Decision Insights Threat Desk
CISA advisories, vendor security bulletins, and CVE disclosures, summarized into sourced briefs. Produced under our Standards & Methodology.
CISA advisories, vendor security bulletins, and CVE disclosures, summarized into sourced briefs. Produced under our Standards & Methodology.
Decision Insights Threat Desk • September 8, 2026
ONLYOFFICE ownCloud plugin 9.12 has an SSRF flaw (CVE-2026-84282) enabling admin-driven outbound requests and internal port probing.
Decision Insights Threat Desk • September 8, 2026
Skullcandy Dime 3 firmware 1.0.0.28 can accept unauthenticated Bluetooth Classic pairing, enabling trusted reconnection and audio interruption.
Decision Insights Threat Desk • September 8, 2026
UEFI Shell in SPI flash can be referenced via added boot entries to bypass Secure Boot and run unauthorized pre-boot code.
Decision Insights Threat Desk • September 3, 2026
Casdoor versions 3.115.0 and earlier have an authorization bypass (CVE-2026-15630) that can bypass tenant isolation and enable cross-tenant admin actions.
Decision Insights Threat Desk • September 1, 2026
Hugging Face Transformers CVE-2026-80047 writes remote custom_generate Python files to ~/.cache/huggingface/modules before trust_remote_code checks.
Decision Insights Threat Desk • August 25, 2026
Kaltura html5lib mwEmbedLoader.php has flaws in unsafe deserialization that enable arbitrary file read and remote code execution (CVE-2026-19912/19913).