2026-09-25
Review the tracked stories and available summary evidence for the archived period shown.
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- vulnerabilitiesCVE-2026-92289
CVE-2026-92289: Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret
CVE-2026-92289 affects Lemonldap::NG::Portal versions 2.23.0 through 2.23.3 for Perl, where the checkEndPointAuthenticationCredentials function fails to validate client secrets in PKCE or secret mode. This oversight enables proof key for code exchange (PKCE) bypass attacks against public relying parties. The vulnerability is resolved in version 2.23.4.
Why it matters: Organizations running affected Lemonldap::NG::Portal versions should upgrade immediately, as attackers can bypass authentication for public relying parties and potentially gain unauthorized access to protected resources.
- vulnerabilitiesCVE-2026-92609
CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication
Apache Qpid Broker-J through version 10.1.0 contains a session fixation vulnerability in its HTTP management interface that allows remote attackers to reuse session identifiers across authentication boundaries. The HTTP session is not renewed after successful authentication, enabling attackers to hijack authenticated management sessions. Versions through 10.1.0 are affected.
Why it matters: Organizations deploying Apache Qpid Broker-J should assess whether the HTTP management interface is exposed and prioritize patching to prevent unauthorized administrative access through session reuse.
- vulnerabilitiesCVE-2026-92608
CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10
CVE-2026-92608 affects Apache Qpid Broker-J through version 10.1.0, where flawed exception handling during message conversion between AMQP 1.0 and AMQP 0-10 protocols permits authenticated producers to send specially crafted messages that disrupt delivery to downstream consumers. The vulnerability carries moderate severity and stems from incomplete validation when encoding message properties during protocol translation.
Why it matters: Organizations running Apache Qpid Broker-J with AMQP protocol conversion need to upgrade to patch this denial of service vector, which an authenticated attacker can exploit to interfere with message delivery and application availability.
- vulnerabilitiesCVE-2026-92573
CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering
CVE-2026-92573 affects Apache Qpid Broker-J through version 10.1.0 and allows authenticated message producers to consume excessive memory through improper handling of compressed data in the shared GZIP decompressor. The vulnerability affects AMQP 0-8, 0-9, 0-9-1, and 0-10 message delivery, message conversion, and HTTP management JSON rendering. An attacker can disrupt broker availability by triggering uncontrolled resource consumption.
Why it matters: Organizations running Apache Qpid Broker-J must patch immediately, as authenticated users can crash the message broker and cause service disruption; verify your version and apply updates from the Apache Qpid project.
- vulnerabilitiesCVE-2026-92564
CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing
Apache Qpid Broker-J versions through 10.1.0 contain a pre-authentication denial of service vulnerability in AMQP field-table processing. A remote attacker could exploit unbounded type nesting to trigger a stack overflow and crash the broker without requiring credentials. Remediation involves upgrading to version 10.1.1.
Why it matters: Organizations running Apache Qpid Broker-J through 10.1.0 face unauthenticated service disruption risk; apply the 10.1.1 patch immediately to restore availability.
- vulnerabilitiesCVE-2026-92560
CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder
CVE-2026-92560 is a denial of service vulnerability in Apache Qpid Broker-J through version 10.1.0 that allows a pre-authentication attacker to trigger excessive memory allocation through improper type size and count handling in the AMQP 0-10 decoder. The vendor recommends upgrading to version 10.1.1 to remediate the flaw.
Why it matters: Organizations running Apache Qpid Broker-J versions 10.1.0 or earlier should upgrade immediately to 10.1.1, as unauthenticated attackers can crash the broker without credentials.
- vulnerabilities
Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs
A threat actor used three open source artificial intelligence (AI) harnesses, Hermes, Strix, and Cairn, to conduct near-autonomous attacks against hundreds of organizations between September 10 and September 15, compromising at least 27 companies including a Fortune 500 hospitality firm, a major US airline, and online retailers. The operator extracted over 600,000 credit card records and deployed card-stealing skimmers across at least 19 websites while spending between $12,000 and $18,000 on cloud application programming interface (API) access. Exploitations typically succeeded within hours, with the AI agents selecting attack paths dynamically through probing and attempting various techniques including SQL injection, privilege escalation, and credential theft.
Why it matters: Security teams across retail, hospitality, aviation, and industrial sectors must assume AI-driven compromise happens faster than current patch cycles allow, requiring detection speed and rapid service recovery as primary defenses rather than patching velocity alone.
- vulnerabilitiesCVE-2026-85491
Re: CVE-2026-85491: Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone
CVE-2026-85491 affects Catalyst::Seal versions before 0.03 for Perl, allowing an attacker to disable authorization checks on a path or route subsequent requests past protection by exploiting dispatch logic that relies only on the request path. The vulnerability poster clarified that repository metadata for the module contained errors.
Why it matters: Perl developers using Catalyst::Seal versions prior to 0.03 should upgrade immediately to prevent authorization bypass attacks that could allow unauthorized access to protected routes.
- vulnerabilitiesCVE-2026-97636
CVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key
Apache Airflow HashiCorp provider versions 4.6.0 through 4.7.x contain a moderate severity vulnerability in the HashiCorp Vault secrets backend that allows a Directed Acyclic Graph (DAG) author to bypass team-scope isolation. An attacker can craft a variable key with path separators to access secrets belonging to other teams in a multi-team deployment.
Why it matters: Organizations running Apache Airflow with HashiCorp Vault and multiple teams face cross-team secret exposure; teams should upgrade to version 4.8.0 or later immediately.
- threat intel
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two GitHub Actions repositories (issues-helper and maintain-one-comment) were compromised during the May 2026 Mini Shai-Hulud campaign, disabled by GitHub on May 19, 2026, and then re-enabled on September 16, 2026 with malicious code still present in their release tags. Any workflow referencing these actions by version tag rather than commit SHA automatically executed the payload again upon their next scheduled or event-triggered run, affecting approximately 15,000 dependent repositories without requiring further threat actor intervention.
Why it matters: DevOps teams and open source maintainers using actions-cool/issues-helper or actions-cool/maintain-one-comment by tag reference have likely already executed compromised code in their CI/CD pipelines; immediate action is required to identify affected workflows, rotate exposed secrets, and pin all third-party actions to verified commit SHAs.