{
  "query": {
    "kev": "1"
  },
  "count": 20,
  "total": 1734,
  "page": 1,
  "limit": 20,
  "updated": {
    "cves": "2026-10-05T22:45:08.761Z",
    "kev": "2026-10-05T23:44:11.393Z",
    "epss": "2026-10-05T18:56:17.551Z",
    "breaches": "2026-10-05T18:44:37.761Z",
    "posts": "2026-10-05T23:45:11.434Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1",
    "next": "https://spydr.io/threats.json?kev=1&page=2"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-88779",
      "url": "https://spydr.io/cve/CVE-2026-88779",
      "published": "2026-10-04T04:16:43.680Z",
      "modified": "2026-10-05T13:35:24.663Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.00534,
      "epss_percentile": 0.43126,
      "exploited": true,
      "kev": {
        "added": "2026-10-04",
        "due": "2026-10-07",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NetScaler"
      ],
      "products": [
        "NetScaler ADC",
        "NetScaler Gateway"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28."
    },
    {
      "id": "CVE-2026-102490",
      "url": "https://spydr.io/cve/CVE-2026-102490",
      "published": "2026-09-30T17:16:40.707Z",
      "modified": "2026-10-03T04:18:00.460Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X",
      "score_source": "divd.nl",
      "epss": 0.00629,
      "epss_percentile": 0.48354,
      "exploited": true,
      "kev": {
        "added": "2026-10-02",
        "due": "2026-10-05",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zammad GmbH"
      ],
      "products": [
        "Zammad GmbH Zammad"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root."
    },
    {
      "id": "CVE-2026-102489",
      "url": "https://spydr.io/cve/CVE-2026-102489",
      "published": "2026-09-30T17:16:40.550Z",
      "modified": "2026-10-03T04:17:56.693Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X",
      "score_source": "divd.nl",
      "epss": 0.01396,
      "epss_percentile": 0.71474,
      "exploited": true,
      "kev": {
        "added": "2026-10-02",
        "due": "2026-10-05",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zammad GmbH"
      ],
      "products": [
        "Zammad GmbH Zammad"
      ],
      "cwes": [
        "CWE-384"
      ],
      "description": "Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions."
    },
    {
      "id": "CVE-2026-104286",
      "url": "https://spydr.io/cve/CVE-2026-104286",
      "published": "2026-10-01T20:17:24.010Z",
      "modified": "2026-10-02T12:35:33.990Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.02201,
      "epss_percentile": 0.81917,
      "exploited": true,
      "kev": {
        "added": "2026-10-01",
        "due": "2026-10-04",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiMail"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests."
    },
    {
      "id": "CVE-2026-76504",
      "url": "https://spydr.io/cve/CVE-2026-76504",
      "published": "2026-09-30T13:17:20.247Z",
      "modified": "2026-10-03T00:16:39.140Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.01575,
      "epss_percentile": 0.74601,
      "exploited": true,
      "kev": {
        "added": "2026-09-30",
        "due": "2026-10-03",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-177"
      ],
      "description": "A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user."
    },
    {
      "id": "CVE-2026-86950",
      "url": "https://spydr.io/cve/CVE-2026-86950",
      "published": "2026-09-28T20:17:11.193Z",
      "modified": "2026-10-01T18:17:28.430Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.01242,
      "epss_percentile": 0.68161,
      "exploited": true,
      "kev": {
        "added": "2026-09-29",
        "due": "2026-10-02",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
    },
    {
      "id": "CVE-2026-88772",
      "url": "https://spydr.io/cve/CVE-2026-88772",
      "published": "2026-09-27T17:16:56.390Z",
      "modified": "2026-09-28T12:26:47.670Z",
      "score": 9.5,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.01301,
      "epss_percentile": 0.69477,
      "exploited": true,
      "kev": {
        "added": "2026-09-27",
        "due": "2026-09-30",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix NetScaler"
      ],
      "products": [
        "Citrix NetScaler ADC",
        "Citrix NetScaler Gateway"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service"
    },
    {
      "id": "CVE-2026-88771",
      "url": "https://spydr.io/cve/CVE-2026-88771",
      "published": "2026-09-27T17:16:56.260Z",
      "modified": "2026-09-29T04:18:01.603Z",
      "score": 9.5,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.01083,
      "epss_percentile": 0.64033,
      "exploited": true,
      "kev": {
        "added": "2026-09-27",
        "due": "2026-09-30",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix NetScaler"
      ],
      "products": [
        "Citrix NetScaler ADC",
        "Citrix NetScaler Gateway"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands."
    },
    {
      "id": "CVE-2026-87902",
      "url": "https://spydr.io/cve/CVE-2026-87902",
      "published": "2026-09-22T17:17:28.310Z",
      "modified": "2026-09-28T12:20:54.040Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.46117,
      "epss_percentile": 0.98777,
      "exploited": true,
      "kev": {
        "added": "2026-09-25",
        "due": "2026-09-28",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "WordPress"
      ],
      "products": [
        "WordPress"
      ],
      "cwes": [
        "CWE-98"
      ],
      "description": "An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE."
    },
    {
      "id": "CVE-2026-67279",
      "url": "https://spydr.io/cve/CVE-2026-67279",
      "published": "2026-09-05T20:17:18.390Z",
      "modified": "2026-09-26T04:17:47.273Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "cert.pl",
      "epss": 0.01027,
      "epss_percentile": 0.6239,
      "exploited": true,
      "kev": {
        "added": "2026-09-25",
        "due": "2026-09-28",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mikrotik"
      ],
      "products": [
        "Mikrotik RouterOS"
      ],
      "cwes": [
        "CWE-841"
      ],
      "description": "RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)"
    },
    {
      "id": "CVE-2026-65660",
      "url": "https://spydr.io/cve/CVE-2026-65660",
      "published": "2026-08-11T17:18:54.080Z",
      "modified": "2026-09-26T04:17:45.630Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02101,
      "epss_percentile": 0.81067,
      "exploited": true,
      "kev": {
        "added": "2026-09-25",
        "due": "2026-09-28",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2026-71362",
      "url": "https://spydr.io/cve/CVE-2026-71362",
      "published": "2026-08-11T18:18:21.610Z",
      "modified": "2026-09-25T12:53:15.757Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "adobe.com",
      "epss": 0.87507,
      "epss_percentile": 0.99755,
      "exploited": true,
      "kev": {
        "added": "2026-09-24",
        "due": "2026-09-27",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Commerce",
        "Adobe Commerce B2B",
        "Adobe Magento Open Source"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2026-5430",
      "url": "https://spydr.io/cve/CVE-2026-5430",
      "published": "2026-08-06T08:16:33.240Z",
      "modified": "2026-09-25T12:53:05.517Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.00588,
      "epss_percentile": 0.46265,
      "exploited": true,
      "kev": {
        "added": "2026-09-24",
        "due": "2026-09-27",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "WSO2"
      ],
      "products": [
        "WSO2 Universal Gateway",
        "WSO2 Traffic Manager",
        "WSO2 API Control Plane",
        "WSO2 API Manager",
        "WSO2 Carbon API Manager Rest API Utility"
      ],
      "cwes": [
        "CWE-347"
      ],
      "description": "The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary."
    },
    {
      "id": "CVE-2026-94127",
      "url": "https://spydr.io/cve/CVE-2026-94127",
      "published": "2026-09-22T15:17:24.313Z",
      "modified": "2026-09-23T14:32:07.910Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "f5.com",
      "epss": 0.02226,
      "epss_percentile": 0.82127,
      "exploited": true,
      "kev": {
        "added": "2026-09-22",
        "due": "2026-09-25",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "F5"
      ],
      "products": [
        "F5 BIG-IP"
      ],
      "cwes": [
        "CWE-122"
      ],
      "description": "When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
    },
    {
      "id": "CVE-2026-93616",
      "url": "https://spydr.io/cve/CVE-2026-93616",
      "published": "2026-09-22T13:17:11.963Z",
      "modified": "2026-09-23T16:38:38.987Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "checkpoint.com",
      "epss": 0.19654,
      "epss_percentile": 0.97323,
      "exploited": true,
      "kev": {
        "added": "2026-09-22",
        "due": "2026-09-25",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "checkpoint"
      ],
      "products": [
        "checkpoint Quantum Security Management"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server."
    },
    {
      "id": "CVE-2026-93952",
      "url": "https://spydr.io/cve/CVE-2026-93952",
      "published": "2026-09-22T08:16:43.047Z",
      "modified": "2026-09-23T14:32:12.417Z",
      "score": 9.5,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "arista.com",
      "epss": 0.01062,
      "epss_percentile": 0.63411,
      "exploited": true,
      "kev": {
        "added": "2026-09-22",
        "due": "2026-09-25",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Arista Networks"
      ],
      "products": [
        "Arista Networks VeloCloud Orchestrator (VCO) On-Prem"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched."
    },
    {
      "id": "CVE-2026-85102",
      "url": "https://spydr.io/cve/CVE-2026-85102",
      "published": "2026-09-09T13:20:43.793Z",
      "modified": "2026-09-23T18:22:07.453Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "checkpoint.com",
      "epss": 0.07546,
      "epss_percentile": 0.9434,
      "exploited": true,
      "kev": {
        "added": "2026-09-22",
        "due": "2026-09-25",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "checkpoint"
      ],
      "products": [
        "checkpoint Quantum Security Gateway"
      ],
      "cwes": [
        "CWE-295"
      ],
      "description": "Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway."
    },
    {
      "id": "CVE-2026-7273",
      "url": "https://spydr.io/cve/CVE-2026-7273",
      "published": "2026-06-16T03:16:13.557Z",
      "modified": "2026-09-22T12:10:51.067Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.02501,
      "epss_percentile": 0.8417,
      "exploited": true,
      "kev": {
        "added": "2026-09-21",
        "due": "2026-09-24",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel GS1900-48HPv2 firmware",
        "Zyxel GS1900-8 firmware",
        "Zyxel GS1900-8HP firmware",
        "Zyxel GS1900-10HP firmware",
        "Zyxel GS1900-16 firmware",
        "Zyxel GS1900-24 firmware",
        "Zyxel GS1900-24E firmware",
        "Zyxel GS1900-24EP firmware",
        "Zyxel GS1900-24HPv2 firmware",
        "Zyxel GS1900-48 firmware"
      ],
      "cwes": [
        "CWE-121"
      ],
      "description": "A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request."
    },
    {
      "id": "CVE-2026-53266",
      "url": "https://spydr.io/cve/CVE-2026-53266",
      "published": "2026-06-25T09:16:44.643Z",
      "modified": "2026-09-19T04:17:53.580Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.00827,
      "epss_percentile": 0.55998,
      "exploited": true,
      "kev": {
        "added": "2026-09-18",
        "due": "2026-09-21",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits()."
    },
    {
      "id": "CVE-2025-39964",
      "url": "https://spydr.io/cve/CVE-2025-39964",
      "published": "2025-10-13T14:15:34.737Z",
      "modified": "2026-09-19T04:17:48.307Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.01276,
      "epss_percentile": 0.68944,
      "exploited": true,
      "kev": {
        "added": "2026-09-18",
        "due": "2026-09-21",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux",
        "Siemens"
      ],
      "products": [
        "Linux",
        "Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
        "Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
        "Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
