CISA lists CVE-2026-9198 as a Langflow code-injection issue that allows unauthenticated remote code execution on default deployments. Do not internet-expose unauthenticated AI workflow UIs. Apply vendor mitigations; this desk does not invent a patch build.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability. Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
The Rails project's GitHub advisory says an unauthenticated attacker can abuse Active Storage image variant processing with libvips to read arbitrary files accessible to the Rails process, including environment secrets; exposed signing or service credentials can enable remote code execution or lateral movement. The affected configuration uses libvips for Active Storage and accepts untrusted image uploads. SecurityWeek reported on 31 August that VulnCheck had observed exploitation. Upgrade Active Storage to 7.2.3.2, 8.0.5.1 or 8.1.3.1, use libvips 8.13 or later, and rotate secret_key_base plus every other secret readable by the application process. Rails branches without a fixed release should move to a supported branch or remove libvips until they can patch.
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability. Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability. Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability . Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
Check Point SmartConsole Improper Authentication Vulnerability. Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
DD-WRT Stack-Based Buffer Overflow Vulnerability. DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability. Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
WordPress Core Interpretation Conflict Vulnerability. WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
WordPress Core SQL Injection Vulnerability. WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.