Security Digest: September 29, 2026 - 23 Critical Vulnerabilities

Today’s alert is severe: 23 critical vulnerabilities span enterprise geospatial software, industrial devices, routers, identity workflows, and widely deployed web apps. Several flaws have public exploits, and multiple issues allow remote code execution, authentication bypass, or full account takeover.

· 15 min read

Executive Summary

Today’s alert is severe: 23 critical vulnerabilities span enterprise geospatial software, industrial devices, routers, identity workflows, and widely deployed web apps. Several flaws have public exploits, and multiple issues allow remote code execution, authentication bypass, or full account takeover.

Act now: prioritize internet-facing systems, OT/industrial devices, and any product with public exploit code. If you run affected software, patch or isolate it immediately and assume exposed services may already be probed.

Critical Vulnerabilities

  • CVE-2026-84154: GEOVIA Geospatial Data Manager code injection
    • Impact: Remote attackers may execute arbitrary code on the server.
    • Affected Systems: GEOVIA Geospatial Data Manager from 3DEXPERIENCE R2024x through R2026x.
    • Immediate Action: Remove external exposure, restrict access to trusted networks, and apply vendor remediation immediately.
    • Mitigation: Patch to the fixed release as soon as available; monitor for unexpected server-side processes.
  • CVE-2026-101354: FAST FAC1203R stack-based buffer overflow
    • Impact: Local-network attackers can trigger code execution; public exploit code is available.
    • Affected Systems: FAST FAC1203R 20200116_2.0.4, function _tWlanTask.
    • Immediate Action: Isolate devices from untrusted local networks and segment wireless/management traffic now.
    • Mitigation: Apply vendor updates if released; otherwise disable exposed management paths and restrict LAN access.
  • CVE-2026-101263: Ziroom ZHOME A0101 command injection via /api/ZRQos/set_online_client
    • Impact: Remote code execution through crafted mac input.
    • Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
    • Immediate Action: Block external access to the API and rotate credentials/secrets tied to the device.
    • Mitigation: Update or remove the product; if no patch exists, isolate it from production networks.
  • CVE-2026-101264: Ziroom ZHOME A0101 command injection via /api/ZRnetwork/set_passwd
    • Impact: Remote attackers can inject commands via password1.
    • Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
    • Immediate Action: Treat as compromised if internet-exposed; block access and inspect for unauthorized changes.
    • Mitigation: Patch or replace; otherwise place behind strict network controls.
  • CVE-2026-102361: mall4j password reset without authentication
    • Impact: Attackers can reset any storefront account password and take over accounts.
    • Affected Systems: mall4j through 4.0, PUT /user/updatePwd.
    • Immediate Action: Disable the endpoint or restrict it immediately; force password resets for users if exposure is suspected.
    • Mitigation: Apply the vendor fix and review logs for unauthorized password changes.
  • CVE-2026-101260: Ziroom ZHOME A0101 command injection via /api/ZRnetwork/firstLogin
    • Impact: Remote command execution through firstLogin.
    • Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
    • Immediate Action: Block API access and remove the device from any exposed environment.
    • Mitigation: Patch or isolate; verify no unauthorized configuration changes.
  • CVE-2026-101261: Ziroom ZHOME A0101 command injection via /api/ZRnetwork/firstSetup_wifi
    • Impact: Remote command execution through login_pwd.
    • Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
    • Immediate Action: Disconnect affected devices from untrusted networks now.
    • Mitigation: Update firmware or retire the device if no fix is available.
  • CVE-2026-101262: Ziroom ZHOME A0101 command injection via /api/ZRQos/set_online_client
    • Impact: Remote attackers can inject commands via ip.
    • Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
    • Immediate Action: Restrict the API to trusted hosts only.
    • Mitigation: Patch or isolate; audit for suspicious device activity.
  • CVE-2026-8065: Hitachi Energy RTU500 firmware upload authentication bypass
    • Impact: Unauthenticated attackers can upload arbitrary firmware and alter device behavior.
    • Affected Systems: Hitachi Energy RTU500 firmware update endpoint.
    • Immediate Action: Remove remote access, segment OT networks, and verify firmware integrity immediately.
    • Mitigation: Apply vendor patch; if unavailable, restrict to maintenance-only access and monitor update attempts.
  • CVE-2026-8066: Hitachi Energy RTU500 directory traversal in file upload
    • Impact: Arbitrary file write/overwrite on the device.
    • Affected Systems: Hitachi Energy RTU500 file upload functionality.
    • Immediate Action: Block untrusted upload access and check for modified system files.
    • Mitigation: Patch immediately; restore from known-good firmware if tampering is suspected.
  • CVE-2026-84739: GitLab merge request diff viewer XSS
    • Impact: Authenticated attackers may run JavaScript in another user’s browser session.
    • Affected Systems: GitLab CE/EE before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.
    • Immediate Action: Upgrade GitLab immediately and review privileged user sessions.
    • Mitigation: Patch to the fixed release; consider session revocation for exposed instances.
  • CVE-2026-102422: shell-quote comment handling can lead to shell injection
    • Impact: Crafted input can break out into shell commands.
    • Affected Systems: shell-quote versions before 1.11.0.
    • Immediate Action: Upgrade dependencies and search code for use of quote() or parse() with untrusted input.
    • Mitigation: Update to 1.11.0 and remove unsafe shell concatenation.
  • CVE-2026-86158: Fiddler Everywhere localhost auth bypass
    • Impact: A local attacker can mint OAuth tokens and read the root certificate.
    • Affected Systems: Fiddler Everywhere 8.0.2 local .NET backend.
    • Immediate Action: Treat affected developer workstations as high risk and update the tool immediately.
    • Mitigation: Patch; restrict local access where possible and reissue credentials/certificates if abused.
  • CVE-2026-102243: MODSetter SurfSense command injection in MCP connector test endpoint
    • Impact: Remote attackers may execute commands on the backend.
    • Affected Systems: SurfSense up to 2.0.3, /api/search-source/connectors/mcp/test.
    • Immediate Action: Disable the endpoint until patched and inspect logs for suspicious requests.
    • Mitigation: Apply the vendor fix; isolate the service if patching is delayed.
  • CVE-2026-102334: Nginx Proxy Manager weak authentication rate limiting
    • Impact: Attackers can brute-force passwords and TOTP codes to gain admin access.
    • Affected Systems: Nginx Proxy Manager through 2.16.0, auth endpoints /api/tokens and /api/tokens/2fa.
    • Immediate Action: Add external rate limiting, lock down admin access, and review failed login spikes now.
    • Mitigation: Upgrade and enforce MFA protections plus IP allowlisting.
  • CVE-2026-101280: OpenDMARC authentication bypass by spoofing
    • Impact: Remote attackers can spoof authentication-related checks.
    • Affected Systems: OpenDMARC up to 1.4.2, opendmarc_policy_query_dmarc.
    • Immediate Action: Patch mail gateways immediately and verify DMARC enforcement behavior.
    • Mitigation: Apply the vendor patch; monitor for suspicious mail-authentication anomalies.
  • CVE-2026-102245: SurfSense missing authentication in circleback webhook route
    • Impact: Remote attackers may access functionality without authentication.
    • Affected Systems: SurfSense up to 2.0.3, surfsense_backend/app/routes/circleback_webhook_route.py.
    • Immediate Action: Restrict webhook exposure and require authentication controls at the edge.
    • Mitigation: Patch immediately and validate all webhook endpoints.
  • CVE-2026-102248: Rebuild login endpoint improper authentication
    • Impact: Remote attackers may bypass login controls.
    • Affected Systems: Rebuild up to 4.4.7/4.5.0-beta5, /user/login.
    • Immediate Action: Force updates and invalidate active sessions if the app is exposed.
    • Mitigation: Apply the fixed version and review authentication logs.
  • CVE-2026-102249: Rebuild file editor missing authorization
    • Impact: Remote attackers may access or change files without proper permission.
    • Affected Systems: Rebuild up to 4.4.11, /commons/file-editor-save.
    • Immediate Action: Restrict the endpoint and check for unauthorized file edits now.
    • Mitigation: Patch and audit file-access permissions.
  • CVE-2026-102293: tacomall improper authorization in admin backend
    • Impact: Attackers may gain admin-level actions by manipulating isAdmin/jobId.
    • Affected Systems: tacomall 1.0.0, api-admin backend.
    • Immediate Action: Limit backend access and review staff/admin role assignments immediately.
    • Mitigation: Patch and verify authorization checks server-side.
  • CVE-2026-101281: OpenDMARC SPF macro handler improper authentication
    • Impact: Remote attackers may bypass authentication checks.
    • Affected Systems: OpenDMARC up to 1.4.2, opendmarc_sp2_find_mailfrom_domain.
    • Immediate Action: Apply the patch referenced by the vendor and restart mail security services.
    • Mitigation: Use patch c48a74c758677fc5272a73eff15ffdbf8afda1a6 or vendor-fixed release.
  • CVE-2026-96326: HT Contact Form stored XSS
    • Impact: Unauthenticated attackers can inject scripts that run in visitors’ browsers.
    • Affected Systems: HT Contact Form – Drag & Drop Form Builder for WordPress up to 2.10.2.
    • Immediate Action: Disable the plugin or remove the rich text field until patched.
    • Mitigation: Update to a fixed version and review published pages for injected content.
  • CVE-2026-102335: Nginx Proxy Manager advanced_config privilege gap
    • Impact: Non-admin users with manage permissions can inject arbitrary nginx directives.
    • Affected Systems: Nginx Proxy Manager through 2.16.0.
    • Immediate Action: Remove unnecessary manage permissions and review all custom config entries now.
    • Mitigation: Upgrade and enforce strict role separation for host configuration.

Previously Alerted

What to Do Now

  1. Patch first: prioritize GEOVIA, Hitachi Energy RTU500, GitLab, OpenDMARC, Nginx Proxy Manager, WordPress plugins, and any product with public exploit code.
  2. Isolate exposed systems: remove internet exposure, limit management interfaces to trusted networks, and segment OT devices immediately.
  3. Reset credentials: force password changes and revoke sessions for apps with auth bypass, password reset, or admin privilege flaws.
  4. Check for abuse: review logs for unusual API calls, failed logins, new admin users, file writes, and suspicious outbound connections.
  5. Contain uncertainty: if a patch is not available, disable the vulnerable feature or take the service offline until remediation is confirmed.

Verification: confirm upgraded versions, validate that vulnerable endpoints are no longer reachable, and test that authentication and authorization controls are enforced after changes.

Monitoring: watch for brute-force activity, webshell indicators, unauthorized firmware uploads, unexpected browser-session activity, and changes to nginx, mail, or application configuration.

Related Resources

  • Internal: Updated patch-priority guidance and incident triage checklist for public-exploit vulnerabilities (to be published).
  • Official vendor advisories: GEOVIA, FAST, Ziroom, Hitachi Energy, GitLab, Progress Software, OpenDMARC, WordPress plugin vendor, and Nginx Proxy Manager release notes.

Keep reading