VYPR
AI Brief2026-09-09· generated Sep 8, 2026

What you need to know today.

Critical RCE and privilege escalation flaws hit Ivanti, Microsoft Azure, Hitachi, and Tenda, while a Linux kernel vulnerability is added to CISA KEV.

A critical deserialization vulnerability in Ivanti Neurons for ITSM, affecting versions prior to 2026.2, allows remote attackers to execute arbitrary code. This impacts both unauthenticated and authenticated users, depending on the specific vulnerability, with multiple CVEs including CVE-2026-12745, CVE-2026-12744, CVE-2026-12650, CVE-2026-12647, CVE-2026-12646, and CVE-2026-12645. As Cyber Security News reported, these flaws enable privilege escalation and RCE attacks, underscoring the need for immediate patching.

Multiple critical vulnerabilities have been disclosed in Microsoft Azure Active Directory B2C and Azure AI Language. CVE-2026-83711 allows unauthorized network access for privilege elevation via a user-controlled key, while CVE-2026-70352 involves missing authentication for critical functions, also enabling network-based privilege escalation. As detailed by Vypr Intelligence and Cyber Security News, these issues highlight significant security gaps in Microsoft's cloud offerings.

Critical command injection and deserialization vulnerabilities affect Hitachi Cosminexus Component Container. Versions from 11-70-01 prior to 11-70-03, 11-60 prior to 11-60-03, and other earlier versions are impacted by CVE-2026-71377 (Command Argument Injection), CVE-2026-71376 (OS command injection), and CVE-2026-71374 (Deserialization of untrusted data). These flaws could allow remote attackers to execute arbitrary commands on affected systems.

A critical OS command injection vulnerability exists in Tenda CP3 versions prior to 27.5.57.101, specifically in the Functions/AutoAddWifi.cpp component. This flaw, identified as CVE-2026-86152, allows for command injection via crafted input, potentially leading to full system compromise. Vypr Intelligence notes that Tenda devices are facing multiple disclosed vulnerabilities, emphasizing the need for users to update their firmware.

The Linux kernel is affected by CVE-2026-31431, a high-severity vulnerability with a CVSS score of 7.8, which has been added to the CISA KEV catalog. This flaw, described as a crypto algorithm issue related to operating out-of-place, has been the subject of extensive reporting and analysis, including by The Hacker News and Unit 42, with various exploits and related vulnerabilities like "Copy Fail" and "Dirty Frag" being discussed. Patches and mitigations have been developed, and users are urged to apply them promptly.

JetBrains Hub and YouTrack are impacted by critical vulnerabilities. CVE-2026-86480 in JetBrains Hub (versions before 2026.2.52442) allows unauthenticated attackers to register trusted services and gain superuser privileges. In JetBrains YouTrack, CVE-2026-86478 affects versions before 2025.3.161254 and 2026.1.14042, enabling unauthenticated account takeover through a self-asserted email address, as reported by Vypr Intelligence.

Critical authentication bypass vulnerabilities affect multiple miniorange.com Joomla extensions. CVE-2026-77998 impacts miniOrange SAML SSO and related plugins (versions < 11.0.2 and < 6.4 respectively), allowing unauthenticated bypass via the SAMLResponse parameter. Additionally, CVE-2026-77995 affects miniOrange OAuth Client and related plugins (versions < 3.2.0 and < 1.2.2 respectively), enabling arbitrary account takeover. These flaws pose a significant risk to Joomla sites using these extensions.

Advantech WISE-6610 series devices are affected by CVE-2026-79697, a critical vulnerability with a CVSS score of 9.9. The exact nature of the vulnerability is not fully detailed but is described as a critical flaw impacting various models within the WISE-6610 product line.

Asus Control Center is vulnerable to CVE-2026-75754, a critical flaw combining Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials. An unauthorized user can exploit this via an HTTP request to obtain an encryption key, leading to local service compromise, as detailed by Cyber Security News.

Digital-Infrastructure v9.6.7 contains a critical Single-Sign On (SSO) component vulnerability, CVE-2026-79576. This flaw allows attackers to authenticate as any user, including administrators, without requiring a password, posing a severe risk to systems utilizing this software.

Synthesized by Vypr AI
Critical RCEs and Linux Kernel Flaw Dominate Security Briefing · VYPR