CVE-2026-44756: A memory corruption vulnerability in SAP (OVERPASS), 10.0 rating βπ₯
A recently disclosed memory corruption vulnerability, which resides in the SAP kernel's processing of the Extended Passport (EPP), allows unauthenticated attackers to run arbitrary OS commands on the SAP host with SAP administrative privileges, potentially leading to a total compromise of underlying business data and processes.
Search at Netlas.io:
π Link: https://nt.ls/U7K8V
π Dork: http.headers.server:"SAP"
Read more :
https://onapsis.com/blog/sap-overpass-remediation/
A recently disclosed memory corruption vulnerability, which resides in the SAP kernel's processing of the Extended Passport (EPP), allows unauthenticated attackers to run arbitrary OS commands on the SAP host with SAP administrative privileges, potentially leading to a total compromise of underlying business data and processes.
Search at Netlas.io:
π Link: https://nt.ls/U7K8V
π Dork: http.headers.server:"SAP"
Read more :
https://onapsis.com/blog/sap-overpass-remediation/
β€3π₯3
CVE-2026-67401: SQL Injection Vulnerability in cPanel, 9.9 Rating π₯
A vulnerability in cPanel's EmailTrack component allows an authenticated attacker with mail-related privileges to create arbitrary files on the server via SQL injection. This may lead to code execution as the root user, giving the attacker full control of the server.
Search at Netlas.io:
π Link: https://nt.ls/dIEpd
π Dork: http.title:cpanel OR http.headers.set_cookie:"cprelogin" OR http.headers.set_cookie:"cpsession"
Vendor's advisory:
https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026
A vulnerability in cPanel's EmailTrack component allows an authenticated attacker with mail-related privileges to create arbitrary files on the server via SQL injection. This may lead to code execution as the root user, giving the attacker full control of the server.
Search at Netlas.io:
π Link: https://nt.ls/dIEpd
π Dork: http.title:cpanel OR http.headers.set_cookie:"cprelogin" OR http.headers.set_cookie:"cpsession"
Vendor's advisory:
https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026
π₯3β€1πΎ1
CVE-2026-85102 and CVE-2026-85103: Two RCE Vulnerabilities in Check Point Products, 9.8 Rating π₯
Two critical VPN-related vulnerabilities recently disclosed in Check Point Security Gateways, firewall appliances, and the Security Management Server could allow unauthenticated remote code execution under specific conditions. Both vulnerabilities exist in the way the products handle VPN certificates.
Search at Netlas.io:
π Link: https://nt.ls/hJmZ6
π Dork: http.headers.server:"CPWS" OR http.favicon.hash_sha256:78bd48391c96c6ac257e74e109783cc2750b39ea144a849f8d830f4f8f279267 OR http.favicon.hash_sha256:475a554d9a6c971ebf248fe45bcecafbab2b663edd7f080486a995c877dd1216 OR http.body:"TITLE>GAiA</TITLE>" OR path:"/sslvpn/Login/Login" OR http.headers.set_cookie:"CheckCookieSupport"
Vendor's advisory:
https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995
Two critical VPN-related vulnerabilities recently disclosed in Check Point Security Gateways, firewall appliances, and the Security Management Server could allow unauthenticated remote code execution under specific conditions. Both vulnerabilities exist in the way the products handle VPN certificates.
Search at Netlas.io:
π Link: https://nt.ls/hJmZ6
π Dork: http.headers.server:"CPWS" OR http.favicon.hash_sha256:78bd48391c96c6ac257e74e109783cc2750b39ea144a849f8d830f4f8f279267 OR http.favicon.hash_sha256:475a554d9a6c971ebf248fe45bcecafbab2b663edd7f080486a995c877dd1216 OR http.body:"TITLE>GAiA</TITLE>" OR path:"/sslvpn/Login/Login" OR http.headers.set_cookie:"CheckCookieSupport"
Vendor's advisory:
https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995
π₯3β€1
π Plug & Pwn: Mapping the Windows PnP Auto-Install Attack Surface
Windows Plug & Play can automatically install signed vendor software with SYSTEM privileges. With RDP USB redirection, this attack surface may also be reachable remotely β no physical USB device required.
Look at how this attack works and how Netlas can help map exposed RDP infrastructure.
π https://netlas.io/blog/windows_pnp_auto_install_attack_surface/
Windows Plug & Play can automatically install signed vendor software with SYSTEM privileges. With RDP USB redirection, this attack surface may also be reachable remotely β no physical USB device required.
Look at how this attack works and how Netlas can help map exposed RDP infrastructure.
π https://netlas.io/blog/windows_pnp_auto_install_attack_surface/
netlas.io
Plug & Pwn: Mapping the Windows PnP Auto-Install Attack Surface - Netlas Blog
How Windows PnP auto-install becomes a privilege-escalation path, what Netlas can reveal about RDP exposure, and which controls reduce the risk.
π₯6π4β€1
CVE-2026-78006 & CVE-2026-78159: Two unauthenticated vulnerability chains leading to RCE in The Events Calendar Plugin for WordPress, 9.8 Rating π₯
Two critical vulnerabilities were recently disclosed in The Events Calendar Plugin for WordPress. The first uses PHP Object Injection to execute arbitrary OS commands on the underlying server. The second allows an unauthenticated attacker to reset an administratorβs password, after which the attacker can upload a malicious plugin and take complete control of the site. The first vulnerability (CVE-2026-78006) is already being exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/mEm8O
π Dork: http.body:"plugins/the-events-calendar"
Read more:
https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
Two critical vulnerabilities were recently disclosed in The Events Calendar Plugin for WordPress. The first uses PHP Object Injection to execute arbitrary OS commands on the underlying server. The second allows an unauthenticated attacker to reset an administratorβs password, after which the attacker can upload a malicious plugin and take complete control of the site. The first vulnerability (CVE-2026-78006) is already being exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/mEm8O
π Dork: http.body:"plugins/the-events-calendar"
Read more:
https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
β€2π₯2
CVE-2026-61642: Request smuggling is possible in Squid proxy, 7.7 Rating π₯
A recently disclosed vulnerability in Squid proxy allows a trusted client to poison the web cache and store arbitrary malicious content at any URL, which can then be delivered to other clients in response to their future requests.
Search at Netlas.io:
π Link: https://nt.ls/B7WF8
π Dork: http.headers.server:"squid"
Read more:
https://github.com/squid-cache/squid/security/advisories/GHSA-537g-4gfh-w7m6
A recently disclosed vulnerability in Squid proxy allows a trusted client to poison the web cache and store arbitrary malicious content at any URL, which can then be delivered to other clients in response to their future requests.
Search at Netlas.io:
π Link: https://nt.ls/B7WF8
π Dork: http.headers.server:"squid"
Read more:
https://github.com/squid-cache/squid/security/advisories/GHSA-537g-4gfh-w7m6
β€2π₯2
CVE-2026-20329 and others: Multiple vulnerabilities in Cisco ASA, up to 9.9 Rating π₯
Cisco has disclosed multiple vulnerabilities in Cisco ASA, which allow a remote authenticated attacker to cause system instability or run arbitrary actions via improper exception handling. Other disclosed flaws can lead to improper access control, validation errors, and other security-relevant issues.
Search at Netlas.io:
π Link: https://nt.ls/ci994
π Dork: snmp.banner:"Cisco Adaptive Security Appliance" OR snmp.banner:"Cisco ASA" OR http.headers.set_cookie:"webvpn" OR http.body:"+CSCOE+"
Vendor's advisory:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN
Cisco has disclosed multiple vulnerabilities in Cisco ASA, which allow a remote authenticated attacker to cause system instability or run arbitrary actions via improper exception handling. Other disclosed flaws can lead to improper access control, validation errors, and other security-relevant issues.
Search at Netlas.io:
π Link: https://nt.ls/ci994
π Dork: snmp.banner:"Cisco Adaptive Security Appliance" OR snmp.banner:"Cisco ASA" OR http.headers.set_cookie:"webvpn" OR http.body:"+CSCOE+"
Vendor's advisory:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN
π₯4β€2
11 new vulnerabilities in WordPress, no CVE assigned yet βοΈ
WordPress 7.1.1 security release patches 11 vulnerabilities including stored XSS, path traversal, and other security flaws.
Search at Netlas.io:
π Link: https://nt.ls/s3kOE
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
WordPress 7.1.1 security release patches 11 vulnerabilities including stored XSS, path traversal, and other security flaws.
Search at Netlas.io:
π Link: https://nt.ls/s3kOE
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
π4π₯2β€1
CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating π₯
Synology has disclosed 8 vulnerabilities in DiskStation Manager (DSM); 2 of them allow a remote unauthenticated attacker to read or write files and cause a denial of service on affected devices.
Search at Netlas.io:
π Link: https://nt.ls/dgzix
π Dork: tag.name:"synology_diskstation"
Vendor's advisory:
https://www.synology.com/en-global/security/advisory/Synology_SA_26_13
Synology has disclosed 8 vulnerabilities in DiskStation Manager (DSM); 2 of them allow a remote unauthenticated attacker to read or write files and cause a denial of service on affected devices.
Search at Netlas.io:
π Link: https://nt.ls/dgzix
π Dork: tag.name:"synology_diskstation"
Vendor's advisory:
https://www.synology.com/en-global/security/advisory/Synology_SA_26_13
π2π₯2β€1
CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating π₯
A recently disclosed improper input validation vulnerability in on-premises VeloCloud Orchestrator (VCO) allows a remote attacker to access privileged internal functionality and impact the VCO host. This vulnerability is known to be actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/Z9gGT
π Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
A recently disclosed improper input validation vulnerability in on-premises VeloCloud Orchestrator (VCO) allows a remote attacker to access privileged internal functionality and impact the VCO host. This vulnerability is known to be actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/Z9gGT
π Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
π₯3β€1
CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating π₯
Another newly disclosed WordPress RCE vulnerability allows an unauthenticated attacker to execute arbitrary code under specific server conditions.
Search at Netlas.io:
π Link: https://nt.ls/B4TJE
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
Another newly disclosed WordPress RCE vulnerability allows an unauthenticated attacker to execute arbitrary code under specific server conditions.
Search at Netlas.io:
π Link: https://nt.ls/B4TJE
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
π₯2β€1πΎ1