VulnCheck September 2nd, 2026 Release Notes

  • Platform - Improve /v3/search/cpe API endpoint responsiveness, improve MCP server (add canary/target/curated exploits/recent advisories tools and improve list_indices/search_docs/search_index tools) and make a number of API improvements
  • Exploit & Vulnerability Intelligence - v4 advisory support is now complete, improve CPE support, add nist-nvd2-cvehist and redhat-purls indexes and make meaningful API improvements
  • Package Intelligence - Improve Maven coverage, added Atlassian and Jenkins Maven repositories, meaningfully boost Maven package dataset size, improve OCaml/opam support, improve NPM package CVE matching and speed up end-to-end collection time
  • Canary Intelligence - Introduce C2Extractor - dedicated C2 extraction service and improve canary reset pipeline
  • Target Intelligence - Improve version detection for message query infrastructure such as RabbitMQ, LavinMQ, Apache Qpid and Erlang as well as improve multi-service fingerprinting to cross-reference multiple exposed interfaces on the same host to improve service and version detection to boost breadth/depth of scanning and results confidence

Recent Initial Access activity

ScadaBR OS Command Injection Remote Code Execution was added on Aug, 12 and is found in 1 product.

View more detail on CVE-2026-8603

PaperCut NG/MF Unsafe Dynamic Class Loading RCE via Central Reports Driver Class was added on Aug, 27 and is found in 2 products.

View more detail on CVE-2026-82078

PaperCut NG/MF Tapestry Page-Confusion Access-Control Bypass was added on Aug, 30 and is found in 2 products.

View more detail on CVE-2026-81578

SPIP Template Environment Export Unauthenticated Remote Code Execution was added on Aug, 20 and is found in 1 product.

View more detail on CVE-2026-77647

GeoServer Unauthenticated SQL Injection to Remote Code Execution was added on Aug, 23 and is found in 1 product.

View more detail on CVE-2026-76904

Zbtlink Router DARKLANTERN Unauthenticated Root Command Injection (MoreQuick infosrvd revProto) was added on Aug, 25 and is found in 16 products.

View more detail on CVE-2026-74233

Zbtlink Router SPEAKINGSTONE Cloud C2 Implant Unauthenticated Root Code Execution was added on Aug, 25 and is found in 15 products.

View more detail on CVE-2026-74232

Zimbra Collaboration Swatchdog Unauthenticated SMTP Log Injection to OS Command Injection was added on Aug, 23 and is found in 1 product.

View more detail on CVE-2026-73570

Metabase Password Reset Unauthenticated SQL Injection to Remote Code Execution was added on Aug, 19 and is found in 1 product.

View more detail on CVE-2026-72898

DataLinkDC Dinky uploadFromRsByLocal Unauthenticated Arbitrary File Write was added on Aug, 23 and is found in 1 product.

View more detail on CVE-2026-70558

Microsoft Windows Defender Scan+Clean TOCTOU Elevation of Privilege was added on Aug, 25 and is found in 1 product.

View more detail on CVE-2026-69414

ComfyUI LoadTrainingDataset Pickle Deserialization was added on Aug, 17 and is found in 1 product.

View more detail on CVE-2026-68711

Microsoft SharePoint BCS DotNetAssembly Unsafe .NET Type Instantiation RCE was added on Aug, 19 and is found in 1 product.

View more detail on CVE-2026-63520

RabbitMQ /api/auth OAuth 2 Client Secret Disclosure was added on Aug, 23 and is found in 1 product.

View more detail on CVE-2026-57219

Microsoft SharePoint SPJsonWebSecurityTokenHandlerV2 JWT Authentication Bypass was added on Aug, 16 and is found in 1 product.

View more detail on CVE-2026-55040

Gladinet CentreStack X-Glad-Filter Header SQL Injection RCE was added on Aug, 12 and is found in 1 product.

View more detail on CVE-2026-54368

Gladinet CentreStack Settings Update Via Unauthenticated API Authorization Bypass was added on Aug, 12 and is found in 1 product.

View more detail on CVE-2026-54367

Gladinet CentreStack Hardcoded Key Token Forgery was added on Aug, 12 and is found in 1 product.

View more detail on CVE-2026-54363

Adobe ColdFusion RDS Path Traversal Arbitrary File Write RCE was added on Aug, 20 and is found in 1 product.

View more detail on CVE-2026-48282

Webkul Krayin CRM Installer Bypass Account Takeover to TinyMCE Upload Unauthenticated RCE was added on Aug, 18 and is found in 1 product.

View more detail on CVE-2026-41452

elFinder Resize Background Parameter Unauthenticated Command Injection RCE was added on Aug, 16 and is found in 1 product.

View more detail on CVE-2026-41247

Cacti RRDtool Command Execution was added on Aug, 23 and is found in 1 product.

View more detail on CVE-2026-40079

OpenEMR Document Category Tree Authenticated Remote Code Execution was added on Aug, 24 and is found in 1 product.

View more detail on CVE-2026-39932

OpenEMR Authenticated Admin Backup-Import Arbitrary SQL Execution was added on Aug, 24 and is found in 1 product.

View more detail on CVE-2026-39931

Webkul Krayin CRM TinyMCE Authenticated Arbitrary File Upload RCE was added on Aug, 18 and is found in 1 product.

View more detail on CVE-2026-38526

Cisco Firewall Management Center license.tmp Hardcoded Credentials was added on Aug, 11 and is found in 1 product.

View more detail on CVE-2026-20316

Langflow Public Flow Build Unauthenticated Remote Code Execution was added on Aug, 12 and is found in 1 product.

View more detail on CVE-2026-13448

Langflow Validate Code Remote Code Execution was added on Aug, 27 and is found in 1 product.

View more detail on CVE-2026-0768

FlowiseAI Flowise Unauthenticated Attachments Path Traversal Remote Code Execution was added on Aug, 25 and is found in 1 product.

View more detail on CVE-2025-71333

D-Link DIR-823x /goform/set_prohibiting Authenticated Command Injection was added on Aug, 18 and is found in 1 product.

View more detail on CVE-2025-29635

MLflow Model Registry Source Path Traversal Arbitrary File Read was added on Aug, 12 and is found in 1 product.

View more detail on CVE-2025-11201

LiteLLM Post Call Rules Remote Code Execution was added on Aug, 18 and is found in 1 product.

View more detail on CVE-2024-6825