2026-09-18
This weekNew web3 security vulnerability disclosures and CVEs in the last 48 hours
In the past 48 hours, several critical vulnerabilities across various technologies have been disclosed, impacting enterprise security management tools, cloud services, industrial control systems, and…
RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours
RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)
Summary
In the past 48 hours, several critical vulnerabilities across various technologies have been disclosed, impacting enterprise security management tools, cloud services, industrial control systems, and software platforms. Key highlights include a novel cybersecurity assessment tool for complex infrastructures, new CVE entries affecting major vendors like Cisco, Docker, and Google, as well as updated advisories from CISA on exploited vulnerabilities.
Key Developments
Cybersecurity Assessment Tool Development
A project funded by the European Commission (EC) aims to deliver a tool for assessing cybersecurity levels across complex enterprise-wide architectures using a Bayesian network-based metamodel. The tool generates vulnerability heat maps and will be validated through pilots with energy utilities in Sweden and Germany. Source: CORDIS Project ID 673980CVE-2026-76460 (Cisco)
A critical vulnerability affecting Cisco products was disclosed, classified under CVE-2026-76460 with a CVSS score of 10. Source: Feedly CVE SearchCVE-2026-91843 (Checkpoint)
Checkpoint systems are vulnerable to an exploitable flaw identified as CVE-2026-91843, carrying a high severity rating of 9.8. Source: Feedly CVE SearchCVE-2026-77179 (Docker)
Docker reported a critical vulnerability (CVE-2026-77179) with a high CVSS rating, affecting container orchestration environments. Source: Feedly CVE SearchCVE-2026-76461 (Cisco)
Another Cisco-related issue, CVE-2026-76461, is marked as known exploited and includes KEV designation, with a CVSS score of 9.8. Source: Feedly CVE SearchCVE-2026-85889 (Microsoft)
A severe vulnerability affecting Microsoft platforms was cataloged under CVE-2026-85889, assigned the maximum CVSS score of 10. Source: Feedly CVE SearchGitLab Path Traversal Vulnerability
GitLab's Community and Enterprise Editions were found vulnerable to path traversal (CVE-2026-85706), enabling unauthenticated users to access arbitrary files, per CISA’s Known Exploited Vulnerabilities Catalog. Source: CISA KEV CatalogJFrog Artifactory Improper Authentication
JFrog Artifactory suffered from an improper authentication vulnerability (CVE-2026-42018) and incorrect authorization flaw (CVE-2026-42016), both potentially exposing sensitive resources. Source: CISA KEV CatalogConnectWise ScreenConnect Privilege Issue
ConnectWise ScreenConnect faced an improper privilege management and missing authorization vulnerability (CVE-2026-84869), which could permit unauthorized file transfers and execution during remote sessions. Source: CISA KEV CatalogMikroTik RouterOS Authentication Flaw
MikroTik's RouterOS was reported to have a missing authentication vulnerability (CVE-2026-67277) impacting the btest service, leading to potential kernel memory disclosure and denial of service. Source: CISA KEV Catalog
Sources
- CORDIS Project Details
- Feedly CVE Search Results
- CISA Known Exploited Vulnerabilities Catalog - GitLab
- CISA KEV Catalog - JFrog Artifactory Issues
- CISA KEV Catalog - ConnectWise ScreenConnect
- CISA KEV Catalog - MikroTik RouterOS
These sources provide comprehensive details on the disclosed vulnerabilities, tool developments, and recommended actions for mitigation.