VYPR
AI Brief2026-09-21· generated Sep 20, 2026

What you need to know today.

Critical RCE in REDCap and sandbox escape in Firefox, alongside multiple other high-severity flaws across various vendors.

A critical vulnerability in Comfast CF-N1-S 2.6.0.1's Web Management Interface could allow attackers to achieve a stack-based buffer overflow. The flaw resides in the get_css_path_from_uri function within the /cgi-bin/mbox-config file. Successful exploitation could lead to system instability or potentially code execution, though specific impact details are limited. Users are advised to update to a patched version once available. CVE-2026-94003.

REDCap is facing a critical unauthenticated Remote Code Execution vulnerability stemming from its survey passthrough routing and Data Import processing logic. Attackers can exploit this by manipulating HTTP requests, potentially gaining unauthorized access and control over affected systems. This highlights a significant risk for organizations using REDCap for data collection and management. CVE-2026-90817.

HPE's SD-WAN Orchestrator has a critical vulnerability that could expose sensitive configuration information. An authenticated remote attacker with read-only privileges can exploit this flaw by sending a specially crafted request, potentially leading to unauthorized access to network configurations. This disclosure, as reported by Cyber Security News, underscores the need for prompt patching of HPE devices. CVE-2026-76672.

A critical sandbox escape vulnerability has been identified in Mozilla Firefox's DOM: Core & HTML component, as detailed in Vypr Intelligence. This flaw could allow attackers to break out of the browser's sandbox, potentially leading to broader system compromise. The vulnerability is fixed in Firefox 156, Firefox ESR 115.41, 140.16, and 153.3, as well as Thunderbird versions 156, 140.16, and 153.3. CVE-2026-92018.

D-Link R95 BE9500_1.00.16 is affected by an OS command injection vulnerability in the DHMAPI component. Specifically, the system function in the /bin/ssi file is vulnerable to manipulation of the NTPServer argument, allowing attackers to execute arbitrary commands on the device. This could lead to full device compromise. CVE-2026-93958.

Multiple high-severity use-after-free vulnerabilities have been disclosed in various Mozilla Firefox components, including Widget: Gtk, Widget: Win32, Graphics, Graphics: Text, SVG, and the JavaScript: WebAssembly component. These flaws, detailed in Vypr Intelligence, could lead to application crashes or potentially arbitrary code execution. Patches are available in Firefox 156, Firefox ESR 115.41, 140.16, and 153.3, and Thunderbird 156, 140.16, and 153.3. CVE-2026-92067, CVE-2026-92056, CVE-2026-92060, CVE-2026-92058, CVE-2026-92049, CVE-2026-92046, CVE-2026-92040, CVE-2026-92029, CVE-2026-92028, CVE-2026-92024.

The Perl Foundation's DBI library, versions prior to 1.653, contains a critical vulnerability that allows arbitrary module loading. By manipulating the dbm_type and dbm_mldbm attributes in DBD::DBM, attackers can trick the library into loading unintended modules, potentially leading to code execution. This highlights a supply chain risk for applications relying on this widely used Perl module. CVE-2026-78030.

Ghostscript versions prior to 10.08.0 contain a critical heap-based buffer overflow vulnerability in its JPEG 2000 output adapter. Attackers can exploit this by providing a crafted PDF with a malicious JPEG 2000 image, leading to memory corruption and potential code execution. This impacts systems that process PDFs containing such images. CVE-2026-39919.

D-Link DIR-X1860 and DIR-X1860Z routers, up to version 1.0.2.220120.165402, are affected by a high-severity vulnerability in the routerd component. Manipulation of the passwd_set argument in the /ubus file could lead to unauthorized access or control over the router's functionality. CVE-2026-94036.

NivoCart through version 2.4.0 has a critical arbitrary file upload vulnerability in its File Manager's multi() endpoint. The vulnerability arises from a failure to properly validate file extensions when the chunks parameter is 2 or higher, or when handling new filenames. Attackers with view-only backend access could exploit this to upload malicious files, potentially leading to remote code execution. CVE-2026-94104.

The ZTE SmartLife app has a high-severity vulnerability that allows attackers to directly call backend interfaces using acquired authentication parameters. This bypasses intended security controls and could lead to unauthorized access or manipulation of smart home devices connected to the app. CVE-2026-86553.

Synthesized by Vypr AI