CISO Brief

Monday, September 28, 2026

Executive summary

30 items tracked in the current window. 14 critical, 15 high severity, and 3 confirmed exploited in the wild. 0 carry GCC or Middle East relevance. Prioritise patching anything below flagged as exploited.

Priority items (10)

CRITICAL

CVE-2026-101087 | NezhaHQ Nezha up to 2.3.2 URL Validator server-side request forgery (EUVD-2026-88022)

critical has been identified in NezhaHQ Nezha up to 2.3.2 . This affects an unknown function of the component URL Validator . Executing a manipulation can lead to server-side request forgery. This vulnerability appears as CVE-2026-101087 . The attack may be performed from remote. There is no available exploit. Upgrading the affected component is recommended.]]>

VulDB Recent3h ago
CRITICAL

CVE-2026-101088 | NezhaHQ Nezha up to 2.3.0 Service Sentinel Worker servicesentinel.go null pointer dereference (EUVD-2026-88023)

critical has been detected in NezhaHQ Nezha up to 2.3.0 . Impacted is an unknown function of the file service/singleton/servicesentinel.go of the component Service Sentinel Worker . This manipulation causes null pointer dereference. This vulnerability is registered as CVE-2026-101088 . Remote exploitation of the attack is possible. No exploit is available. You should upgrade the affected component.]]>

VulDB Recent3h ago
CRITICAL

CVE-2026-101084 | obot-platform Obot up to 0.21.0 MCP Connect Endpoint access control (EUVD-2026-88029)

obot-platform Obot up to 0.21.0 . It has been classified as critical . Affected by this issue is some unknown functionality of the component MCP Connect Endpoint . Performing a manipulation results in improper access controls. This vulnerability is identified as CVE-2026-101084 . The attack can be initiated remotely. There is not any exploit available. Upgrading the affected component is recommended.]]>

VulDB Recent3h ago
CRITICAL

CVE-2026-101062 | obot-platform Obot up to 0.22.x OAuth Dynamic Client Registration improper authentication (EUVD-2026-88033)

obot-platform Obot up to 0.22.x and classified as critical . Affected by this vulnerability is an unknown functionality of the component OAuth Dynamic Client Registration . Such manipulation leads to improper authentication. This vulnerability is referenced as CVE-2026-101062 . It is possible to launch the attack remotely. No exploit is available. It is suggested to upgrade the affected component.]]>

VulDB Recent3h ago
CRITICAL

CVE-2026-101065 | obot-platform Obot Quickstart OBOT_SERVER_ENABLE_AUTHENTICATION improper authentication (d7e6970 / EUVD-2026-88030)

critical , has been found in obot-platform Obot . This affects an unknown function of the component Quickstart . The manipulation of the argument OBOT_SERVER_ENABLE_AUTHENTICATION leads to improper authentication. This vulnerability is uniquely identified as CVE-2026-101065 . The attack is possible to be carried out remotely. No exploit exists. Applying a patch is the recommended action to fix this issue.]]>

VulDB Recent3h ago
CRITICAL

CVE-2026-96280 | Red Hat Enterprise Linux OCI delta stream parser heap-based overflow (EUVD-2026-88015)

very critical was found in Red Hat Enterprise Linux . The impacted element is an unknown function of the component OCI delta stream parser . Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is handled as CVE-2026-96280 . The attack can be executed remotely. There is not any exploit available.]]>

VulDB Recent3h ago
CRITICAL

CVE-2026-101081 | D-Link DI-8400 16.07 Web Administration Service menu_nat_more.asp menu_nat_more_asp opt stack-based overflow

very critical has been found in D-Link DI-8400 16.07 . This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service . The manipulation of the argument opt results in stack-based buffer overflow. This vulnerability is reported as CVE-2026-101081 . The attack can be launched remotely. Moreover, an exploit is present.]]>

VulDB Recent6h ago
CRITICAL

CVE-2026-88776 | Citrix ADC/Gateway buffer overflow

critical has been discovered in Citrix ADC and Gateway . Affected by this issue is some unknown functionality. Executing a manipulation can lead to buffer overflow. This vulnerability is registered as CVE-2026-88776 . It is possible to launch the attack remotely. No exploit is available. It is advisable to upgrade the affected component.]]>

VulDB Recent6h ago
CRITICAL

CVE-2026-101078 | deepseek-ai deepseek-harness up to 0.1.7-rc.2 Landlock Backend profiles.ts isolation

deepseek-ai deepseek-harness up to 0.1.7-rc.2 . It has been declared as critical . Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend . Such manipulation leads to improper isolation or compartmentalization. This vulnerability is listed as CVE-2026-101078 . The attack must be carried out locally. In addition, an exploit is available. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way.]]>

VulDB Recent6h ago
CRITICAL

CVE-2026-101077 | Netcore NR289-GE 1.4.5102 boa_temp process_request missing authentication

Netcore NR289-GE 1.4.5102 . It has been classified as very critical . This impacts the function process_request of the component boa_temp Handler . This manipulation causes missing authentication. This vulnerability is tracked as CVE-2026-101077 . The attack is possible to be carried out remotely. Moreover, an exploit is present. The vendor was contacted early about this disclosure but did not respond in any way.]]>

VulDB Recent6h ago

GCC / Middle East watchlist (0)

No regional items in this window.