Before the release of a hardened version, the core module of Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem) contains an improper cryptographic signature verification flaw (CWE-347) caused by incorrect input validation. An attacker can exploit the vulnerability remotely over the network with low attack complexity and no user interaction. This could severely compromise system confidentiality, integrity, and availability, allowing remote code execution or complete control of the target system. All Cisco License On-Prem users who have not updated to a fixed version are affected. Because the attack is network-based and requires neither privileges nor user interaction, an attacker can easily launch it remotely.
Component
Cisco License On-Prem is Cisco's on-premises software license management platform. It manages and validates software licenses within an enterprise and is an important part of Cisco's commitment to proactive security and product quality.
Risks
Complete system control: With a CVSS score of 10.0 and an expanded scope (Scope Changed), the vulnerability allows an attacker to execute arbitrary code on the victim's system and obtain the highest privileges
No-user-interaction attack: The attack takes place over the network (AV:N) and requires no user interaction (UI:N), allowing an attacker to trigger the vulnerability remotely without the target's knowledge
Severe impact: The vulnerability has a high impact on confidentiality, integrity, and availability (C:H/I:H/A:H), potentially causing data disclosure, system tampering, or service disruption
Restrict network access to the management platform, allowing connections only from trusted IP addresses
Monitor abnormal network requests and input data, and deploy an intrusion detection system to identify potential exploitation attempts
CVE-2026-96408
CVSS
10.0 Critical
2026-10-07
Code injection in the Movable Type upgrade script allows arbitrary code execution
The Movable Type upgrade script contains a code injection flaw (CWE-94) caused by improper validation and control of input data. The vulnerability allows an unauthenticated attacker to execute arbitrary Perl scripts or SQL queries on the affected product. Movable Type fails to properly filter user-controlled input during the upgrade process, allowing malicious code to be injected. All Movable Type deployments without mitigation measures are affected. An attacker can trigger the vulnerability remotely without authentication, directly execute system commands or manipulate the database, and cause serious security damage.
Component
Movable Type is a popular open-source blogging and content management system, widely used to build websites and publish content.
Risks
Complete system control: An attacker can exploit the vulnerability to execute arbitrary Perl scripts on the server and take full control of the server environment
Database tampering: An attacker can execute arbitrary SQL queries, leading to data disclosure, modification, or deletion
Unauthenticated remote attack: An attacker can access the upgrade script endpoint to launch an attack without logging in or requiring any user interaction
Immediately restrict network access to the upgrade script, allowing access only from trusted administrator IP addresses
Configure Web application firewall (WAF) rules to block malicious code injection attempts targeting the upgrade script
Contact the vendor promptly for an official patch or upgrade to a secure version
CVE-2026-107102
CVSS
10.0 Critical
2026-10-07
Payment callback parameter validation bypass in an ERP system allows authentication bypass
An ERP system contains an insufficient data authenticity verification flaw (CWE-345) caused by improper validation of payment callback parameters and inadequate authentication controls on API endpoints. An unauthenticated remote attacker can manipulate parameters to make the application create an authenticated session for any user without valid payment verification. Successful exploitation allows the attacker to bypass authentication and gain unauthorized access to other users' accounts on the target system. All users of ERP systems where this flaw remains unfixed are affected. An attacker can launch the attack remotely without any prerequisites.
Component
An ERP (enterprise resource planning) system integrates and manages an enterprise's core business processes, including finance, supply chain, and manufacturing modules.
Risks
Complete authentication bypass: An attacker can bypass the normal login and payment verification processes to gain direct access to the system
Unauthorized account access: An attacker can impersonate any user to access and use other users' sensitive data and functions
Remote attack without user interaction: An attacker only needs to send a crafted API request to trigger the vulnerability and take control remotely, with no user interaction
Strictly verify the origin and integrity of payment callback parameters and ensure that signature verification works correctly
Strengthen authentication controls on API endpoints and enforce strict access-control lists (ACL)
Monitor abnormal session creation, especially sessions created without completing the full payment process
Package Poisoning
4
Package Poisoning
npm2026-10-08
kiyoramarkets@8.0.16
flagged as malicious
The component was found to belong to a large family of malicious packages impersonating the Baileys WhatsApp library. It uses users' authenticated sessions to automatically subscribe them to attacker-controlled WhatsApp channels without their knowledge.
MD5
b1aae294b0fa058f9c78f3b9cc1c7a56
Package Poisoning
npm2026-10-08
internallib_v788@>= 0
flagged as malicious
The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.
MD5
77f250da5748a91aba5c934aa150c93f
Package Poisoning
npm2026-10-08
tensorlake@>= 0
flagged as malicious
The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.
MD5
52daf62ca347b137227574b065b1c95d
Package Poisoning
npm2026-10-08
tailwind-animatecss-uniform@2.0.7
flagged as malicious
The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.