PULSE
FEED
ransomplay reclama a Titus · DE · Technologyransomplay reclama a Airtech Mechanical Services · US · Professional Servicesransomplay reclama a Orth Automobile · DE · Manufacturingransominterlock reclama a Blaise C. Bender, PC · US · Professional Servicesransomaurora reclama a Buford-Thompson Company, LTD · US · Manufacturingransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomplay reclama a Titus · DE · Technologyransomplay reclama a Airtech Mechanical Services · US · Professional Servicesransomplay reclama a Orth Automobile · DE · Manufacturingransominterlock reclama a Blaise C. Bender, PC · US · Professional Servicesransomaurora reclama a Buford-Thompson Company, LTD · US · Manufacturingransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturing
← All CVEs
CVE WatchSep 29, 2026

CVE-2026-102263

A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown f

CVSS

4.7

Medium

EPSS

0.2%

p11

KEV

—

Exploit Today

3

0-100

Published: Sep 29, 2026 · Last modified: Sep 29, 2026 · CWE-284 · CWE-434

EPSS · 30d

Not enough EPSS history yet.

Technical description

A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-103239—
—
———MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload. A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator. Preconditions: - An authenticated account with the tag editor permission (perm_tag_editor) - Network access to the MISP instance Impact: - Unauthorized creation or modification of User and Organisation records - Privilege escalation from tag editor to site administrator Affected versions: < 2.5.4811h
CVE-2026-1024547.2 HIG
—
———EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.13h
CVE-2026-1028455.3 MED
—
———A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component HTTP Response. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.8h
CVE-2026-1028426.3 MED
—
——0A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the argument ADMIN_RS_KCFINDER leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.8h
CVE-2026-703569.1 CRI
—
——0The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.1d
CVE-2026-92226—
—
——0Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.1d