New MCP server — Bring vulnerability intelligence into your AI
Back to feed

CVE-2026-100909

NVDCIRCL

Published Sep 28, 2026 · today

A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded.

Weaknesses

CWE-918

CVSS scores

  • v4.05.5CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.17.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • v2.07.5AV:N/AC:L/Au:N/C:P/I:P/A:P

References

Potentially impacted assets

See if this affects your attack surface

Latest trending attack

Criticaltoday

Citrix NetScaler ADC / Gateway - Unauthenticated Authentication Bypass in AAA/VPN & Memory Corruption Remote Code Execution (RCE) or Denial of Service (DOS) & Unauthenticated Remote Code Execution (RCE) via Input Validation

Citrix NetScaler ADC and Gateway are internet-exposed edge devices providing SSL VPN, remote access, and application proxy services for enterprises. They serve as critical entry points between external users and internal network resources. CVE-2026-19490 Critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Boasting a CVSS score of 9.3, this flaw resides in the alternative path handling of authentication mechanisms. It allows an unauthenticated remote attacker to completely circumvent authentication controls and gain unauthorized access to protected internal services without requiring legitimate user interaction or credentials. CVE-2026-88771 Extremely high-risk remote code execution (RCE) zero-day vulnerability found in Citrix NetScaler ADC and NetScaler Gateway. Rated with a critical CVSS score of 9.5, it stems from an improper input validation error (CWE-20). Because it affects all default deployment configurations without any feature prerequisites, a network-based unauthenticated attacker can exploit it to execute arbitrary commands directly on the appliance. CVE-2026-88772 Critical zero-day vulnerability affecting Citrix NetScaler ADC and Gateway instances that have Datagram Transport Layer Security (DTLS) enabled. It is caused by an improper restriction of operations within the bounds of a memory buffer, resulting in a memory overflow. With a CVSS score of 9.5, this flaw allows unauthenticated remote threat actors to trigger a total denial-of-service (DoS) condition or achieve remote code execution.

Take 15 minutes to discover our platform with our experts

PatrowlIntel platform screenshot