🛡️ Cyber Times — CISO Intelligence Update
Sunday, 13 September 2026 · Coverage: 12 Sep 2026 08:00 IST → 13 Sep 2026 08:00 IST
The high-confidence sweep produced 30 publishable records. This edition presents 7 source-linked updates across 1 security domains; 7 are marked for priority review.
🛡️ Vulnerabilities Worth Attention
CVE-2026-85706 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain…
CRITICAL — NVD CVSS 10.0 (critical). GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 12 Sep 2026 23:50 IST Sources: NVD · tech-insider.org
CVE-2026-82845 — The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing…
CRITICAL — NVD CVSS 9.9 (critical). The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 12 Sep 2026 11:46 IST Sources: NVD
CVE-2026-87719 — GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain…
CRITICAL — NVD CVSS 9.9 (critical). GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 12 Sep 2026 08:46 IST Sources: NVD
CVE-2026-78159 — The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function
CRITICAL — NVD CVSS 9.8 (critical). The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget ‘classes’ map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 12 Sep 2026 13:46 IST Sources: NVD
CVE-2026-78006 — The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance…
CRITICAL — NVD CVSS 9.8 (critical). The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 12 Sep 2026 13:46 IST Sources: NVD
CVE-2026-85681 — The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users…
CRITICAL — NVD CVSS 9.8 (critical). The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site’s options. On a single site installation this leads to a full takeover, as registration can be…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 12 Sep 2026 11:46 IST Sources: NVD
CVE-2026-84171 — The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible…
CRITICAL — NVD CVSS 9.8 (critical). The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 12 Sep 2026 11:46 IST Sources: NVD
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 554 records inspected · 91 passed collection filters · 30 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.