VulnCheck September 23rd, 2026 Release Notes

  • Platform - Improved OSV and SBOM scan support in API / CLI / GitHub Action and improved MCP server including routing / response shaping / exploit filters / classification.
  • Exploit & Vulnerability Intelligence - Improve CVE refresh handling to leverage new pipeline for improved timeliness and efficiency, improved vulncheck-nvd2 support for complete and error-free CVSS scores and references, improve MITRE ATT&CK technique fetcher data correctness and improved index timestamp correctness.
  • Package Intelligence - Improve collection timeliness, boost Maven license coverage, add new repo support to Maven, increase Maven SHA1s and meaningfully improve NPM data completeness.
  • Canary Intelligence - Canary rest pipeline including forensic report generation is now in production.
  • Target Intelligence - Improved reliability, improved accuracy, big boost in request efficiency, improved SSH scanning and improved documentation.

Recent Initial Access activity

Sangoma Switchvox Phone-Apps PhoneIP SQL Injection to Command Execution was added on Sep, 1 and is found in 1 product.

View more detail on CVE-2026-9586

Langflow Unauthenticated Code Injection via auto_login SUPERUSER Token was added on Sep, 15 and is found in 1 product.

View more detail on CVE-2026-9198

N-able N-central Struts MultipartRequestHandler Unauthenticated RCE was added on Sep, 16 and is found in 1 product.

View more detail on CVE-2026-86218

HKUDS AutoAgent Sandbox TCP Command Server Unauthenticated RCE was added on Sep, 13 and is found in 1 product.

View more detail on CVE-2026-86124

MikroTik RouterOS Unauthenticated SSH Takeover (MikroTrick) was added on Sep, 6 and is found in 1 product.

View more detail on CVE-2026-86060

GitLab CE/EE Repository Commits and Files API Unauthenticated Arbitrary File Read was added on Sep, 16 and is found in 2 products.

View more detail on CVE-2026-85706

SonicWall SMA1000 ctrl-service cmsSnmpTrap.sh Sed Command Injection was added on Sep, 9 and is found in 3 products.

View more detail on CVE-2026-83549

SonicWall SMA1000 Unauthenticated Root RCE via CouchDB SSRF Chained with cmsSnmpTrap Command Injection was added on Sep, 9 and is found in 3 products.

View more detail on CVE-2026-83548

JFrog Artifactory Authentication Bypass via Blank Join Key to Obtain Admin Token was added on Sep, 9 and is found in 1 product.

View more detail on CVE-2026-82329

Ubiquiti UniFi OS CRLF Injection Auth Bypass was added on Sep, 9 and is found in 1 product.

View more detail on CVE-2026-77550

Ubiquiti UniFi OS Server Pre-Auth Command Injection was added on Sep, 14 and is found in 1 product.

View more detail on CVE-2026-77539

Ubiquiti UniFi Protect Application Device Registration Command Injection was added on Sep, 9 and is found in 1 product.

View more detail on CVE-2026-77537

ASUS Control Center ServerGUID Key Leak RCE was added on Sep, 9 and is found in 1 product.

View more detail on CVE-2026-75754

MikroTik RouterOS SSH Rekey Connection-Protocol Bypass was added on Sep, 6 and is found in 1 product.

View more detail on CVE-2026-67279

MikroTik RouterOS SSH RSA Public-Key Authentication Bypass was added on Sep, 6 and is found in 1 product.

View more detail on CVE-2026-67276

OSGeo GeoNetwork Unauthenticated Formatter Upload and Saxon XSLT Injection to Remote Code Execution was added on Sep, 1 and is found in 1 product.

View more detail on CVE-2026-63219

OSGeo GeoNetwork Saxon XSLT External Function Injection to Remote Code Execution was added on Sep, 1 and is found in 1 product.

View more detail on CVE-2026-58400

Langflow Responses API Authorization Bypass Through User-Controlled Key was added on Sep, 14 and is found in 1 product.

View more detail on CVE-2026-55255

Gogs Pull Request Rebase Merge Argument Injection Remote Code Execution was added on Sep, 7 and is found in 1 product.

View more detail on CVE-2026-52806

CrowdStrike Falcon Sensor Macro Remediation TOCTOU Local Privilege Escalation was added on Sep, 15 and is found in 1 product.

View more detail on CVE-2026-40058

OpenPrinting CUPS Local Admin Token Theft Root File Write was added on Sep, 1 and is found in 1 product.

View more detail on CVE-2026-34990

Langflow Python Function Component Unauthenticated RCE was added on Sep, 14 and is found in 1 product.

View more detail on CVE-2026-19295

Microsoft Windows Recall Scheduled Task Link Following Local Privilege Escalation was added on Sep, 9 and is found in 1 product.

View more detail on CVE-2025-60710

Fortinet FortiOS CAPWAP Heap-Based Buffer Overflow was added on Sep, 15 and is found in 2 products.

View more detail on CVE-2025-25249

Proxmox VE Authentication Bypass via tfa-challenge Parameter was added on Sep, 7 and is found in 1 product.

View more detail on CVE-2023-54391

XWiki Platform SkinsCode.XWikiSkinsSheet Groovy Template Injection RCE was added on Sep, 11 and is found in 1 product.

View more detail on CVE-2023-37462

pyLoad js2py pyimport Unauthenticated Remote Code Execution was added on Sep, 11 and is found in 1 product.

View more detail on CVE-2023-0297

SnakeYAML Unsafe Deserialization RCE was added on Sep, 9 and is found in 1 product.

View more detail on CVE-2022-1471

Squirrelly Express Render API Config Injection SSTI to RCE was added on Sep, 10 and is found in 1 product.

View more detail on CVE-2021-32819

ThinkPHP invokefunction RCE via Arbitrary PHP Function Call was added on Sep, 10 and is found in 1 product.

View more detail on CVE-2019-9082

Drupal Core Render Array PHP Injection RCE (Drupalgeddon 3) was added on Sep, 10 and is found in 1 product.

View more detail on CVE-2018-7602

Drupal Form API Remote Code Execution via Render Array Injection was added on Sep, 10 and is found in 1 product.

View more detail on CVE-2018-7600