Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2026-76460
Known exploited
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
CVSS Score
10.0
EPSS Score
0.009
Published
2026-09-16
CVE-2026-58704
Known exploited
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS Score
8.8
EPSS Score
0.002
Published
2026-09-15
CVE-2026-76461
Known exploited
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
CVSS Score
9.8
EPSS Score
0.022
Published
2026-09-14
CVE-2026-85706
Known exploited
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
CVSS Score
10.0
EPSS Score
0.111
Published
2026-09-12
CVE-2026-87491
Known exploited
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVSS Score
8.8
EPSS Score
0.009
Published
2026-09-09
CVE-2026-84869
Known exploited
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVSS Score
9.9
EPSS Score
0.007
Published
2026-09-08
CVE-2026-85880
Known exploited
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.006
Published
2026-09-08
CVE-2026-81963
Known exploited
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.006
Published
2026-09-08
CVE-2026-75650
Known exploited
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS Score
10.0
EPSS Score
0.021
Published
2026-09-07
CVE-2026-86218
Known exploited
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CVSS Score
10.0
EPSS Score
0.007
Published
2026-09-06


Contact Us

Shodan ® - All rights reserved