🔐 Security Pulse · 2026-09-12 16:00 UTC

⚡ TL;DR

Critical: Multiple Concrete CMS and Kimai vulnerabilities allowing XSS and CSRF attacks threaten web portals and applications; patching recommended. Overall threat level: elevated.

🔐 CYBER THREATS

  • 🔴🔴🔴 CVE-2026-81917 and CVE-2026-81918 Concrete CMS versions below 9.5.3 vulnerable to stored XSS via file description/tags and Date Format fields, enabling malicious script execution by users with edit permissions [1] [2].
  • 🔴🔴🔴 CVE-2026-81907 Concrete CMS up to 9.5.2 impacted by CSRF in Express "Clear Entries" feature leading to unauthorized actions [3].
  • 🔴🟡 CVE-2026-49865 and CVE-2026-49992 Kimai time tracking application contains SSRF and authenticated CSRF vulnerabilities that could allow attackers to manipulate invoice previews and team creation [4] [5].
  • 🟡 CVE-2026-49464 NL Portal Backend Libraries leak backend data and may expose Dutch government portals to compromise [6].
  • 🟡 CVE-2026-54165 Dobase suffers from stored DOM-based XSS pre-2026.06.03 versions, risking workspace data manipulation [7].
  • 🟡 CVE-2026-54166 Shelf platform allows authenticated users with asset import permissions to trigger SSRF, exposing internal network attack surface [8].
  • 🔴 Multiple OpenStack Ironic CVEs (CVE-2026-90443 to CVE-2026-90452) involve broken authentication, insecure token handling, and remote path manipulations risking cloud infrastructure compromises [9] [10].
  • 🟢 Mousehole seedbox update service (CVE-2026-50025) HTTP/WebSocket management boundaries have vulnerabilities in versions before 0.4.05 possibly allowing unauthorized control.
  • 🟢 Hoverfly API simulator (CVE-2026-50013 and CVE-2026-50018) has shared resource write and timeout configuration flaws in versions before 1.12.8, raising potential denial or manipulation risks.

🛡️ NATIONAL SECURITY

  • 🟡 Saudi Crown Prince Mohammed bin Salman sought US President Trump’s assistance against Iran-backed Houthis in Yemen, indicating ongoing regional conflict escalation concerns.
  • 🟡 The Pentagon calls for advanced AI to improve missile defense clarity and decision-making amid missile threat proliferation, highlighting ongoing modernization of defense systems.

⚠️ RISK FLAGS

  • ⚠️🔴 Concrete CMS stored XSS and CSRF vectors permit attackers with limited permissions to hijack sessions or escalate privileges on widely used government and organizational portals [1] [2] [3].
  • ⚠️🔴 OpenStack Ironic series of vulnerabilities threaten cloud-hosted data centers and potentially critical infrastructure via authentication bypass and request manipulation [9] [10].
  • ⚠️🟡 Regional tension persists with Saudi Arabia’s active engagement against Houthi forces, risking spillover instability.

🧭 THREAT MOOD

  • 🟡 ELEVATED: Numerous high-severity application vulnerabilities require immediate patching; geopolitical instability in Middle East could increase physical and cyber risks; overall must maintain vigilance given observed exploitation potential.

📎 Sources

  1. CVE-2026-81917 Concrete CMS below 9.5.3 does not apply HTML ou… — @CVEnew
  2. CVE-2026-81918 Concrete CMS below 9.5.3 is vulnerable to Store… — @CVEnew
  3. CVE-2026-81907 Concrete CMS 9.5.2 and below is vulnerable to C… — @CVEnew
  4. CVE-2026-49865 Kimai is an open-source time tracking applicati… — @CVEnew
  5. CVE-2026-49992 Kimai is an open-source time tracking applicati… — @CVEnew
  6. CVE-2026-49464 NL Portal Backend Libraries provide backend com… — @CVEnew
  7. CVE-2026-54165 Dobase is an open-source, self-hosted workspace… — @CVEnew
  8. CVE-2026-54166 Shelf is a platform for tracking physical asset… — @CVEnew
  9. CVE-2026-90461 OpenStack Ironic through 38.0.0 may send a user… — @CVEnew
  10. CVE-2026-90443 A web interface reflects a portion of the reque… — @CVEnew

Educational & informational only — not financial advice. Markets carry risk; do your own research.
Serial 20260912-16-v68 · 2026-09-12 16:00 UTC · pulse.uzylab.com