Weekly Security Roundup: August 24 to September 06, 2026
10 vulnerabilities analyzed the week of September 06, 2026. 1 critical, 9 high. Grouped by vendor with patching priorities.
Intelligence Feed
The Sherlock Forensics Intelligence Feed provides expert analysis of AI code security, vibe coding vulnerabilities, CVE advisories and digital forensics methodologies from certified examiners with over 20 years of field experience in Vancouver, BC.
Editor Picks
The most-read pieces our team is shipping right now.
10 vulnerabilities analyzed the week of September 06, 2026. 1 critical, 9 high. Grouped by vendor with patching priorities.
Adobe Connect versions 2025.3, cross-site scripting (CVE-2026-27243) scores CVSS 9.3 CRITICAL.
Vulnerability in the Oracle vulnerability (CVE-2026-22016) scores CVSS 7.5 HIGH. Analysis of affected systems and remediation steps.
Microsoft Edge (Chromium-based) Remote remote code execution (CVE-2026-45495) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.
NGINX JavaScript has a buffer overflow (CVE-2026-8711) scores CVSS 8.1 HIGH. Analysis of affected systems and remediation steps.
IBM Web Server Plug-ins vulnerability (CVE-2026-8620) scores CVSS 7.5 HIGH. Analysis of affected systems and remediation steps.
IBM Web Server Plug-ins remote code execution (CVE-2026-9170) scores CVSS 7.5 HIGH. Analysis of affected systems and remediation steps.
A security vulnerability has buffer overflow (CVE-2026-13515) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.
CVE-2025-62718 (Security, CVSS 9.9 CRITICAL, CWE-441 and CWE-918 and CWE-1289) affecting axios axios. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-21762 (Security, CVSS 9.8 CRITICAL, CWE-787) affecting fortinet fortiproxy. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-9680 (Security, CVSS 9.8 CRITICAL, CWE-416 and CWE-416) affecting mozilla firefox. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-22225 (Security, CVSS 8.2 HIGH, CWE-787 and CWE-123) affecting vmware esxi. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-21762 (Security, CVSS 9.8 CRITICAL, CWE-787) affecting fortinet fortiproxy. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-24919 (Security, CVSS 8.6 HIGH, CWE-200) affecting checkpoint quantum spark firmware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-51378 (OS Command Injection, CVSS 10.0 CRITICAL, CWE-78 and CWE-78) affecting cyberpanel cyberpanel. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-9680 (Security, CVSS 9.8 CRITICAL, CWE-416 and CWE-416) affecting mozilla firefox. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-22225 (Security, CVSS 8.2 HIGH, CWE-787 and CWE-123) affecting vmware esxi. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-24919 (Security, CVSS 8.6 HIGH, CWE-200) affecting checkpoint quantum spark firmware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-51378 (OS Command Injection, CVSS 10.0 CRITICAL, CWE-78 and CWE-78) affecting cyberpanel cyberpanel. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-42467 (Security, CVSS 10.0 CRITICAL, CWE-918) affecting openhab openhab web interface. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-1086 (Security, CVSS 7.8 HIGH, CWE-416 and CWE-416) affecting netapp h300s firmware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-62718 (Security, CVSS 9.9 CRITICAL, CWE-441 and CWE-918 and CWE-1289) affecting axios axios. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-14537 (Security, CVSS 9.8 CRITICAL, CWE-863) affecting google mcp toolbox for databases. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-8037 (Security, CVSS 9.6 CRITICAL, CWE-77) affecting progress connection manager for objectscale. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-1086 (Security, CVSS 7.8 HIGH, CWE-416 and CWE-416) affecting netapp h300s firmware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-62718 (Security, CVSS 9.9 CRITICAL, CWE-441 and CWE-918 and CWE-1289) affecting axios axios. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-14537 (Security, CVSS 9.8 CRITICAL, CWE-863) affecting google mcp toolbox for databases. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-49875 (Security, CVSS 9.8 CRITICAL, CWE-611 and CWE-611) affecting apache cxf. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-8037 (Security, CVSS 9.6 CRITICAL, CWE-77) affecting progress connection manager for objectscale. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-62718 (Security, CVSS 9.9 CRITICAL, CWE-441 and CWE-918 and CWE-1289) affecting axios axios. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-8037 (Security, CVSS 9.6 CRITICAL, CWE-77) affecting progress connection manager for objectscale. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-23692 (Code Injection, CVSS 9.8 CRITICAL, CWE-1336 and CWE-94) affecting rejetto http file server. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-14733 (Security, CVSS 9.8 CRITICAL, CWE-787) affecting watchguard fireware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-9242 (Security, CVSS 9.8 CRITICAL, CWE-787) affecting watchguard fireware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-16232 (Security, CVSS 9.8 CRITICAL, CWE-287) affecting checkpoint multi-domain security management. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-8037 (Security, CVSS 9.6 CRITICAL, CWE-77) affecting progress connection manager for objectscale. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2024-23692 (Code Injection, CVSS 9.8 CRITICAL, CWE-1336 and CWE-94) affecting rejetto http file server. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-14733 (Security, CVSS 9.8 CRITICAL, CWE-787) affecting watchguard fireware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-9242 (Security, CVSS 9.8 CRITICAL, CWE-787) affecting watchguard fireware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-16232 (Security, CVSS 9.8 CRITICAL, CWE-287) affecting checkpoint multi-domain security management. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE Intelligence
High and critical vulnerabilities relevant to cloud, web and AI infrastructure. Updated daily from the National Vulnerability Database.
| CVE | Severity | CVSS | Affected Product | Vulnerability |
|---|---|---|---|---|
| CVE-2026-23696 | CRITICAL | 9.9 | Windmill CE/EE | SQL injection in folder ownership management |
| CVE-2021-4473 | CRITICAL | 9.8 | Tianxin Management System | Command injection in Reporter component |
| CVE-2026-22679 | CRITICAL | 9.8 | Weaver E-cology 10.0 | Unauthenticated RCE via debug endpoint |
| CVE-2026-3296 | CRITICAL | 9.8 | Everest Forms (WordPress) | PHP Object Injection via deserialization |
| CVE-2026-4631 | CRITICAL | 9.8 | Cockpit (Linux) | SSH command injection via login endpoint |
| CVE-2026-1346 | CRITICAL | 9.3 | IBM Verify Identity Access | Privilege escalation for local users |
| CVE-2026-22683 | HIGH | 8.8 | Windmill | Missing authorization bypasses operator restrictions |
| CVE-2026-3357 | HIGH | 8.8 | IBM Langflow Desktop | Insecure FAISS deserialization enables code execution |
| CVE-2026-1342 | HIGH | 8.5 | IBM Verify Identity Access | Local users can execute malicious scripts |
| CVE-2026-4788 | HIGH | 8.4 | IBM Tivoli Netcool Impact | Sensitive data exposure in log files |
| CVE-2026-4740 | HIGH | 8.2 | Red Hat ACM / Open Cluster Mgmt | Certificate forgery via improper validation |
| CVE-2026-5736 | HIGH | 7.3 | PowerJob | detailPlus endpoint manipulation |
| CVE-2026-5739 | HIGH | 7.3 | PowerJob | Code injection via OpenAPI workflow endpoint |
| CVE-2026-5741 | HIGH | 7.3 | docker-mcp-server | OS command injection via HTTP interface |
| CVE-2026-1343 | HIGH | 7.2 | IBM Verify Identity Access | SSRF exposes internal auth endpoints |
| CVE-2026-22682 | HIGH | 7.1 | OpenHarness | Improper access control exposes local files |
Make Sherlock Forensics your preferred source in Google Search