{"total":25,"items":[{"id":663,"title":"Cisco IOS XE Software Security Hardening Release: August 2026","original_title":"Cisco IOS XE Software Security Hardening Release: August 2026","source_rating":null,"summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review…","ai":false,"actions":[],"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Security%20Hardening%20Release:%20August%202026%26vs_k=1","type":"advisory","language":"en","published_at":"2026-10-02T19:21:28+00:00","severity":"laag","priority":15,"vendors":["Cisco"],"cves":[{"id":"CVE-2026-20272","cvss":9.8,"epss":0.00573,"epss_percentile":0.45354,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-20268","cvss":8.6,"epss":0.00467,"epss_percentile":0.3821,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-20269","cvss":8.6,"epss":0.00467,"epss_percentile":0.38212,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-20270","cvss":8.6,"epss":0.00467,"epss_percentile":0.38212,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-20271","cvss":8.6,"epss":0.00467,"epss_percentile":0.3821,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-20273","cvss":8.6,"epss":0.00467,"epss_percentile":0.38211,"in_kev":false,"kev_ransomware":false}],"cve_count":7,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":9.8,"epss_max":0.00573,"source_count":1,"ncsc":null,"source":{"slug":"cisco-psirt","name":"Cisco PSIRT","category":"vendor","country":null,"license":"© Cisco","reuse":"excerpt"},"bundle":null},{"id":662,"title":"CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability","original_title":"CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability","source_rating":null,"summary":"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.","ai":false,"actions":[],"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940","type":"advisory","language":"en","published_at":"2026-10-02T14:00:00+00:00","severity":"laag","priority":0,"vendors":["Microsoft"],"cves":[{"id":"CVE-2026-96940","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"msrc","name":"Microsoft Security Response Center","category":"vendor","country":null,"license":"© Microsoft","reuse":"excerpt"},"bundle":null},{"id":614,"title":"Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site","original_title":"Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site","source_rating":null,"summary":"","ai":false,"actions":[],"url":"https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site","type":"news","language":"en","published_at":"2026-10-02T12:09:09.135475+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"europol","name":"Europol","category":"opsporing","country":"EU","license":"© Europol, alleen titel en link","reuse":"link"},"bundle":null},{"id":613,"title":"[NIEUW] [hoog] OpenCTI: Kwetsbaarheid maakt verkrijgen van beheerrechten mogelijk","original_title":"[NEU] [hoch] OpenCTI: Schwachstelle ermöglicht Erlangen von Administratorrechten","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3717","type":"advisory","language":"de","published_at":"2026-10-02T11:26:29+00:00","severity":"middel","priority":25,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":611,"title":"[UPDATE] [hoog] Ghostscript: Kwetsbaarheid maakt code-uitvoering en manipulatie van gegevens mogelijk","original_title":"[UPDATE] [hoch] Ghostscript: Schwachstelle ermöglicht Codeausführung und Manipulation von Daten","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3408","type":"advisory","language":"de","published_at":"2026-10-02T11:11:29+00:00","severity":"middel","priority":25,"vendors":["Ghostscript"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":{"mode":"updates","count":15,"day":"2026-10-02","source":"bsi-wid","in_kev":0,"worst":"middel"}},{"id":612,"title":"[NIEUW] [hoog] CPython: Meerdere kwetsbaarheden","original_title":"[NEU] [hoch] CPython: Mehrere Schwachstellen","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3716","type":"advisory","language":"de","published_at":"2026-10-02T11:11:29+00:00","severity":"middel","priority":25,"vendors":["Python"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":607,"title":"[NIEUW] [ONGEPATCHT] [middel] CUPS: Meerdere kwetsbaarheden","original_title":"[NEU] [UNGEPATCHT] [mittel] CUPS: Mehrere Schwachstellen","source_rating":"middel","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3715","type":"advisory","language":"de","published_at":"2026-10-02T10:51:29+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":608,"title":"[NIEUW] [middel] OpenBao: Meerdere kwetsbaarheden","original_title":"[NEU] [mittel] OpenBao: Mehrere Schwachstellen","source_rating":"middel","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3714","type":"advisory","language":"de","published_at":"2026-10-02T10:51:29+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":606,"title":"[NIEUW] [middel] Bouncy Castle: Meerdere kwetsbaarheden","original_title":"[NEU] [mittel] Bouncy Castle: Mehrere Schwachstellen","source_rating":"middel","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3713","type":"advisory","language":"de","published_at":"2026-10-02T10:41:29+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":588,"title":"[NIEUW] [hoog] Tenable Security Nessus: Meerdere kwetsbaarheden","original_title":"[NEU] [hoch] Tenable Security Nessus: Mehrere Schwachstellen","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3708","type":"advisory","language":"de","published_at":"2026-10-02T10:26:30+00:00","severity":"middel","priority":25,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":585,"title":"[NIEUW] [hoog] LiteLLM: Kwetsbaarheid maakt openbaarmaking van informatie en mogelijk privilege-escalatie mogelijk","original_title":"[NEU] [hoch] LiteLLM: Schwachstelle ermöglicht Offenlegung von Informationen und potenziell Privilegieneskalation","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3711","type":"advisory","language":"de","published_at":"2026-10-02T10:26:30+00:00","severity":"middel","priority":25,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":584,"title":"[NIEUW] [ONGEPATCHT] [kritiek] Foreman: Meerdere kwetsbaarheden","original_title":"[NEU] [UNGEPATCHT] [kritisch] Foreman: Mehrere Schwachstellen","source_rating":"kritiek","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3712","type":"advisory","language":"de","published_at":"2026-10-02T10:26:30+00:00","severity":"hoog","priority":45,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":587,"title":"[NIEUW] [middel] MediaWiki: Meerdere kwetsbaarheden","original_title":"[NEU] [mittel] MediaWiki: Mehrere Schwachstellen","source_rating":"middel","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3709","type":"advisory","language":"de","published_at":"2026-10-02T10:26:30+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":586,"title":"[NIEUW] [hoog] CODESYS Control Runtime en Gateway Client: Meerdere kwetsbaarheden","original_title":"[NEU] [hoch] CODESYS Control Runtime und Gateway Client: Mehrere Schwachstellen","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3710","type":"advisory","language":"de","published_at":"2026-10-02T10:26:30+00:00","severity":"middel","priority":25,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":591,"title":"[NIEUW] [hoog] MISP: Meerdere kwetsbaarheden","original_title":"[NEU] [hoch] MISP: Mehrere Schwachstellen","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3705","type":"advisory","language":"de","published_at":"2026-10-02T10:26:29+00:00","severity":"middel","priority":25,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":593,"title":"[NIEUW] [hoog] Apache HTTP Server: Meerdere kwetsbaarheden","original_title":"[NEU] [hoch] Apache HTTP Server: Mehrere Schwachstellen","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3703","type":"advisory","language":"de","published_at":"2026-10-02T10:26:29+00:00","severity":"middel","priority":25,"vendors":["Apache"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":590,"title":"[NIEUW] [hoog] BigBlueButton: Meerdere kwetsbaarheden","original_title":"[NEU] [hoch] BigBlueButton: Mehrere Schwachstellen","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3706","type":"advisory","language":"de","published_at":"2026-10-02T10:26:29+00:00","severity":"middel","priority":25,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":594,"title":"[NIEUW] [middel] FasterXML Jackson: Meerdere kwetsbaarheden maken denial of service mogelijk","original_title":"[NEU] [mittel] FasterXML Jackson: Mehrere Schwachstellen ermöglichen Denial of Service","source_rating":"middel","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3702","type":"advisory","language":"de","published_at":"2026-10-02T10:26:29+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":589,"title":"[NIEUW] [middel] HCL BigFix: Meerdere kwetsbaarheden","original_title":"[NEU] [mittel] HCL BigFix: Mehrere Schwachstellen","source_rating":"middel","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3707","type":"advisory","language":"de","published_at":"2026-10-02T10:26:29+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":592,"title":"[NIEUW] [hoog] Wind River VxWorks: Kwetsbaarheid maakt privilege-escalatie mogelijk","original_title":"[NEU] [hoch] Wind River VxWorks: Schwachstelle ermöglicht Privilegieneskalation","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3704","type":"advisory","language":"de","published_at":"2026-10-02T10:26:29+00:00","severity":"middel","priority":25,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":582,"title":"[NIEUW] [kritiek] Fortinet FortiMail: Kwetsbaarheid maakt manipulatie van bestanden mogelijk","original_title":"[NEU] [kritisch] Fortinet FortiMail: Schwachstelle ermöglicht Manipulation von Dateien","source_rating":"kritiek","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3701","type":"advisory","language":"de","published_at":"2026-10-02T09:11:29+00:00","severity":"hoog","priority":45,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":581,"title":"Kwetsbaarheid verholpen in Fortinet FortiMail","original_title":"Kwetsbaarheid verholpen in Fortinet FortiMail","source_rating":null,"summary":"Fortinet heeft een kwetsbaarheid verholpen in FortiMail. FortiMail bevat een kritieke kwetsbaarheid (CVE-2026-104286) in de verwerking van bestandspaden, veroorzaakt door een combinatie van Path Traversal (CWE-22) en onvoldoende neutralisatie van NULL-bytes (CWE-158). Een niet-geauthenticeerde aanvaller kan via speciaa","ai":false,"actions":[],"url":"https://advisories.ncsc.nl/advisory?id=NCSC-2026-0398","type":"advisory","language":"nl","published_at":"2026-10-02T07:21:47+00:00","severity":"kritiek","priority":70,"vendors":["Fortinet"],"cves":[{"id":"CVE-2026-104286","cvss":9.8,"epss":null,"epss_percentile":null,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.8,"epss_max":null,"source_count":2,"ncsc":{"kans":"M","schade":"H"},"source":{"slug":"ncsc-nl-advisories","name":"NCSC-NL Security Advisories","category":"overheid","country":"NL","license":"CC0 (Rijksoverheid)","reuse":"open"},"bundle":null},{"id":661,"title":"Stable Channel Update for Desktop","original_title":"Stable Channel Update for Desktop","source_rating":null,"summary":"The Stable channel has been updated to 154.0.8037.97/.98 for Windows and Mac and 154.0.8037.97 to Linux which will roll out over the coming days/weeks. A full list of changes in this build is…","ai":false,"actions":[],"url":"http://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html","type":"advisory","language":"en","published_at":"2026-10-02T01:04:35+00:00","severity":"laag","priority":0,"vendors":["Microsoft","Google"],"cves":[{"id":"CVE-2026-103628","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-103626","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-103621","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-103630","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-103625","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-103624","cvss":null,"epss":null,"epss_percentile":null,"in_kev":false,"kev_ransomware":false}],"cve_count":11,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"chrome","name":"Google Chrome Releases","category":"vendor","country":null,"license":"© Google","reuse":"excerpt"},"bundle":null},{"id":659,"title":"CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability","original_title":"CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability","source_rating":null,"summary":"Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.\n\nVereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Pri","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102490","type":"kev","language":"en","published_at":"2026-10-02T00:00:00+00:00","severity":"hoog","priority":65,"vendors":["Zammad"],"cves":[{"id":"CVE-2026-102490","cvss":9.4,"epss":0.00262,"epss_percentile":0.16336,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.4,"epss_max":0.00262,"source_count":4,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":660,"title":"CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability","original_title":"CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability","source_rating":null,"summary":"Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.\n\nVereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updat","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102489","type":"kev","language":"en","published_at":"2026-10-02T00:00:00+00:00","severity":"hoog","priority":65,"vendors":["Zammad"],"cves":[{"id":"CVE-2026-102489","cvss":9.4,"epss":0.00582,"epss_percentile":0.45835,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.4,"epss_max":0.00582,"source_count":4,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null}]}