CVE-2026-6485
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
CVSS
8.2
High
EPSS
0.1%
p2
KEV
—
Exploit Today
1
0-100
Published: Sep 9, 2026 · Last modified: Sep 10, 2026 · CWE-489
0.1%EPSS · 30 days0.1%
2026-09-092026-09-11
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-539529.8 CRI—
——0GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installation. However, this control is neutralized by a self-exclusion bug within the deletion logic, leaving the setup script accessible for unauthorized account creation even after a legitimate installation is completed. As of time of publication, no known patched versions are available.23hCVE-2026-775459.0 CRI11.8%
——4A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.15dCVE-2026-667875.4 MED15.0%
——5A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.9dCVE-2026-664058.8 HIG20.6%
——6DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.15dCVE-2026-664037.5 HIG17.0%
——5DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.15dCVE-2026-411867.5 HIG27.4%
——8When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutine stacks (including function arguments), and command-line arguments. Depending on the process's in-memory state, the heap may contain sensitive material. The debug listener is opt-in but is unsafe when enabled because it offers no authentication and no safe localhost-only binding option.36d