PULSE
FEED
ransomqilin reclama a Arnold Center · US · Not Foundransomincransom reclama a bakemyday.se · SE · Retail & E-Commerceransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Servicesransomqilin reclama a Arnold Center · US · Not Foundransomincransom reclama a bakemyday.se · SE · Retail & E-Commerceransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Services
← All CVEs
CVE WatchSep 28, 2026

CVE-2026-101000

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/

CVSS

10.0

Critical

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Sep 28, 2026 · Last modified: Sep 28, 2026 · CWE-862 · CWE-863

EPSS · 30d

Not enough EPSS history yet.

Technical description

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1011392.7 LOW
—
———A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.5h
CVE-2026-499949.1 CRI
—
———Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1.6h
CVE-2026-86102—
—
———An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.6h
CVE-2026-96538—
—
———WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.7h
CVE-2026-973357.7 HIG
—
———Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.7h
CVE-2026-863356.3 MED
—
———Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.7h