L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
LIVE INTELLIGENCE / WEEK 09-22

Threats don't wait.
Neither should you.

Radar público de vulnerabilidades recém-publicadas, produtos afetados e probabilidade de exploração. Dados objetivos para reduzir o tempo entre exposição e resposta.

CVEs / 7 DIAS8621
FEED ATUALIZADO2026-09-22
FONTESNVD + EPSS
01 / FRESH DISCLOSURES

Novas vulnerabilidades

Publicações dos últimos sete dias, enriquecidas semanalmente com contexto técnico e probabilidade de exploração.

FABRICANTES
CVE-2026-95661MEDIUM
FABRICANTENÃO INFORMADO

MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can cause an authenticated MISP user to visit a crafted URL containing a malicious type value can execute arbitrary JavaScript in the victim's browser within the MISP application origin. Successful exploitation allows the attacker to read session cookies, perform actions on behalf of the victim, or exfiltrate sensitive data accessible from the MISP interface.  The vulnerability requires the victim to be authenticated and to actively navigate to the attacker-supplied URL.

AFFECTED SURFACEProduct not specified
CVSS 5.1
CVE-2026-95659MEDIUM
FABRICANTENÃO INFORMADO

MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation and passed it to the Overmind-themed AnalystData thread view element, where it was interpolated into two translated strings and rendered into the HTML response without output encoding. An authenticated attacker who can induce a victim to navigate to a crafted URL can inject arbitrary JavaScript that executes in the victim's browser within the MISP application context. This may allow the attacker to read session data, manipulate the page, or perform actions on behalf of the victim.  The vulnerability requires the victim to be authenticated to MISP and to actively visit the attacker-supplied URL. The affected component is the AnalystData controller and the Overmind theme's AnalystData thread element. Version affected: <2.5.47

AFFECTED SURFACEProduct not specified
CVSS 4.8
CVE-2026-95658MEDIUM
FABRICANTENÃO INFORMADO

MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because moduleStatelessExecution executes a workflow module's exec() method with caller-supplied input and parameters, the absence of CSRF protection allowed an attacker to craft a cross-site form post (or equivalent cross-origin request) that, when submitted by an authenticated site administrator, would cause the administrator's browser to invoke the action on the MISP instance.  The attacker could select any workflow module to execute, including action modules that write blocklist and warninglist entries, and supply arbitrary input and parameters of their choosing. This constitutes a cross-site request forgery (CSRF) vulnerability with high integrity impact on the MISP instance's security-related data.  The vulnerability was identified during an internal security review and was not externally reported. The fix is included in MISP v2.5.47.

AFFECTED SURFACEProduct not specified
CVSS 6.9
CVE-2026-95619HIGH
FABRICANTENÃO INFORMADO

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the C++ `new` operator. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.

AFFECTED SURFACEProduct not specified
CVSS 7.7
CVE-2026-95273LOW
FABRICANTENÃO INFORMADO

A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Distinct from CVE-2026-25527, which fixed a different parameter (group) in the same function. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 2.1
CVE-2026-95272LOW
FABRICANTENÃO INFORMADO

A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing a manipulation of the argument filename results in path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 2.9
CVE-2026-95271MEDIUM
FABRICANTENÃO INFORMADO

A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 5.5
CVE-2026-93616CRITICAL
FABRICANTENÃO INFORMADO

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

AFFECTED SURFACEProduct not specified
CVSS 9.8
02 / EXPLOIT PROBABILITY

Top 5 EPSS · Setembro 2026

CVEs publicadas em Setembro 2026 ordenadas pela probabilidade estimada de exploração nos próximos 30 dias.

METHOD / EPSS é probabilidade, não severidade. Combine-a com CVSS, exposição do ativo e impacto no negócio.
EXPLORAR TODAS AS CVEs →