Weekly /
Week 2026-W41
2026-10-05 to 2026-10-11 · 120 new CVEs · 5 added to CISA KEV · 3 high-priority with public PoCs
- CVE-2015-3306 ProFTPD ProFTPD 75exploited in the wild, public PoC
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
- CVE-2015-5477 ISC BIND 65exploited in the wild, public PoC
ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
- CVE-2023-22894 Strapi Strapi 65exploited in the wild, public PoC
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontin
- CVE-2016-3081 Apache Struts 60exploited in the wild
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
- CVE-2026-76459 As part of Cisco's ongoing commitment to proactive security and… 60critical 9.8
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnera
- CVE-2026-76454 A vulnerability in the Cisco Smart Licensing Utility API of Cisco… 55critical 9.1
A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerab
- CVE-2021-3199 ONLYOFFICE Docs 50exploited in the wild
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
- CVE-2026-106237 google chrome 50critical 9.6
Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106195 google chrome 50critical 9.1
Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
- CVE-2026-82531 Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection… 45critical 9.2, public PoC
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbat
Reading
- Max severity SonicWall SMA1000 flaw now exploited in attacks · BleepingComputer
- Microsoft, Adobe, Apple, and Foxit vulnerabilities · Cisco Talos
- CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products · Rapid7
- CVE-2026-21589 | Atlassian Data Center Products Unauthenticated Arbitrary File Read Vulnerability · Horizon3.ai
- You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) · watchTowr Labs