๐ ADVISORIES
- SonicWall Patches Critical RCE Flaws in Discontinued GMS Platform
SonicWall patched critical unauthenticated RCE flaws in its discontinued GMS platform.
- SonicWall GMS Virtual Appliance and Windows versions 9.5.1 and earlier are affected.
CVE-2026-66147enables unauthenticated remote code execution through command injection.CVE-2026-66145enables sensitive-data disclosure through a zip slip attack.- SonicWall fixed the GMS flaws in version 9.5.2 and reported no known exploitation in the wild. ๐ Source: cisecurity.org ยท ๐ Coverage: radar.offseq.com ยท ๐ via CIS Advisories
๐ CVEs & KEV
- CVE-2026-73300 โ CVSS 9.6 โ Budibase: SQL Injection via
multipleStatements: trueBudibase is an open-sou... - CVE-2026-69106 โ CVSS 8.8 โ Potential cache poisoning in JFrog ArtifactoryA low-privileged user may poiso...
- CVE-2026-18952 โ CVSS 8.6 โ Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security A...
- CVE-2026-19311 โ CVSS 8.6 โ Missing Authorization in Execute Monitor API in OpenSearch Alerting PluginMis...
- CVE-2026-15423 โ CVSS 8.5 โ Incorrect Authorization in GitLabGitLab has remediated an issue in GitLab CE/...
- CVE-2026-16627 โ CVSS 7.7 โ Improper Neutralization of Input During Web Page Generation ('Cross-site Scri...
- CVE-2026-16907 โ CVSS 7.6 โ IBM i is Affected By Multiple Vulnerabilities in the Debug ServerIBM i 7.6, 7...
- CVE-2026-42018 โ CVSS 7.5 โ Anonymous user token generation exposure in JFrog ArtifactoryJFrog Artifactor...
- CVE-2026-17271 โ CVSS 7.5 โ IBM i is Affected By Multiple Vulnerabilities in the Debug ServerIBM i 7.6, 7...
- CVE-2026-17248 โ CVSS 7.1 โ IBM i is Affected By Multiple Vulnerabilities in the Debug ServerIBM i 7.6, 7...
- CVE-2026-18677 โ CVSS 6.0 โ Kong Mesh: a dataplane token without a workload binding can claim any workloa...