New MCP server — Bring vulnerability intelligence into your AI
Back to feed

CVE-2026-100903

NVDCIRCL

Published Sep 28, 2026 · today

A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."

Weaknesses

CWE-306CWE-287

CVSS scores

  • v4.05.5CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.15.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.05.0AV:N/AC:L/Au:N/C:P/I:N/A:N

References

Potentially impacted assets

See if this affects your attack surface

Latest trending attack

Criticaltoday

Citrix NetScaler ADC / Gateway - Unauthenticated Authentication Bypass in AAA/VPN & Memory Corruption Remote Code Execution (RCE) or Denial of Service (DOS) & Unauthenticated Remote Code Execution (RCE) via Input Validation

Citrix NetScaler ADC and Gateway are internet-exposed edge devices providing SSL VPN, remote access, and application proxy services for enterprises. They serve as critical entry points between external users and internal network resources. CVE-2026-19490 Critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Boasting a CVSS score of 9.3, this flaw resides in the alternative path handling of authentication mechanisms. It allows an unauthenticated remote attacker to completely circumvent authentication controls and gain unauthorized access to protected internal services without requiring legitimate user interaction or credentials. CVE-2026-88771 Extremely high-risk remote code execution (RCE) zero-day vulnerability found in Citrix NetScaler ADC and NetScaler Gateway. Rated with a critical CVSS score of 9.5, it stems from an improper input validation error (CWE-20). Because it affects all default deployment configurations without any feature prerequisites, a network-based unauthenticated attacker can exploit it to execute arbitrary commands directly on the appliance. CVE-2026-88772 Critical zero-day vulnerability affecting Citrix NetScaler ADC and Gateway instances that have Datagram Transport Layer Security (DTLS) enabled. It is caused by an improper restriction of operations within the bounds of a memory buffer, resulting in a memory overflow. With a CVSS score of 9.5, this flaw allows unauthenticated remote threat actors to trigger a total denial-of-service (DoS) condition or achieve remote code execution.

Take 15 minutes to discover our platform with our experts

PatrowlIntel platform screenshot