NVD disclosure day

Published threat advisories for September 30, 2026

CVE advisoryCRITICAL

CVE-2026-51859

Bisheng Directory Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A directory traversal vulnerability in Bisheng's file handling could allow unauthorized access to system files. This issue, located in the `save_download_file` function, is reachable via crafted requests and could lead to arbitrary file modification or system compromise.

CVE advisoryKnown Exploit

CVE-2026-102489

Zammad Session Hijack Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A session hijack vulnerability in Zammad could allow remote code execution as the zammad user. This affects versions 6.3.0 through 6.5.4, and while present in versions 7.0.0 to 7.1.3, it is not exploitable in those later versions due to environmental conditions. This issue is critical because it could compromise system

• CISA KEV

CVE advisoryKnown Exploit

CVE-2026-76504

Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Cisco Catalyst SD-WAN Manager's API authentication could allow an unauthenticated attacker to gain admin privileges. This is due to improper handling of URI encoding in HTTP requests. Exploitation could lead to unauthorized access and control of affected systems.

• CISA KEV