NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
RSS

2026-10-08 Daily Security Intelligence

CVE Intelligence 3

CVE-2026-76482 CVSS 10.0 Critical 2026-10-08

Improper input validation in Cisco License On-Prem allows remote code execution

Before the release of a hardened version, the core module of Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem) contains an improper cryptographic signature verification flaw (CWE-347) caused by incorrect input validation. An attacker can exploit the vulnerability remotely over the network with low attack complexity and no user interaction. This could severely compromise system confidentiality, integrity, and availability, allowing remote code execution or complete control of the target system. All Cisco License On-Prem users who have not updated to a fixed version are affected. Because the attack is network-based and requires neither privileges nor user interaction, an attacker can easily launch it remotely.

Component
Cisco License On-Prem is Cisco's on-premises software license management platform. It manages and validates software licenses within an enterprise and is an important part of Cisco's commitment to proactive security and product quality.
Risks
  • Complete system control: With a CVSS score of 10.0 and an expanded scope (Scope Changed), the vulnerability allows an attacker to execute arbitrary code on the victim's system and obtain the highest privileges
  • No-user-interaction attack: The attack takes place over the network (AV:N) and requires no user interaction (UI:N), allowing an attacker to trigger the vulnerability remotely without the target's knowledge
  • Severe impact: The vulnerability has a high impact on confidentiality, integrity, and availability (C:H/I:H/A:H), potentially causing data disclosure, system tampering, or service disruption
Source
Remediation
  • Restrict network access to the management platform, allowing connections only from trusted IP addresses
  • Monitor abnormal network requests and input data, and deploy an intrusion detection system to identify potential exploitation attempts
CVE-2026-96408 CVSS 10.0 Critical 2026-10-07

Code injection in the Movable Type upgrade script allows arbitrary code execution

The Movable Type upgrade script contains a code injection flaw (CWE-94) caused by improper validation and control of input data. The vulnerability allows an unauthenticated attacker to execute arbitrary Perl scripts or SQL queries on the affected product. Movable Type fails to properly filter user-controlled input during the upgrade process, allowing malicious code to be injected. All Movable Type deployments without mitigation measures are affected. An attacker can trigger the vulnerability remotely without authentication, directly execute system commands or manipulate the database, and cause serious security damage.

Component
Movable Type is a popular open-source blogging and content management system, widely used to build websites and publish content.
Risks
  • Complete system control: An attacker can exploit the vulnerability to execute arbitrary Perl scripts on the server and take full control of the server environment
  • Database tampering: An attacker can execute arbitrary SQL queries, leading to data disclosure, modification, or deletion
  • Unauthenticated remote attack: An attacker can access the upgrade script endpoint to launch an attack without logging in or requiring any user interaction
Source
Remediation
  • Immediately restrict network access to the upgrade script, allowing access only from trusted administrator IP addresses
  • Configure Web application firewall (WAF) rules to block malicious code injection attempts targeting the upgrade script
  • Contact the vendor promptly for an official patch or upgrade to a secure version
CVE-2026-107102 CVSS 10.0 Critical 2026-10-07

Payment callback parameter validation bypass in an ERP system allows authentication bypass

An ERP system contains an insufficient data authenticity verification flaw (CWE-345) caused by improper validation of payment callback parameters and inadequate authentication controls on API endpoints. An unauthenticated remote attacker can manipulate parameters to make the application create an authenticated session for any user without valid payment verification. Successful exploitation allows the attacker to bypass authentication and gain unauthorized access to other users' accounts on the target system. All users of ERP systems where this flaw remains unfixed are affected. An attacker can launch the attack remotely without any prerequisites.

Component
An ERP (enterprise resource planning) system integrates and manages an enterprise's core business processes, including finance, supply chain, and manufacturing modules.
Risks
  • Complete authentication bypass: An attacker can bypass the normal login and payment verification processes to gain direct access to the system
  • Unauthorized account access: An attacker can impersonate any user to access and use other users' sensitive data and functions
  • Remote attack without user interaction: An attacker only needs to send a crafted API request to trigger the vulnerability and take control remotely, with no user interaction
Source
Remediation
  • Strictly verify the origin and integrity of payment callback parameters and ensure that signature verification works correctly
  • Strengthen authentication controls on API endpoints and enforce strict access-control lists (ACL)
  • Monitor abnormal session creation, especially sessions created without completing the full payment process

Package Poisoning 4

Package Poisoning npm 2026-10-08

kiyoramarkets@8.0.16 flagged as malicious

The component was found to belong to a large family of malicious packages impersonating the Baileys WhatsApp library. It uses users' authenticated sessions to automatically subscribe them to attacker-controlled WhatsApp channels without their knowledge.

MD5
b1aae294b0fa058f9c78f3b9cc1c7a56
Package Poisoning npm 2026-10-08

internallib_v788@>= 0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
77f250da5748a91aba5c934aa150c93f
Package Poisoning npm 2026-10-08

tensorlake@>= 0 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
52daf62ca347b137227574b065b1c95d
Package Poisoning npm 2026-10-08

tailwind-animatecss-uniform@2.0.7 flagged as malicious

The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.

MD5
af32ce729f436f12021f86bb5fd31bd2