Contact Zero

Weekly /

Week 2026-W41

2026-10-05 to 2026-10-11 · 120 new CVEs · 5 added to CISA KEV · 3 high-priority with public PoCs

  1. CVE-2015-3306 ProFTPD ProFTPD 75
    exploited in the wild, public PoC

    ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

  2. CVE-2015-5477 ISC BIND 65
    exploited in the wild, public PoC

    ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

  3. CVE-2023-22894 Strapi Strapi 65
    exploited in the wild, public PoC

    Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontin

  4. CVE-2016-3081 Apache Struts 60
    exploited in the wild

    Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

  5. CVE-2026-76459 As part of Cisco's ongoing commitment to proactive security and… 60
    critical 9.8

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnera

  6. CVE-2026-76454 A vulnerability in the Cisco Smart Licensing Utility API of Cisco… 55
    critical 9.1

    A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerab

  7. CVE-2021-3199 ONLYOFFICE Docs 50
    exploited in the wild

    ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

  8. CVE-2026-106237 google chrome 50
    critical 9.6

    Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

  9. CVE-2026-106195 google chrome 50
    critical 9.1

    Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)

  10. CVE-2026-82531 Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection… 45
    critical 9.2, public PoC

    Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbat

Reading