaw in Keycloak, the widely used open-source identity and access management server, lets an unauthenticated attacker take over any account through its password-reset flow. Tracked as CVE-2026-18963, the bug is improper state validation in the reset-credentials flow: a crafted request to the reset endpoint pushes the authentication session straight to the password-update step, so the action token Keycloak normally emails is never required, and the attacker sets new credentials for a chosen user. It needs no user interaction and works against any account, including administrators. Red Hat fixed it in Keycloak 26.7.2 and related releases; there is no confirmed exploitation yet.

Check
Upgrade Keycloak to a fixed release such as 26.7.2, and if you ran a vulnerable version, revoke active and offline sessions and rotate client secrets, since tokens may already have been issued.
Affected
Organizations running Keycloak with the forgotten-password feature enabled on a vulnerable version (CVE-2026-18963); an unauthenticated attacker can reset and take over any user or admin account without the email verification step.
Fix
Patch promptly, then treat exposure as possible account compromise: revoke sessions, rotate accessible client secrets, review identity links and admin permissions, and remember downstream services may hold tokens issued before patching.

Unpatched Calix router flaw lets attackers expose devices behind home networks

An unpatched flaw in Calix residential routers used by several US broadband providers lets a remote, unauthenticated attacker create port-forwarding rules that expose devices on the local network to the internet. Tracked as CVE-2026-75501, the missing-authentication issue affects the Calix GS7 XGS model on a specific firmware version, and Calix supplies gear to large providers including Cox and Brightspeed. The researcher who found it reported it to the vendor in June, got no response, and disclosed through CERT/CC after further attempts failed. Because it lets an attacker punch holes through the router's network address translation, internal devices that were never meant to be reachable can be exposed. No fix is available.

Check
If you operate or manage affected Calix broadband routers, ask the provider or vendor about a fix and mitigations, and check devices for unexpected port-forwarding rules exposing internal systems.
Affected
Networks behind affected Calix GS7 XGS routers on the vulnerable firmware (CVE-2026-75501); a remote, unauthenticated attacker can add port-forwarding rules that expose internal devices to the internet, and no patch exists.
Fix
Press the broadband provider and Calix for a firmware fix, restrict remote management where possible, monitor for unauthorized port-forwarding entries, and place sensitive internal devices behind an additional firewall until resolved.

Cisco patches nine Crosswork and Secure Workload flaws, five rated a perfect ten

Cisco released fixes for nine vulnerabilities across its Crosswork network-automation platforms and Secure Workload software, five of them rated 10.0. Four affect Crosswork Data Gateway, Network Controller, and Planning regardless of configuration, and include a SQL injection flaw, a missing-authentication flaw, and external control of the file system, each scored 10.0, plus an insufficiently protected credentials issue at 9.9. Five more affect Secure Workload in both cloud and on-premises deployments, led by a 10.0 improper access control flaw and a 9.9 command-injection flaw. Cisco found them in internal testing using AI models and says none are exploited yet, but there are no workarounds, so patching is the only fix.

Check
Upgrade Crosswork to 7.2.1-SP and Secure Workload to 3.10.9.1 or 4.0.4.16, and note that Secure Workload cloud tenants must still upgrade agent and connector software themselves.
Affected
Organizations running Cisco Crosswork 7.2.1 or earlier, or Secure Workload 3.10 or 4.0 branches; multiple 10.0 flaws allow SQL injection, authentication bypass, file-system control, and command injection, with no workarounds.
Fix
Apply the fixed releases promptly since there are no workarounds, prioritize internet-reachable instances, and for Secure Workload cloud deployments confirm agent and connector components are upgraded, not just Cisco's cluster.

Exploited Entra ID flaw scored a perfect ten but was fixed in Microsoft's cloud

Microsoft disclosed that a critical flaw in Entra ID, its cloud identity and access service formerly known as Azure Active Directory, was exploited in the wild, though it says the issue is fully mitigated on its side and customers need take no action. Tracked as CVE-2026-69836 and scored 10.0, it is an unsafe-deserialization bug that let an unauthenticated attacker run code over the network in the identity service. Because Entra ID underpins sign-in to Microsoft 365, Azure, and many third-party apps, a code execution flaw there is unusually serious. Microsoft has not shared how it was exploited, so the practical step is reviewing identity logs for suspicious activity before the disclosure.

Check
No patching is required since Microsoft fixed this in its cloud, but review Entra ID sign-in and audit logs for suspicious service-principal changes, role assignments, and unusual token or admin activity.
Affected
Organizations relying on Microsoft Entra ID for identity (CVE-2026-69836); the flaw allowed unauthenticated remote code execution in the identity service itself, though Microsoft states it is now fully mitigated.
Fix
Treat this as a prompt to hunt for identity compromise, not to patch: review privileged accounts, tokens, and app registrations for anomalies, tighten conditional access, and monitor Entra logs.

Attackers exploit unauthenticated Zimbra SNMP flaw for remote code execution

Poland's national CERT warned that attackers are exploiting a now-patched flaw in Zimbra Collaboration to run commands on mail servers without authentication. Tracked as CVE-2026-73570 and scored 8.9, it is an OS command injection bug in Zimbra's SNMP monitoring feature: when the optional SNMP package is installed and notification traps are enabled, improper input handling lets an unauthenticated attacker send crafted requests that execute commands as the Zimbra user. The monitoring service involved is on by default where SNMP is used, widening exposure. Zimbra fixed it in version 10.1.20 in July, and Zimbra servers are a long-standing target, so unpatched instances should be treated as urgent.

Check
Update Zimbra Collaboration to 10.1.20 or later now, and check whether the SNMP package is installed with notifications enabled, which is the exposed configuration under active attack.
Affected
Organizations running Zimbra Collaboration before 10.1.20 with the SNMP package installed and notifications enabled (CVE-2026-73570); an unauthenticated attacker can execute operating-system commands as the Zimbra user, and exploitation is underway.
Fix
Patch to 10.1.20, and if you ran an exposed version, inspect the Zimbra log for suspicious service restarts and recently created files, since patching alone will not evict a foothold.

Critical Citrix NetScaler flaw lets attackers bypass authentication on gateways

Citrix patched a critical flaw in NetScaler ADC and Gateway that lets a remote, unauthenticated attacker bypass authentication on appliances used for remote access. Tracked as CVE-2026-19490 and scored 9.3, it is an authentication-bypass issue affecting devices configured as a gateway for SSL VPN, ICA proxy, clientless VPN, or RDP proxy, or as an AAA authentication server. On newer builds it requires a SAML configuration, but on older builds any gateway or AAA configuration is exposed. There is no confirmed exploitation yet, but NetScaler appliances sit at the network edge and have repeatedly been attacked soon after disclosure, so patching is urgent.

Check
Upgrade NetScaler ADC and Gateway to the fixed builds immediately, and check your configuration for SAML action, gateway, and AAA virtual server entries to gauge exposure, treating edge appliances as priority targets.
Affected
Organizations running affected Citrix NetScaler ADC or Gateway as a gateway or AAA server (CVE-2026-19490); a remote, unauthenticated attacker can bypass authentication and reach internal services normally protected by it.
Fix
Patch to the fixed NetScaler versions, review configurations against Citrix's exposure criteria, monitor these appliances closely for compromise given their history as targets, and restrict management and gateway exposure where possible.