<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecOps Pulse — Autonomous Threat Intelligence Feed</title>
    <link>https://www.secopspulse.com</link>
    <description>Real-time cybersecurity threat monitoring, zero-day advisories, and curated security tool recommendations.</description>
    <language>en-us</language>
    <lastBuildDate>Sun, 20 Sep 2026 14:38:38 GMT</lastBuildDate>
    <atom:link href="https://www.secopspulse.com/rss.xml" rel="self" type="application/rss+xml"/>

    <item>
      <title>[Low] CVE-2026-84223 - The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, al</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-84223</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-84223</guid>
      <pubDate>Sun, 20 Sep 2026 07:16:50 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a f... This is a low threat mapped to CVE-2026-84223; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-84223</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-84223">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-82842 - The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-82842</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-82842</guid>
      <pubDate>Sun, 20 Sep 2026 07:16:50 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolv... This is a low threat mapped to CVE-2026-82842; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-82842</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-82842">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-81654 - The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options ca</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-81654</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-81654</guid>
      <pubDate>Sun, 20 Sep 2026 07:16:49 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users g... This is a low threat mapped to CVE-2026-81654; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-81654</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-81654">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-81653 - The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an imag</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-81653</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-81653</guid>
      <pubDate>Sun, 20 Sep 2026 07:16:49 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its g... This is a low threat mapped to CVE-2026-81653; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-81653</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-81653">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-81652 - The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is ent</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-81652</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-81652</guid>
      <pubDate>Sun, 20 Sep 2026 07:16:49 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing us... This is a high threat mapped to CVE-2026-81652; security leaders should validate exposure, prioritize patching, and verify compensati...</p>
        <p><strong>CVEs:</strong> CVE-2026-81652</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-81652">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-81651 - The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-81651</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-81651</guid>
      <pubDate>Sun, 20 Sep 2026 07:16:49 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capa... This is a low threat mapped to CVE-2026-81651; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-81651</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-81651">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-81650 - The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of f</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-81650</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-81650</guid>
      <pubDate>Sun, 20 Sep 2026 07:16:49 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable bei... This is a low threat mapped to CVE-2026-81650; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-81650</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-81650">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-16542 - The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before req</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-16542</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-16542</guid>
      <pubDate>Sun, 20 Sep 2026 07:16:49 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-pr... This is a high threat mapped to CVE-2026-16542; security leaders should validate exposure, prioritize patching, and verify compensati...</p>
        <p><strong>CVEs:</strong> CVE-2026-16542</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-16542">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-14844 - The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-14844</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-14844</guid>
      <pubDate>Sun, 20 Sep 2026 07:16:48 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allo... This is a low threat mapped to CVE-2026-14844; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-14844</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-14844">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93965 - A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93965</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93965</guid>
      <pubDate>Sun, 20 Sep 2026 06:16:50 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. T... This is a medium threat mapped to CVE-2026-93965; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-93965</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93965">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93964 - A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCe</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93964</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93964</guid>
      <pubDate>Sun, 20 Sep 2026 06:16:50 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.... This is a medium threat mapped to CVE-2026-93964; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-93964</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93964">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93963 - A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93963</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93963</guid>
      <pubDate>Sun, 20 Sep 2026 06:16:49 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipula... This is a medium threat mapped to CVE-2026-93963; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-93963</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93963">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-93962 - A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93962</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93962</guid>
      <pubDate>Sun, 20 Sep 2026 05:16:29 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the compone... This is a high threat mapped to CVE-2026-93962; security leaders should validate exposure, prioritize patching, and verify compensati...</p>
        <p><strong>CVEs:</strong> CVE-2026-93962</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93962">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93961 - A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93961</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93961</guid>
      <pubDate>Sun, 20 Sep 2026 05:16:28 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api... This is a medium threat mapped to CVE-2026-93961; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-93961</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93961">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93960 - A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Co</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93960</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93960</guid>
      <pubDate>Sun, 20 Sep 2026 04:17:55 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Sco... This is a medium threat mapped to CVE-2026-93960; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-93960</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93960">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-86553 - SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Us</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-86553</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-86553</guid>
      <pubDate>Sun, 20 Sep 2026 04:17:06 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. This is a high threat mapped to CVE-2026-86553; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-86553</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-86553">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-86552 - SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acqui</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-86552</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-86552</guid>
      <pubDate>Sun, 20 Sep 2026 04:17:02 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. This is a medium threat mapped to CVE-2026-86552; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-86552</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-86552">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-93959 - A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93959</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93959</guid>
      <pubDate>Sun, 20 Sep 2026 03:16:31 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course... This is a high threat mapped to CVE-2026-93959; security leaders should validate exposure, prioritize patching, and verify compensati...</p>
        <p><strong>CVEs:</strong> CVE-2026-93959</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93959">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Critical] CVE-2026-94084 - Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.r</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-94084</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-94084</guid>
      <pubDate>Sun, 20 Sep 2026 02:16:53 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Critical | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform. This is a critical threat mapped to CVE-2026-94084; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-94084</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-94084">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Critical] CVE-2026-94083 - Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-94083</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-94083</guid>
      <pubDate>Sun, 20 Sep 2026 02:16:53 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Critical | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when the... This is a critical threat mapped to CVE-2026-94083; security leaders should validate exposure, prioritize patching, and verify compen...</p>
        <p><strong>CVEs:</strong> CVE-2026-94083</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-94083">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Critical] CVE-2026-93958 - A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93958</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93958</guid>
      <pubDate>Sun, 20 Sep 2026 02:16:53 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Critical | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argumen... This is a critical threat mapped to CVE-2026-93958; security leaders should validate exposure, prioritize patching, and verify compen...</p>
        <p><strong>CVEs:</strong> CVE-2026-93958</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93958">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93957 - A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleF</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93957</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93957</guid>
      <pubDate>Sun, 20 Sep 2026 02:16:52 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter of the file src/SearchEngine.php of the component Filt... This is a medium threat mapped to CVE-2026-93957; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-93957</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93957">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-86551 - The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-86551</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-86551</guid>
      <pubDate>Sun, 20 Sep 2026 02:16:51 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the S... This is a low threat mapped to CVE-2026-86551; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-86551</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-86551">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-94057 - Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead dep</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-94057</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-94057</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:11 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA proc... This is a medium threat mapped to CVE-2026-94057; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-94057</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-94057">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-94056 - Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uni</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-94056</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-94056</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:11 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory. This is a high threat mapped to CVE-2026-94056; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-94056</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-94056">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-94055 - Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-94055</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-94055</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:10 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. This is a low threat mapped to CVE-2026-94055; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-94055</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-94055">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-94054 - Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-94054</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-94054</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:10 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. This is a high threat mapped to CVE-2026-94054; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-94054</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-94054">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-93993 - Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93993</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93993</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:10 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a r... This is a high threat mapped to CVE-2026-93993; security leaders should validate exposure, prioritize patching, and verify compensati...</p>
        <p><strong>CVEs:</strong> CVE-2026-93993</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93993">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-93992 - Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93992</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93992</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:10 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers... This is a high threat mapped to CVE-2026-93992; security leaders should validate exposure, prioritize patching, and verify compensati...</p>
        <p><strong>CVEs:</strong> CVE-2026-93992</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93992">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-93991 - Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93991</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93991</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:10 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadat... This is a high threat mapped to CVE-2026-93991; security leaders should validate exposure, prioritize patching, and verify compensati...</p>
        <p><strong>CVEs:</strong> CVE-2026-93991</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93991">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-93990 - Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-1</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93990</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93990</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:10 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encod... This is a high threat mapped to CVE-2026-93990; security leaders should validate exposure, prioritize patching, and verify compensati...</p>
        <p><strong>CVEs:</strong> CVE-2026-93990</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93990">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-93989 - vLLM through 0.29.0 fails to properly validate bad_words token indices against the model&apos;s generation output width in Sa</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93989</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93989</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:10 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>vLLM through 0.29.0 fails to properly validate bad_words token indices against the model&apos;s generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply o... This is a low threat mapped to CVE-2026-93989; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-93989</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93989">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93988 - QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows a</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93988</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93988</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:09 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Atta... This is a medium threat mapped to CVE-2026-93988; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-93988</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93988">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-93956 - A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighl</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93956</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93956</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:09 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Sear... This is a low threat mapped to CVE-2026-93956; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-93956</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93956">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93955 - A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the functio</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93955</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93955</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:09 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org... This is a medium threat mapped to CVE-2026-93955; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-93955</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93955">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-89155 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-89155</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-89155</guid>
      <pubDate>Sat, 19 Sep 2026 23:17:08 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This is a low threat mapped to CVE-2026-89155; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-89155</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-89155">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93954 - A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSet</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93954</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93954</guid>
      <pubDate>Sat, 19 Sep 2026 22:16:28 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/j... This is a medium threat mapped to CVE-2026-93954; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-93954</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93954">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-82672 - Inconsistent Interpretation of HTTP Requests (&apos;HTTP Request/Response Smuggling&apos;) vulnerability in elixir-mint mint allow</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-82672</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-82672</guid>
      <pubDate>Sat, 19 Sep 2026 17:16:35 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Inconsistent Interpretation of HTTP Requests (&apos;HTTP Request/Response Smuggling&apos;) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connectio...</p>
        <p><strong>CVEs:</strong> CVE-2026-82672</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-82672">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Low] CVE-2026-82560 - Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting d</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-82560</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-82560</guid>
      <pubDate>Sat, 19 Sep 2026 16:16:32 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Low | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its in... This is a low threat mapped to CVE-2026-82560; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-82560</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-82560">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-94001 - A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-94001</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-94001</guid>
      <pubDate>Sat, 19 Sep 2026 15:17:08 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. This is a medium threat mapped to CVE-2026-94001; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-94001</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-94001">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-94000 - A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue oc</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-94000</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-94000</guid>
      <pubDate>Sat, 19 Sep 2026 15:17:08 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. This is a medium threat mapped to CVE-2026-94000; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-94000</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-94000">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-93999 - A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-93999</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-93999</guid>
      <pubDate>Sat, 19 Sep 2026 15:17:08 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. This is a medium threat mapped to CVE-2026-93999; security leaders should validate exposure, prioritize patching, and verify compensating controls.</p>
        <p><strong>CVEs:</strong> CVE-2026-93999</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-93999">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-9855 - The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the &apos;post_ID&apos; parameter in all</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-9855</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-9855</guid>
      <pubDate>Sat, 19 Sep 2026 12:16:55 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the &apos;post_ID&apos; parameter in all versions up to, and including, 2.7.8 due to insufficient es... This is a medium threat mapped to CVE-2026-9855; security leaders should validate exposure, prioritize patching, and verify compensat...</p>
        <p><strong>CVEs:</strong> CVE-2026-9855</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-9855">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-9832 - The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptograph</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-9832</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-9832</guid>
      <pubDate>Sat, 19 Sep 2026 12:16:55 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. Th... This is a medium threat mapped to CVE-2026-9832; security leaders should validate exposure, prioritize patching, and verify compensat...</p>
        <p><strong>CVEs:</strong> CVE-2026-9832</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-9832">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-9615 - The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. T</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-9615</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-9615</guid>
      <pubDate>Sat, 19 Sep 2026 12:16:55 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_dea... This is a medium threat mapped to CVE-2026-9615; security leaders should validate exposure, prioritize patching, and verify compensat...</p>
        <p><strong>CVEs:</strong> CVE-2026-9615</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-9615">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-9232 - The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-9232</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-9232</guid>
      <pubDate>Sat, 19 Sep 2026 12:16:55 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes i... This is a medium threat mapped to CVE-2026-9232; security leaders should validate exposure, prioritize patching, and verify compensat...</p>
        <p><strong>CVEs:</strong> CVE-2026-9232</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-9232">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-87917 - The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via &apos;data&apos; Dynam</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-87917</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-87917</guid>
      <pubDate>Sat, 19 Sep 2026 12:16:54 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via &apos;data&apos; Dynamic Content Tag in all versions up to, and including, 4.14.0... This is a medium threat mapped to CVE-2026-87917; security leaders should validate exposure, prioritize patching, and verify compensat...</p>
        <p><strong>CVEs:</strong> CVE-2026-87917</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-87917">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[High] CVE-2026-85658 - The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePres</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-85658</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-85658</guid>
      <pubDate>Sat, 19 Sep 2026 12:16:54 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> High | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode... This is a high threat mapped to CVE-2026-85658; security leaders should validate exposure, prioritize patching, and verify compensatin...</p>
        <p><strong>CVEs:</strong> CVE-2026-85658</p>
        <p><strong>Recommended Security Defense:</strong> <a href="https://www.tenable.com/products/nessus?ref=rampeand&utm_source=secopspulse&utm_medium=rss-feed&utm_campaign=tenable">Enterprise Vulnerability Management &amp; Continuous Scanning</a></p>
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-85658">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-7527 - The WP Ghost (Hide My WP Ghost) – Security &amp; Firewall plugin for WordPress is vulnerable to Open Redirect in all version</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-7527</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-7527</guid>
      <pubDate>Sat, 19 Sep 2026 12:16:54 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The WP Ghost (Hide My WP Ghost) – Security &amp; Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin no... This is a medium threat mapped to CVE-2026-7527; security leaders should validate exposure, prioritize patching, and verify compensat...</p>
        <p><strong>CVEs:</strong> CVE-2026-7527</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-7527">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>

    <item>
      <title>[Medium] CVE-2026-75959 - The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the &apos;log_table_filter&apos; paramet</title>
      <link>https://www.secopspulse.com/cve/CVE-2026-75959</link>
      <guid isPermaLink="true">https://www.secopspulse.com/cve/CVE-2026-75959</guid>
      <pubDate>Sat, 19 Sep 2026 12:16:54 GMT</pubDate>
      <description><![CDATA[<p><strong>Severity:</strong> Medium | <strong>Category:</strong> CVE | <strong>Source:</strong> NVD</p>
        <p>The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the &apos;log_table_filter&apos; parameter in all versions up to, and including, 1.0.36 due to insuf... This is a medium threat mapped to CVE-2026-75959; security leaders should validate exposure, prioritize patching, and verify compensa...</p>
        <p><strong>CVEs:</strong> CVE-2026-75959</p>
        
        <p><a href="https://www.secopspulse.com/cve/CVE-2026-75959">Read full intelligence briefing on SecOpsPulse</a></p>]]></description>
    </item>
  </channel>
</rss>