Six critical software vulnerabilities disclosed in September 2026

Between 2026-09-07 and 2026-09-09, security researchers disclosed six critical vulnerabilities across enterprise and network products with CVSS scores of 9.1–10.0, including unauthenticated remote code execution in JetBrains Hub, D-Link routers, Google Cloud ADK, SAP CAP, and Check Point Quantum Security Gateway, plus credential theft in a payment processing module. No patches were available as of the latest report date.

12 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-86480 (CRITICAL, CVSS 9.8) in JetBrains Hub allows unauthenticated attackers to escalate to superuser by registering a trusted service. No patch yet — restrict access & monitor activity. Deta

mastodon:infosec-exchangeother22d ago kagi ↗

CVE-2026-86480 (CRITICAL, CVSS 9.8) in JetBrains Hub allows unauthenticated attackers to escalate to superuser by registering a trusted service. No patch yet — restrict access & monitor activity. Details: https:// radar.offseq.com/threat/cve-20 26-86480-cwe-306-in-jetbrains-hub-86541d52679a2997 # OffSeq # JetBrains # CVE202686480 # Infosec

D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates

mastodon:infosec-exchangeother22d ago kagi ↗

D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. https:// radar.offseq.com/threat/cve-20 26-86510-out-of-bounds-write-in-d-link-dir-822a-e90339b14a1aa39b # OffSeq # CVE202686510 # RouterSecurity # Infosec

SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — mo

mastodon:infosec-exchangeother21d ago kagi ↗

SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — monitor SAP updates. https:// radar.offseq.com/threat/cve-20 26-76969-cwe-522-insufficiently-protected-credentials-in-sapse-sap-cloud-application-programming-ee3e359619813d60 # OffSeq # SAP # infosec #

CVE-2026-62645 (CRITICAL, CVSS 9.8) in Siemens Reyrolle 7SR5 <2.70 allows attackers to calculate session IDs and bypass authentication via web interface. Restrict access, check Siemens advisory for up

mastodon:infosec-exchangeother21d ago kagi ↗

CVE-2026-62645 (CRITICAL, CVSS 9.8) in Siemens Reyrolle 7SR5 <2.70 allows attackers to calculate session IDs and bypass authentication via web interface. Restrict access, check Siemens advisory for updates. https:// radar.offseq.com/threat/cve-20 26-62645-cwe-306-missing-authentication-for-critical-function-in-siemens-reyrolle-7sr5-698cd29283a49514 # OffSeq # ICS # Vuln # OTsec

CRITICAL (CVSS 9.9): CVE-2026-78234 in Red Hat build of Apache Camel - HawtIO 4 allows users with edit access to mint Service-CA-signed certs, enabling service impersonation & RCE. Restrict HawtIO CR

mastodon:infosec-exchangeother21d ago kagi ↗

CRITICAL (CVSS 9.9): CVE-2026-78234 in Red Hat build of Apache Camel - HawtIO 4 allows users with edit access to mint Service-CA-signed certs, enabling service impersonation & RCE. Restrict HawtIO CR access, audit certs. Details: https:// radar.offseq.com/threat/cve-20 26-78234-improper-certificate-validation-in-red-hat-red-hat-build-of-apache-camel-hawtio-4-903d3c886e0b139e # OffSeq # CVE20267823

CVE-2026-53581 (CRITICAL, CVSS 9.0): OPNsense core <26.1.9 NTP module path traversal lets privileged users overwrite files as root. Upgrade to 26.1.9+ & backend 26.4_20+ now. https:// radar.offseq.com

mastodon:infosec-exchangeother21d ago kagi ↗

CVE-2026-53581 (CRITICAL, CVSS 9.0): OPNsense core <26.1.9 NTP module path traversal lets privileged users overwrite files as root. Upgrade to 26.1.9+ & backend 26.4_20+ now. https:// radar.offseq.com/threat/cve-20 26-53581-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-35f8611179753b8a # OffSeq # OPNsense # Vuln # PathTraversal

CVE-2026-15667: HIGH-severity LFI in Eventin WordPress plugin (≤4.1.22). Contributors can include arbitrary PHP via 'event_layout', risking code execution. Restrict privileges & await patch. https://

mastodon:infosec-exchangeother21d ago kagi ↗

CVE-2026-15667: HIGH-severity LFI in Eventin WordPress plugin (≤4.1.22). Contributors can include arbitrary PHP via 'event_layout', risking code execution. Restrict privileges & await patch. https:// radar.offseq.com/threat/cve-20 26-15667-cwe-98-improper-control-of-filename-for-includerequire-statement-in-php-program-php-b89bc3860052e068 # OffSeq # WordPress # Vuln # LFI

CVE-2026-12855: HIGH-severity vuln in InsydeH2O firmware (HP). Local attackers with high privileges may execute arbitrary code due to improper input validation. No patch yet — restrict local admin acc

mastodon:infosec-exchangeother20d ago kagi ↗

CVE-2026-12855: HIGH-severity vuln in InsydeH2O firmware (HP). Local attackers with high privileges may execute arbitrary code due to improper input validation. No patch yet — restrict local admin access. https:// radar.offseq.com/threat/cve-20 26-12855-cwe-20-improper-input-validation-in-insyde-software-insydeh2o-96c11fc7beb122a7 # OffSeq # Vulnerability # Firmware # Infosec

CVE-2026-76009 (HIGH): Next-Cart Store to WooCommerce Migration ≤3.9.8 exposes an auth bypass via REST API. Attackers can execute arbitrary SQL & delete files — full site compromise possible. Patch st

mastodon:infosec-exchangeother20d ago kagi ↗

CVE-2026-76009 (HIGH): Next-Cart Store to WooCommerce Migration ≤3.9.8 exposes an auth bypass via REST API. Attackers can execute arbitrary SQL & delete files — full site compromise possible. Patch status unknown. Details: https:// radar.offseq.com/threat/cve-20 26-76009-cwe-287-improper-authentication-in-martinnguyen1990-next-cart-store-to-woocommerce-e35aad4a96ee528d # OffSeq # WordPress # Vuln

CVE-2026-16272 (CVSS 9.1, CRITICAL) in PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0: Use of less trusted source can compromise confidentiality and integrity. No patch yet — restrict access a

mastodon:infosec-exchangeother20d ago kagi ↗

CVE-2026-16272 (CVSS 9.1, CRITICAL) in PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0: Use of less trusted source can compromise confidentiality and integrity. No patch yet — restrict access and monitor vendor updates. https:// radar.offseq.com/threat/cve-20 26-16272-cwe-348-use-of-less-trusted-source-in-paytr-payment-and-electronic-money-institution-04a905be1a132f6a # OffSeq # CVE2026_162

CVE-2026-79696: Critical code injection (CVSS 10.0) in Google Cloud ADK for Python (2.0.0 – 2.6.0). Unauth RCE possible via crafted session replay in pytest-enabled Cloud Run & GKE. Patch or update no

mastodon:infosec-exchangeother20d ago kagi ↗

CVE-2026-79696: Critical code injection (CVSS 10.0) in Google Cloud ADK for Python (2.0.0 – 2.6.0). Unauth RCE possible via crafted session replay in pytest-enabled Cloud Run & GKE. Patch or update now. https:// radar.offseq.com/threat/cve-20 26-79696-cwe-184-incomplete-list-of-disallowed-inputs-in-google-cloud-agent-development-kit-adk-3b96714136b44311 # OffSeq # CVE # CloudSecurity # Python

CRITICAL CVE-2026-85103 in Check Point Quantum Security Gateway: Heap-based buffer overflow in VPN certificate ASN.1 decoding allows unauthenticated RCE. Patch pending — monitor vendor. https:// radar

mastodon:infosec-exchangeother20d ago kagi ↗

CRITICAL CVE-2026-85103 in Check Point Quantum Security Gateway: Heap-based buffer overflow in VPN certificate ASN.1 decoding allows unauthenticated RCE. Patch pending — monitor vendor. https:// radar.offseq.com/threat/cve-20 26-85103-cwe-122-heap-based-buffer-overflow-in-checkpoint-quantum-security-gateway-769c0bcac8d0fa47 # OffSeq # CheckPoint # infosec # Vuln