SecOpsPulse Executive Threat Digest
Weekly briefing for security leaders — 9/13/2026 – 9/20/2026
At a Glance
- Critical threats: 20
- High threats: 23
- Total actionable items this week: 43
- Top sources: NVD, CISA, CISA KEV
- Featured security controls: Enterprise Vulnerability Management & Continuous Scanning · Email, Phishing & Business Email Compromise Defense · Application Security, SAST/DAST & Software Supply Chain · Identity, Privileged Access & Multi-Factor Authentication
Top Critical & High Severity Threats
1. CVE-2026-94084 - Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.r — Critical
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform. This is a critical threat mapped to CVE-2026-94084; security leaders should validate exposure, prioritize patching, and verify compensating controls.
- CVEs: CVE-2026-94084
- Source: NVD — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
2. CVE-2026-94083 - Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state — Critical
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when the... This is a critical threat mapped to CVE-2026-94083; security leaders should validate exposure, prioritize patching, and verify compen...
- CVEs: CVE-2026-94083
- Source: NVD — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
3. CVE-2026-93958 - A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ — Critical
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argumen... This is a critical threat mapped to CVE-2026-93958; security leaders should validate exposure, prioritize patching, and verify compen...
- CVEs: CVE-2026-93958
- Source: NVD — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
4. CVE-2026-93985 - OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template — Critical
OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. This is a critical threat mapped to CVE-2026-93985; security leaders should validate exposure, prioritize patching, and v...
- CVEs: CVE-2026-93985
- Source: NVD — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
5. CVE-2026-78030 - DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. — Critical
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attribut... This is a critical threat mapped to CVE-2026-78030; security leaders should validate exposure, prioritize patching, and verify compen...
- CVEs: CVE-2026-78030
- Source: NVD — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
6. CVE-2026-86591 - The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowi — Critical
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress optio... This is a critical threat mapped to CVE-2026-86591; security leaders should validate exposure, prioritize patching, and verify compen...
- CVEs: CVE-2026-86591
- Source: NVD — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
7. CVE-2026-93741 - A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the functio — Critical
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation... This is a critical threat mapped to CVE-2026-93741; security leaders should validate exposure, prioritize patching, and verify compens...
- CVEs: CVE-2026-93741
- Source: NVD — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
8. CISA Adds One Known Exploited Vulnerability to Catalog — Critical
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. This is a critical threat mapped to CVE-2025-39682; security leaders should validate exposure, prioritize patching, and verify compensating controls.
- CVEs: CVE-2025-39682
- Source: CISA — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
9. CISA Adds Two Known Exploited Vulnerabilities to Catalog — Critical
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. This is a critical threat mapped to CVE-2025-39964, CVE-2026-53266; security leaders should validate exposure, prioritize patching, and verify compensating controls.
- CVEs: CVE-2025-39964, CVE-2026-53266
- Source: CISA — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
10. Linux Kernel Race Condition Vulnerability — Critical
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. This is a critical threat mapped to CVE-2025-39964; security leaders should validate exposure, priori...
- CVEs: CVE-2025-39964
- Source: CISA KEV — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
11. Linux Kernel Out-of-Bounds Write Vulnerability — Critical
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. This is a critical threat mapped to CVE-2026-53266; security leaders should valid...
- CVEs: CVE-2026-53266
- Source: CISA KEV — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
12. Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability — Critical
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy...
- CVEs: CVE-2025-39682
- Source: CISA KEV — Read more
- Recommended control: Enterprise Vulnerability Management & Continuous Scanning
Affiliate Disclosure
SecOpsPulse may earn a commission if you purchase security products through the sponsor links in this briefing. Recommendations are selected automatically based on threat context and are independent of editorial coverage.