FOCUS FRIDAY: TPRM Insights on Critical Vulnerabilities in Citrix NetScaler, SonicWall SMA1000, Exchange Server, Cisco NX-OS, Atlassian, Langflow, and Elastic
Introduction
This week's Focus Friday covers seven FocusTags spanning perimeter security appliances, enterprise messaging infrastructure, data center network operating systems, cross-product collaboration platforms, AI development tools, and data analytics stacks. Two tags are direct continuations of active advisories: Citrix NetScaler returns with two additional CVEs requiring a newer fix build than last week's advisory — vendors who patched to 14.1-73.37 are still partially exposed and must patch again to 14.1-73.41. SonicWall SMA1000 expands its known pre-authentication SSRF chain with four new CVEs, including a Zip Slip and stored XSS, on top of an already CISA KEV-listed exploitation cluster. Langflow closes the week with its largest single disclosure batch: 21 CVEs from IBM covering Langflow OSS 1.0.0 through 1.12.2 — including multiple unauthenticated remote code execution paths — marking this platform's fifth advisory cycle within a single reporting period.
The highest-urgency situations this week center on active advisory expansion and systemic platform collapse. The Citrix NetScaler double-patch requirement is the most operationally dangerous: organizations that responded to last week's advisory may believe they are fully remediated when they are not. Cisco NX-OS carries an unauthenticated remote code execution vulnerability via its NX-API feature — a critical attack surface on the network switching layer that standard TPRM processes rarely surface. Atlassian's single CVE simultaneously impacts every product in its Data Center portfolio — Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye — making it a disproportionately broad event for a single CVE. Langflow's 21-CVE batch, arriving after four prior critical advisory cycles, signals a platform that has fundamentally failed as a secure AI development environment.

Filtered view of vendors with the Citrix PitScaler 2 FocusTag® on the Black Kite platform.
Citrix PitScaler 2 (CVE-2025-6543, CVE-2026-88771, CVE-2026-88772, CVE-2026-88779, CVE-2026-88778)
What is this vulnerability?
Citrix NetScaler ADC and NetScaler Gateway are widely deployed enterprise perimeter appliances providing application delivery, SSL/TLS offloading, and secure remote access. The October 2026 advisory expands the September 2026 (Latest) cluster with two additional CVEs that require an upgraded fix build — 14.1-73.41 or 13.1-64.28 — beyond the 14.1-73.37 build required by last week's advisory. Vendors who patched to 14.1-73.37 remain exposed to CVE-2025-6543 and CVE-2026-88779 and must patch again.
CVE-2025-6543 is a memory overflow vulnerability that manifests specifically when NetScaler is configured as a Gateway — covering VPN virtual server, ICA Proxy, CVPN, and RDP Proxy configurations. Exploitation leads to unintended control flow or denial of service. CVE-2026-88779 is an additional vulnerability in NetScaler ADC and Gateway that is only remediated by the newer 14.1-73.41 or 13.1-64.28 builds. The three remaining CVEs — CVE-2026-88771 (unauthenticated RCE via improper input validation), CVE-2026-88772 (memory overflow via DTLS), and CVE-2026-88778 (predictable value generation) — were first disclosed in the September 2026 advisory and are included in this consolidated update. The full five-CVE set is remediated only by 14.1-73.41 or 13.1-64.28.
CVE-2026-88771 and CVE-2026-88772 were part of the Sep2026 (Latest) advisory. CVE-2025-6543 and CVE-2026-88779 require the newer 14.1-73.41 / 13.1-64.28 build — patching to 14.1-73.37 alone does not fully remediate this advisory.
CVE | CVSS | Vulnerability Name | Short Description |
|---|---|---|---|
CVE-2025-6543 | 9.8 | Memory Overflow — Gateway Mode | Memory overflow in Gateway config (VPN, ICA Proxy, CVPN, RDP Proxy) → unintended control flow or DoS |
CVE-2026-88771 | 9.8 | Unauthenticated RCE — Improper Input Validation | Improper input validation → unauthenticated RCE on all default ADC/Gateway deployments |
CVE-2026-88772 | 8.1 | Memory Overflow via DTLS | DTLS-triggered memory overflow → unauthenticated RCE |
CVE-2026-88779 | 7.5 | Unspecified — Newer Build Required (14.1-73.41) | Vulnerability in ADC/Gateway fixed only in 14.1-73.41 / 13.1-64.28; prior advisory builds insufficient |
CVE-2026-88778 | 7.5 | Predictable Value from Previous State | Predictable value generation in ADC/Gateway → information disclosure risk |
Why should TPRM professionals care?
The double-patch scenario is the defining TPRM challenge of this advisory. Vendors who responded to last week's Citrix NetScaler Sep2026 (Latest) FocusTag® may have communicated confirmed remediation to their TPRM teams — but if they patched to 14.1-73.37 rather than 14.1-73.41, they remain vulnerable to CVE-2025-6543 and CVE-2026-88779. A vendor's accurate answer to last week's patch question is not a valid answer to this week's. CVE-2025-6543 specifically targets Gateway configurations — the most common enterprise deployment pattern for NetScaler — meaning virtually all organizations using NetScaler for remote access, VPN, or application delivery are in scope. TPRM teams must re-engage all vendors identified in last week's NetScaler FocusTag® and verify the build version is 14.1-73.41 or 13.1-64.28.
What questions should TPRM professionals ask vendors?
- Have you upgraded all NetScaler ADC and Gateway deployments to version 14.1-73.41 or 13.1-64.28 — specifically confirming these build numbers rather than the 14.1-73.37 build required by last week's advisory?
- Is your NetScaler deployment configured in Gateway mode — including as a VPN virtual server, ICA Proxy, CVPN, or RDP Proxy — which is specifically in scope for CVE-2025-6543's memory overflow?
- If you previously confirmed remediation for the September 2026 NetScaler advisory, have you re-verified your build version against the October 2026 requirements, given that 14.1-73.37 does not remediate this updated advisory?
- Have you conducted a compromise assessment for the period between deployment of the September patch and deployment of the October patch, during which CVE-2025-6543 remained exploitable?
- What is your patch deployment SLA for Citrix emergency advisories that update previously patched CVE clusters, and was a re-patch process triggered automatically when the October advisory was published?
Remediation recommendations
- Upgrade all NetScaler ADC and Gateway deployments to version 14.1-73.41 or 13.1-64.28 immediately; patching to 14.1-73.37 from last week's advisory is insufficient for CVE-2025-6543 and CVE-2026-88779.
- Re-engage all vendors confirmed as patched for the September 2026 NetScaler advisory to verify their build version meets the October 2026 requirement of 14.1-73.41 or 13.1-64.28.
- Prioritize NetScaler deployments in Gateway mode — VPN, ICA Proxy, CVPN, RDP Proxy — as these are specifically exposed to CVE-2025-6543's memory overflow and represent the most common enterprise remote access configuration.

Black Kite's Citrix PitScaler 2 FocusTag® details critical insights on the event for TPRM professionals.
SonicWall SMA1000 - Oct2026 (CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, CVE-2026-83548, CVE-2026-83549)
What is this vulnerability?
SonicWall SMA1000 is an enterprise secure access gateway providing SSL VPN, application access control, and zero-trust network access for remote users. The October 2026 advisory consolidates the existing CISA KEV-listed August 2026 pair with four new CVEs, expanding the known attack surface on the SMA1000 Appliance Management Console (AMC) and Work Place interface. CVE-2026-102255 is a new pre-authentication SSRF vulnerability in the Work Place interface — operating through the same unintended alternate access path mechanism as the August 2026 CISA KEV CVE-2026-83548. CVE-2026-102256 is a post-authentication OS command injection vulnerability in the AMC that under specific conditions allows code execution at the OS level. CVE-2026-102257 is a Zip Slip vulnerability in the AMC: a specially crafted archive submitted through the management interface allows an attacker to extract files outside the intended destination directory, enabling path traversal to sensitive locations. CVE-2026-102258 is a post-authentication stored XSS vulnerability in the AMC that under specific conditions enables further exploitation.
The August 2026 pair — CVE-2026-83548 (pre-authentication SSRF, CISA KEV) and CVE-2026-83549 (post-authentication OS command injection, CISA KEV) — are included in this advisory as the foundation of the exploitation chain. Vendors who deployed fixes for the August 2026 advisory must verify whether the October 2026 advisory requires an additional patch action to remediate the four new CVEs.
CVE | CVSS | Vulnerability Name | Short Description |
|---|---|---|---|
CVE-2026-102255 | 10.0 | Pre-Auth SSRF — Work Place Interface (New) | Unauthenticated SSRF via alternate access path in Work Place → internal system access |
CVE-2026-83548 | 10.0 | Pre-Auth SSRF — Work Place Interface (Aug2026, CISA KEV) | Known CISA KEV SSRF — foundation of the Aug2026 exploitation chain |
CVE-2026-102256 | 7.8 | Post-Auth OS Command Injection — AMC (New) | Command injection in AMC under specific conditions → OS-level code execution |
CVE-2026-83549 | 7.8 | Post-Auth OS Command Injection — AMC (Aug2026, CISA KEV) | Known CISA KEV command injection in AMC (previously disclosed) |
CVE-2026-102257 | 7.2 | Zip Slip / Path Traversal — AMC (New) | Crafted archive in AMC allows file extraction outside intended directory |
CVE-2026-102258 | 6.1 | Post-Auth Stored XSS — AMC (New) | Stored XSS in AMC under specific conditions → further exploitation vector |
Why should TPRM professionals care?
SonicWall SMA1000 gateways serve as the remote access entry point for enterprise environments — a position that makes pre-authentication vulnerabilities on this platform immediately impactful. The October 2026 advisory does not replace the August 2026 CISA KEV cluster; it adds to it. Vendors who received and responded to the August 2026 FocusTag® outreach must be re-engaged to confirm that the October advisory's four new CVEs are also remediated. The new pre-authentication SSRF (CVE-2026-102255) operates through the same access path mechanism as the CISA KEV CVE — suggesting this attack surface has not been fully closed in prior patches. The Zip Slip vulnerability introduces a file-write primitive through the management interface, creating a distinct exploitation path independent of the SSRF chain.
What questions should TPRM professionals ask vendors?
- Have you applied the October 2026 SonicWall SMA1000 patch that remediates CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, and CVE-2026-102258, in addition to the August 2026 fixes for CVE-2026-83548 and CVE-2026-83549?
- Is your SMA1000 Work Place interface accessible from the internet, and if so, have you restricted access to trusted IP ranges as a defense-in-depth measure against the pre-authentication SSRF vulnerabilities?
- Have you restricted AMC access to internal management networks only, given that CVE-2026-102256, CVE-2026-102257, and CVE-2026-102258 all require AMC access to exploit?
- Have you reviewed SMA1000 audit logs for exploitation indicators of the August 2026 CISA KEV pair — including anomalous SSRF requests through Work Place and unexpected OS-level activity from AMC processes — covering the period since the August advisory?
- What is your patch deployment process for SonicWall advisory updates that expand previously patched CVE clusters, and does your patch tracking system trigger re-evaluation when a new advisory references CVEs already acknowledged as remediated?
Remediation recommendations
- Apply the October 2026 SonicWall SMA1000 patch to remediate all six CVEs in this advisory; the August 2026 patch alone does not cover CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, or CVE-2026-102258.
- Restrict SMA1000 Work Place and AMC interfaces to trusted IP ranges; the pre-authentication SSRF attack surface is eliminated when Work Place is not accessible from untrusted networks.
- Conduct a compromise assessment for any SMA1000 deployment that had internet-facing Work Place access during the August-to-October unpatched window, given the CISA KEV status of CVE-2026-83548.

Black Kite's SonicWall SMA1000 - Oct2026 FocusTag® details critical insights on the event for TPRM professionals.
Exchange Server - Oct2026 (CVE-2026-96940)
What is this vulnerability?
Microsoft Exchange Server is the foundational enterprise email and calendar platform deployed across organizations globally. CVE-2026-96940 is a privilege escalation vulnerability caused by weak authorization in Exchange Server's network-accessible components. An authenticated attacker — any user with a valid Exchange account — can exploit the weak authorization logic to elevate their privileges over the network without requiring physical access or additional preconditions beyond a valid credential. The vulnerability affects Exchange Server deployments where the management or internal communication interfaces are reachable over the network, which is the standard configuration for virtually all on-premises Exchange installations.
Unlike remote code execution vulnerabilities that require no authentication, CVE-2026-96940's authenticated prerequisite means the initial barrier is valid credentials — which can be obtained through phishing, credential stuffing, or prior breaches. Once inside, the privilege escalation path allows an attacker to move from a standard user's access level to elevated permissions within the Exchange infrastructure. No public proof-of-concept or CISA KEV listing has been reported as of this advisory date. Remediation is through Microsoft's October 2026 patch release.
Why should TPRM professionals care?
Exchange Server is a high-value target for threat actors because it provides centralized access to email — one of the most sensitive data categories in any organization. Privilege escalation within Exchange can enable an attacker to access mailboxes beyond their own account, create mail forwarding rules for data exfiltration, modify transport rules, or use elevated Exchange permissions as a stepping stone to broader Active Directory compromise. The authenticated-only prerequisite lowers the urgency compared to unauthenticated exploits, but the combination of Exchange's sensitivity and the prevalence of credential-based attacks makes this a meaningful TPRM event. TPRM teams should verify that vendors running on-premises Exchange have applied the October 2026 patch and have reviewed privilege assignments for anomalous escalation indicators.
What questions should TPRM professionals ask vendors?
- Have you applied Microsoft's October 2026 Exchange Server patch that remediates CVE-2026-96940, and has this been confirmed across all on-premises Exchange Server deployments in your environment?
- Have you reviewed Exchange Server audit logs for anomalous privilege escalation activity — including unexpected changes to mailbox permissions, admin role assignments, or transport rule modifications — that could indicate prior exploitation of CVE-2026-96940?
- Are Exchange Server management interfaces restricted to internal trusted IP ranges, limiting the network exposure required to exploit CVE-2026-96940?
- Have you implemented and reviewed Exchange Server role-based access control (RBAC) assignments to ensure that standard user accounts do not hold elevated Exchange permissions that would amplify the impact of a privilege escalation?
- What is your patch deployment SLA for Microsoft Exchange Server security releases, and was the October 2026 patch included in your standard patch cycle or deployed on an accelerated basis given the Exchange target value?
Remediation recommendations
- Apply Microsoft's October 2026 Exchange Server security update remediating CVE-2026-96940 across all on-premises Exchange deployments; Microsoft Exchange Online is not affected.
- Audit Exchange RBAC role assignments to identify any accounts that have received elevated permissions inconsistent with their job function — which could indicate prior exploitation of the privilege escalation path.
- Review Exchange transport rules and mailbox forwarding rules for unauthorized additions that may have been created using elevated privileges obtained through CVE-2026-96940 exploitation.

Black Kite's Exchange Server - Oct2026 FocusTag® details critical insights on the event for TPRM professionals.
Cisco NX-OS - Oct2026 (CVE-2026-76471 and 6 additional CVEs)
What is this vulnerability?
Cisco NX-OS is the network operating system running on Cisco's Nexus data center switching platform — the fabric infrastructure of enterprise data centers globally. The October 2026 advisory covers seven CVEs across NX-OS. CVE-2026-76471 is the most critical: a vulnerability in the NX-API feature of Cisco NX-OS Software that allows an unauthenticated remote attacker to execute arbitrary code with root privileges or cause a denial of service condition. NX-API is a REST/JSON API interface used for programmatic management of Nexus switches; when enabled, it exposes this unauthenticated attack surface on the management network. Six additional CVEs — CVE-2026-76455 (critical), CVE-2026-76459, CVE-2026-76453 (high), and CVE-2026-76456, CVE-2026-76457, CVE-2026-76458 (high) — were identified through Cisco's internal proactive security review of NX-OS and cover additional vulnerability classes across the operating system.
NX-API is disabled by default on NX-OS deployments; CVE-2026-76471 is exploitable only when this feature is enabled. However, NX-API is widely adopted in modern data center automation workflows, SDN integrations, and infrastructure-as-code deployments — making it a realistic exposure for organizations with programmatically managed Nexus infrastructure. The management network position of NX-OS devices means exploitation of the RCE provides root-level access to the switch operating system, from which an attacker can inspect, modify, or disrupt all traffic transiting the data center fabric.
CVE | CVSS | Vulnerability Name | Short Description |
|---|---|---|---|
CVE-2026-76471 | 9.8 | Unauthenticated RCE / DoS — NX-API | NX-API feature allows unauthenticated remote attacker to execute code as root or cause DoS |
CVE-2026-76455 | 9.8 | Proactively Identified — Critical | Critical-severity flaw identified by Cisco's internal NX-OS security review |
CVE-2026-76459 | 8.8 | Proactively Identified — High | High-severity flaw from Cisco's internal NX-OS security review |
CVE-2026-76453 | 8.8 | Proactively Identified — High | High-severity flaw from Cisco's internal NX-OS security review |
CVE-2026-76456 | 8.6 | Proactively Identified — High | High-severity flaw from Cisco's internal NX-OS security review |
CVE-2026-76457 | 8.6 | Proactively Identified — High | High-severity flaw from Cisco's internal NX-OS security review |
CVE-2026-76458 | 8.6 | Proactively Identified — High | High-severity flaw from Cisco's internal NX-OS security review |
Why should TPRM professionals care?
Network operating system vulnerabilities are a persistent blind spot in TPRM — because NX-OS runs on switching infrastructure rather than application servers, it rarely appears in standard asset inventories or vulnerability management workflows. Yet Nexus switches form the data center fabric of enterprise environments, carrying all east-west and north-south traffic between application tiers, storage systems, and external networks. Root-level RCE on a Nexus switch gives an attacker the ability to inspect all traffic in transit, redirect flows, disrupt data center connectivity, or establish persistent footholds in the network fabric that are invisible to application-layer monitoring. For TPRM professionals assessing vendors with data center infrastructure, NX-OS version currency is a critical but often unmeasured indicator of network security posture.
What questions should TPRM professionals ask vendors?
- Have you applied Cisco's October 2026 NX-OS security advisory patch across all Nexus switch deployments, and do you have a complete inventory of NX-OS versions running in your environment?
- Is the NX-API feature enabled on any Nexus switches in your environment, and if so, are these switches accessible only from trusted internal management networks or also from less-restricted network segments?
- Have you reviewed NX-OS audit logs for anomalous API calls, unexpected configuration changes, or unusual process activity that could indicate exploitation of CVE-2026-76471?
- For Nexus switches with NX-API enabled that cannot be immediately patched, have you implemented mitigations such as restricting NX-API access to trusted management hosts via access-list or disabling NX-API until patching is complete?
- Does your patch management process cover network operating systems such as NX-OS, and is there a defined SLA for Cisco security advisories affecting data center switching infrastructure?
Remediation recommendations
- Apply Cisco's October 2026 NX-OS security advisory patch across all Nexus switch deployments running affected NX-OS versions per Cisco's advisory.
- Disable NX-API on any Nexus switch where it is not operationally required; if NX-API is required, restrict access to trusted management host IP addresses using NX-OS access-list controls on the management interface.
- Extend vulnerability management and asset inventory processes to explicitly include network operating systems — NX-OS, IOS, IOS-XE, and equivalents — to ensure advisory coverage does not depend on application-layer scanning.

Black Kite's Cisco NX-OS - Oct2026 FocusTag® details critical insights on the event for TPRM professionals.
Atlassian - Oct2026 (CVE-2026-21589)
What is this vulnerability?
Atlassian's Data Center suite is one of the most widely deployed enterprise collaboration and development infrastructure platforms globally, encompassing source code management, project tracking, knowledge management, CI/CD, identity management, and code review. CVE-2026-21589 is a critical vulnerability that simultaneously affects every product in Atlassian's Data Center portfolio: Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. The cross-product scope of a single CVE is highly unusual and reflects a shared component or framework vulnerability that propagates across the entire Atlassian platform.
The CVSS score for CVE-2026-21589 had not been published to NVD at the time of this advisory. Given the cross-product scope and Atlassian's classification of it as critical, organizations should treat this as a high-urgency event regardless of the pending numerical score. Remediation requires patching each affected product independently to the fixed versions specified in Atlassian's advisory, as no single patch addresses all eight products simultaneously.
CVE | CVSS | Vulnerability Name | Short Description |
|---|---|---|---|
CVE-2026-21589 | — | Cross-Product Critical — Full Atlassian Data Center Suite | Critical vulnerability simultaneously affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center |
Why should TPRM professionals care?
A single CVE affecting all eight Atlassian Data Center products creates a uniquely broad TPRM impact scenario. Atlassian's Data Center suite serves as the operational backbone of software development organizations: Bitbucket holds source code, Confluence holds internal documentation and architectural knowledge, Jira tracks every project and sprint, Jira Service Management handles IT and customer service queues, Bamboo runs CI/CD pipelines, and Crowd manages identity across all of these. A vulnerability that spans all of them simultaneously is not a single-system event — it is a platform-wide exposure. For TPRM professionals assessing software vendors, technology companies, or any organization with a mature software development function, CVE-2026-21589 is a high-priority event requiring rapid vendor engagement and independent patch confirmation across each product individually.
What questions should TPRM professionals ask vendors?
- Have you applied the Atlassian October 2026 security advisory patch for each affected Data Center product independently — Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye — and can you confirm the patched version for each?
- Which Atlassian Data Center products are deployed in your environment, and have you assessed the scope of CVE-2026-21589 across all of them, including any products that may not be in your primary IT inventory?
- Have you reviewed audit logs across all affected Atlassian products for anomalous access patterns, unexpected privilege changes, or suspicious API activity that could indicate exploitation?
- Are any Atlassian Data Center products — particularly Bitbucket, Confluence, or Jira — accessible from the internet, and if so, have access controls been reviewed to minimize exposure while the patch is being deployed?
- Does your patch management process track Atlassian Data Center advisory releases separately from standard OS and application patching, and what is your SLA for critical Atlassian advisories?
Remediation recommendations
- Apply Atlassian's October 2026 advisory patches for each affected Data Center product independently; there is no single consolidated patch — each product requires its own update to the fixed version specified in Atlassian's advisory.
- Prioritize internet-accessible Atlassian products — particularly Bitbucket, Confluence, and Jira — for patch deployment, as their external exposure amplifies the risk profile of CVE-2026-21589.
- Maintain a complete inventory of Atlassian Data Center products and versions across all business units and subsidiary environments, as the cross-product scope of this advisory requires comprehensive visibility to confirm full remediation.

Black Kite's Atlassian - Oct2026 FocusTag® details critical insights on the event for TPRM professionals.
Langflow - Oct2026 (CVE-2026-104334, CVE-2026-93674, and 19 additional CVEs)
What is this vulnerability?
Langflow is an open-source low-code platform for building and deploying visual AI application workflows. IBM's October 2026 security advisory for Langflow OSS versions 1.0.0 through 1.12.2 discloses 21 CVEs — the single largest disclosure batch for this platform to date and the fifth advisory cycle within this reporting period. The advisory spans the full spectrum from unauthenticated remote code execution to authenticated privilege escalation and information disclosure, reflecting a systematic security review that found vulnerabilities throughout Langflow's core execution and authorization architecture. Fixed version: Langflow OSS 1.12.3.
The two most critical CVEs are unauthenticated: CVE-2026-104334 (improper control of code generation) and CVE-2026-93674 (improper neutralization of OS command special elements), both enabling remote code execution without authentication. CVE-2026-97655 and CVE-2026-93675 are additional unauthenticated RCE paths via an incomplete blocklist in the code security scanner and a dependency confusion attack respectively. The remaining 17 CVEs require authentication — but with authentication representing the minimum access level for any Langflow user — and cover authenticated RCE through sandbox escape, improper input validation, code injection, OS command injection, and improper access control, as well as information disclosure through path traversal, credential exposure, and authorization bypass.
CVE | CVSS | Vulnerability Name | Short Description |
|---|---|---|---|
CVE-2026-104334 | 9.8 | Unauthenticated RCE — Code Generation Control | Remote attacker executes arbitrary code via improper control of code generation |
CVE-2026-93674 | 9.8 | Unauthenticated RCE — OS Command Injection | OS command special elements unfiltered → unauthenticated RCE |
CVE-2026-97655 | 8.8 | Unauthenticated RCE — Incomplete Blocklist | Code security scanner's incomplete blocklist bypassed → unauthenticated RCE |
CVE-2026-93675 | 8.8 | Unauthenticated RCE — Dependency Confusion | Dependency confusion attack → unauthenticated arbitrary code execution |
CVE-2026-97676 | 8.8 | Authenticated RCE — Sandbox Escape (Code Injection) | Authenticated attacker escapes sandbox → arbitrary code execution |
CVE-2026-97678 | 8.8 | Authenticated RCE — Improper Input Validation | Input validation failure → authenticated RCE |
CVE-2026-97673 | 8.8 | Authenticated RCE — Improper Input Validation | Input validation failure → authenticated RCE |
CVE-2026-97679 | 8.8 | Authenticated RCE — OS Command Injection | OS command injection ('Code Injection') → authenticated RCE |
CVE-2026-88962 | 8.8 | Authenticated RCE — Code Generation Control | Improper code generation control → authenticated RCE |
CVE-2026-104335 | 8.8 | Authenticated RCE — Improper Access Control | Access control failure → authenticated RCE |
CVE-2026-93449 | 8.5 | Authenticated RCE — Code Generation Control | Code generation control failure → authenticated RCE |
CVE-2026-97680 | 8.3 | Authenticated Info Disclosure / Injection — Cache | Vertex result cache access control failure → data exfiltration or malicious injection |
CVE-2026-97674 | 8.1 | Authenticated OS Command Execution | Code injection enabling OS command execution by authenticated attacker |
CVE-2026-103360 | 8.1 | Authenticated Path Traversal — Info Disclosure | Path not restricted to intended directory → authenticated information disclosure |
CVE-2026-93445 | 8.1 | Authenticated RCE — Code Generation Control | Code generation control failure → authenticated RCE |
CVE-2026-101331 | 7.7 | Authenticated Credential Disclosure | Insufficiently protected credentials → credential exposure to authenticated attacker |
CVE-2026-93677 | 7.7 | Authenticated Info Disclosure | Sensitive information exposed to unauthorized actor via authenticated access |
CVE-2026-93678 | 7.6 | Authenticated Info Disclosure — Authorization Bypass | Authorization failure → authenticated information disclosure |
CVE-2026-93447 | 7.5 | Authenticated RCE — Redis Deserialization | Server secret + Redis write access → malicious cache value → deserialization RCE |
CVE-2026-93443 | 7.5 | Authenticated RCE — Code Injection | Code injection via unfiltered special elements → authenticated RCE |
CVE-2026-97677 | — | Pending NVD Score | NVD scoring not yet published |
Why should TPRM professionals care?
Twenty-one CVEs in a single advisory, arriving as the fifth IBM disclosure batch for this platform within one reporting period, is not a patch management challenge — it is a platform architecture verdict. Langflow's core attack surface is its design: a visual programming environment that executes arbitrary code as part of its normal function. Each advisory cycle reveals new incomplete defenses in the same execution and validation subsystem. For TPRM professionals, the accumulating volume of critical and high-severity Langflow disclosures over this reporting period raises a question that goes beyond patch verification: is Langflow an appropriate platform for production AI deployment in environments that handle sensitive data? Vendors who have now been exposed to five advisory cycles of Langflow vulnerabilities and continue to operate it without architectural remediation present a systemic, not transient, risk.
What questions should TPRM professionals ask vendors?
- Have you upgraded Langflow OSS to version 1.12.3 to remediate all 21 CVEs in the October 2026 IBM advisory, and have the four prior Langflow advisory batches also been addressed through previous updates?
- Is Langflow accessible from the internet or from networks accessible to untrusted users, given that four of this advisory's CVEs are unauthenticated — requiring no credentials at all to achieve remote code execution?
- What data sources, cloud credentials, internal databases, and network segments does your Langflow deployment have access to, and has the blast radius of a Langflow compromise been assessed and documented?
- Given that this is the fifth advisory cycle for Langflow within this reporting period, has a formal architectural review been conducted on whether Langflow is an appropriate platform for your production environment given its demonstrated security track record?
- If Langflow continues to be used, have network segmentation controls been implemented to isolate it from production data systems, cloud IAM roles, and internal databases that would amplify the impact of any future exploitation?
Remediation recommendations
- Upgrade Langflow OSS to version 1.12.3 immediately; this is the complete fix for all 21 CVEs in the October 2026 advisory and the fifth required upgrade within this reporting period.
- Isolate Langflow from internet access and from sensitive internal network segments; with four unauthenticated RCE paths in this advisory alone, no internet-facing Langflow deployment can be considered secure at any patch level between advisories.
- Conduct a formal architectural review of Langflow's role in production environments: assess whether its data access, cloud IAM permissions, and network position are appropriate given five advisory cycles of critical disclosures, and document the risk acceptance decision.
- Enforce IMDSv2 on AWS instances running Langflow, restrict Langflow's access to cloud metadata endpoints at the network level, and implement Redis authentication to mitigate CVE-2026-93447's deserialization attack path.

Black Kite's Langflow - Oct2026 FocusTag® details critical insights on the event for TPRM professionals.
Elastic - Oct2026 (CVE-2026-102406, CVE-2026-103007, CVE-2026-103009, and 5 additional CVEs)
What is this vulnerability?
Elastic's platform — comprising Elasticsearch for distributed search and analytics and Kibana for visualization and management — is one of the most widely deployed data infrastructure stacks in enterprise environments, underpinning security operations (SIEM), observability, application search, and business analytics. The October 2026 advisory covers eight CVEs spanning authorization bypass, privilege escalation, information disclosure, and denial of service across both Elasticsearch and Kibana.
The most critical vulnerability is CVE-2026-102406 — an Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana that leads to cross-tenant data interception. In multi-tenant Kibana deployments, where different users or teams share the same Kibana instance with data isolation enforced by tenant boundaries, this vulnerability allows an attacker to access data belonging to other tenants by manipulating a user-controlled key in their requests. CVE-2026-103007 is an Incorrect Authorization flaw in Elasticsearch enabling privilege escalation through a delegated administrative privilege whose scope is not fully enforced — allowing actions beyond the intended delegation boundary. CVE-2026-103009 is another authorization bypass in Elasticsearch enabling information disclosure via cross-cluster search requests that reference unauthorized shards. Three denial-of-service vulnerabilities — CVE-2026-103008 and CVE-2026-103006 (uncontrolled recursion via aggregation and nested data structures) and CVE-2026-102411 (resource exhaustion via user-supplied size parameters) — allow disruption of Elasticsearch availability. CVE-2026-103005 allows a user with connector management privileges to trigger excessive memory allocation. CVE-2026-102412 is an Incorrect Authorization flaw in Kibana enabling sensitive information disclosure to users with limited access.
CVE | CVSS | Vulnerability Name | Short Description |
|---|---|---|---|
CVE-2026-102406 | 8.8 | Auth Bypass — Kibana Cross-Tenant Data Access | User-controlled key manipulation in Kibana → access to other tenants' data |
CVE-2026-103007 | 7.2 | Privilege Escalation — Elasticsearch Delegated Admin | Delegated admin privilege scope not enforced → privilege escalation beyond intended boundary |
CVE-2026-103009 | 7.1 | Auth Bypass — Elasticsearch Cross-Cluster Search | Crafted cross-cluster search request accesses unauthorized shards → information disclosure |
CVE-2026-103008 | 6.5 | DoS — Elasticsearch Uncontrolled Recursion (Deep Nesting) | Deeply nested data structure request triggers uncontrolled recursion → DoS |
CVE-2026-103006 | 6.5 | DoS — Elasticsearch Aggregation Recursion | Search API aggregation request triggers uncontrolled recursion → DoS |
CVE-2026-103005 | 6.5 | DoS — Elasticsearch Excessive Memory Allocation | Connector management user triggers excessive memory allocation → DoS |
CVE-2026-102412 | 6.5 | Info Disclosure — Kibana Authorization Bypass | Limited Kibana user accesses functionality outside their ACL → sensitive data exposure |
CVE-2026-102411 | 6.5 | DoS — Elasticsearch Resource Exhaustion | User-supplied size parameter bypasses limit → excessive allocation / DoS |
Why should TPRM professionals care?
Elasticsearch and Kibana frequently store and expose security-sensitive data — including SIEM logs, application telemetry, user behavior data, and business analytics — making authorization failures on this platform directly impactful for data confidentiality. CVE-2026-102406's cross-tenant data interception in Kibana is particularly relevant for organizations whose vendors operate shared Elastic deployments serving multiple internal teams or business units: the tenant isolation model that is supposed to separate their data from other tenants' data can be bypassed by any authenticated user. CVE-2026-103007's privilege escalation in Elasticsearch is relevant for organizations using role delegation to limit administrative scope — the delegated admin pattern is a common enterprise deployment approach that this vulnerability undermines. The three DoS vulnerabilities collectively represent availability risk for any Elasticsearch deployment accessible to potentially hostile internal users or that processes externally supplied query parameters.
What questions should TPRM professionals ask vendors?
- Have you applied Elastic's October 2026 security update for both Elasticsearch and Kibana, and can you confirm the patched version numbers for both components?
- Does your Kibana deployment serve multiple tenants — different users, teams, or business units — with data isolation enforced by Kibana's tenant model, and if so, has CVE-2026-102406's cross-tenant authorization bypass been assessed for your specific deployment configuration?
- Do any Elasticsearch role assignments use delegated administrative privileges, and if so, have you reviewed whether CVE-2026-103007's authorization scope enforcement failure could allow privilege escalation beyond the intended delegation boundary?
- Are any Elasticsearch search or aggregation API endpoints accessible to externally supplied query parameters — including from application layers or untrusted users — creating exposure to the uncontrolled recursion DoS vulnerabilities?
- What categories of data are stored in your Elasticsearch indices, and have the data access implications of CVE-2026-102406 and CVE-2026-103009's authorization bypasses been assessed in the context of that data sensitivity?
Remediation recommendations
- Apply Elastic's October 2026 security update for both Elasticsearch and Kibana across all deployments; both products require independent updates as the vulnerabilities affect different components.
- Review Kibana tenant configuration and access controls for any multi-tenant deployment to assess the specific exposure of CVE-2026-102406, and consider restricting Kibana access to single-tenant configurations until patched.
- Audit Elasticsearch role assignments for delegated administrative privileges and review whether any role delegation pattern in your deployment is susceptible to the scope enforcement failure in CVE-2026-103007.
- Implement request size and depth limits at the application or API gateway layer in front of Elasticsearch as a defense-in-depth measure against the uncontrolled recursion and resource exhaustion DoS vectors.

Black Kite's Elastic - Oct2026 FocusTag® details critical insights on the event for TPRM professionals.
How TPRM Professionals Can Leverage Black Kite for These Vulnerabilities
This week's seven FocusTags® present several situations where standard TPRM workflows are insufficient without platform support: a double-patch advisory where prior confirmations are no longer valid, an expanding KEV chain requiring re-engagement of already-queried vendors, a cross-product single-CVE event requiring eight simultaneous patch verifications, a platform entering its fifth advisory cycle, and network infrastructure vulnerabilities outside normal TPRM scope.
For Citrix NetScaler, Black Kite tracks the September and October advisories as separate FocusTags®, enabling TPRM teams to identify vendors who have satisfied the September advisory but not the October update — the double-patch gap that creates false remediation confidence. For SonicWall SMA1000, the FocusTag® covers the full six-CVE set including the August KEV pair, enabling re-engagement of vendors previously assessed for the August advisory to confirm October advisory remediation. For Langflow, Black Kite's FocusTag® history across all five advisory cycles enables identification of vendors with persistent Langflow exposure — a pattern that warrants escalation beyond standard patch verification to architectural review. For Cisco NX-OS, Black Kite surfaces network infrastructure vulnerabilities that are invisible to application-layer scanning, providing the only external signal available for TPRM teams without network-level access to vendor environments. The Bridge connector enables simultaneous questionnaire dispatch to all seven FocusTag® vendor populations, managing the week's parallel engagement workstreams as a single coordinated workflow.
Strengthening TPRM Outcomes with Black Kite's FocusTags®
This week's seven-tag release illustrates how Black Kite's FocusTags® address scenarios that standard TPRM processes cannot handle alone.
- Double-Patch Advisory Tracking: Citrix NetScaler's October advisory requires a patch beyond last week's — meaning vendor confirmations from the September FocusTag® are no longer sufficient. Black Kite tracks each advisory separately, enabling TPRM teams to identify precisely which vendors confirmed September remediation but have not yet confirmed October remediation — preventing false assurance from stale confirmations.
- KEV Chain Expansion Re-Engagement: SonicWall SMA1000's October advisory expands the August CISA KEV cluster with four new CVEs. FocusTags® enable re-targeting of vendors already engaged for the August advisory, converting a new advisory into a structured re-engagement workflow rather than a cold outreach exercise.
- Cross-Product Single-CVE Portfolio Assessment: Atlassian's CVE-2026-21589 simultaneously affects eight distinct products across the Data Center portfolio. FocusTags® aggregate this cross-product impact into a single vendor alert, enabling TPRM teams to identify which vendors run one or more affected Atlassian products and initiate structured multi-product patch verification without eight separate tracking threads.
- Network Infrastructure Layer Visibility: Cisco NX-OS vulnerabilities sit at the data center switching layer — outside the scope of application-layer TPRM assessment. FocusTags® surface network operating system exposures that standard scanning cannot detect, providing TPRM teams with a signal they would otherwise have no access to.
- Platform Architecture Risk Pattern: Langflow's fifth advisory cycle within a single reporting period is a systemic signal that goes beyond any individual CVE. Black Kite's FocusTag® history across all five cycles enables TPRM teams to identify vendors with persistent Langflow exposure and escalate engagement to architectural review — the appropriate response when a platform has demonstrated fundamental security architecture failure.
- Multi-Tenant Data Integrity Risk Detection: Elastic's Kibana cross-tenant authorization bypass directly threatens data isolation in shared deployments. FocusTags® identify vendors running vulnerable Kibana versions in environments where multi-tenant isolation is a security control — enabling TPRM teams to prioritize outreach to vendors whose data isolation architecture is specifically at risk.
- The Bridge: Scalable Seven-Tag Engagement: With seven simultaneous FocusTags® and five requiring re-engagement of vendors from prior advisories, The Bridge connector enables automated questionnaire dispatch to all affected populations at once — ensuring comprehensive coverage across both new and updated advisory events in a single managed workflow.
FocusTags® in the Last 30 Days
- Citrix NetScaler - Oct2026: CVE-2025-6543, CVE-2026-88771, CVE-2026-88772, CVE-2026-88779, CVE-2026-88778, Updated Advisory Requiring Build 14.1-73.41 / 13.1-64.28 — Vendors Patched to 14.1-73.37 per Sep2026 Advisory Remain Exposed to Memory Overflow in Gateway Mode and Must Patch Again.
- SonicWall SMA1000 - Oct2026: CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, CVE-2026-83548, CVE-2026-83549, Oct2026 Advisory Expands CISA KEV-Listed Pre-Auth SSRF/RCE Chain with Four New CVEs Including Zip Slip and Stored XSS in AMC.
- Exchange Server - Oct2026: CVE-2026-96940, Weak Authorization in Microsoft Exchange Server Enabling Authenticated Network Privilege Escalation (Patched: October 2026 Security Update).
- Cisco NX-OS - Oct2026: CVE-2026-76471 and 6 additional CVEs, Unauthenticated RCE with Root Privileges via NX-API Feature and Proactively Identified High-Severity Flaws in Cisco NX-OS Data Center Switching Platform.
- Atlassian - Oct2026: CVE-2026-21589, Critical Cross-Product Vulnerability Simultaneously Affecting All Atlassian Data Center Products — Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye.
- Langflow - Oct2026: CVE-2026-104334, CVE-2026-93674, and 19 additional CVEs, Fifth Advisory Cycle — 21-CVE IBM Batch Disclosure Including 4 Unauthenticated RCEs and 17 Authenticated RCE / Info Disclosure Vulnerabilities in Langflow OSS 1.0.0–1.12.2 (Fixed: 1.12.3).
- Elastic - Oct2026: CVE-2026-102406, CVE-2026-103007, CVE-2026-103009, and 5 additional CVEs, Kibana Cross-Tenant Authorization Bypass, Elasticsearch Privilege Escalation, Cross-Cluster Information Disclosure, and Denial of Service.
- Kiteworks: No CVE, Precautionary Shutdown Advisory Driven by Federal Intelligence Warning of Imminent Cyberattack, Advanced Forms Vulnerability Identified (Fixed: Kiteworks 9.5.1, Mandiant Engaged, Fewer Than 1% of Customers Affected).
- Citrix NetScaler - Sep2026 (Latest): CVE-2026-88771, CVE-2026-88772, and 6 additional CVEs, Two Confirmed Zero-Day Unauthenticated RCEs in All Default NetScaler Deployments and HTTP Smuggling (CISA KEV Sep 27 2026, Federal Deadline Sep 30, Fixed: 14.1-73.37, 13.1-64.23).
- MikroTik RouterOS - Sep2026: CVE-2026-84411, CVE-2026-86060, CVE-2026-67276, Integer Underflow Enabling Unauthenticated RCE or DoS, SSH Username Argument Flaw, and SSH Key Comparison Bypass (CISA ICS Advisory ICSA-26-272-06, Fixed: RouterOS 7.24).
- OpenSSL - Sep2026: CVE-2026-84782, CVE-2026-84783, CVE-2026-72897, CVE-2026-84784, Out-of-Bounds Read in DTLS, Use-After-Free in X.509 Certificate Caching, OOB Write in SSL_CTX Switching, and QUIC Resource Exhaustion (~1.8M Exposed Instances, Fixed: 3.0.16–3.4.1, 4.0.1).
- WordPress Core - Sep2026: CVE-2026-87902, Pre-Authentication Path Traversal → LFI → Unauthenticated RCE via PEAR pearcmd.php, Present Since WordPress 4.7.0 (CISA KEV Sep 25 2026, Public PoC, Fixed: 7.1.2 / backports to 4.7.37).
- ScreenConnect - Sep2026: CVE-2026-84869, Missing Authorization in ScreenConnect Client File-Transfer Enabling Worm-Like Malware Propagation to Every Connected Host Session (CISA KEV, Actively Exploited).
- Exim Mail - Sep2026: CVE-2026-94054, CVE-2026-94056, Out-of-Bounds Write and Uninitialized Resource in Exim PROXY Protocol v1 and v2 Handling (Fixed: Exim 4.100.1).
- Citrix NetScaler - Sep2026: CVE-2026-19490, CVE-2026-19489, Authentication Bypass via Unsigned SAML Assertion and Memory Overflow via SIP ALG (CISA KEV, Actively Exploited, Public PoC).
- Apache Tomcat - Sep2026: CVE-2026-76183, CVE-2026-86248, CVE-2026-86350, and 5 additional CVEs, WebSocket Security Constraint Bypass, CLIENT_CERT Auth Failure, and HTTP Request Smuggling (Fixed: 9.0.122, 10.1.60, 11.0.26).
- Langflow - Sep2026: CVE-2026-12944, CVE-2026-7524, CVE-2026-0770, CVE-2026-9198, Fourth Critical Vulnerability — SSRF via Incomplete DANGEROUS_IMPORTS Blocklist with False 'Validated: True' Signal (Fixed: 1.10.1).
- N-central - Sep2026: CVE-2026-86218, CVE-2026-86206, CVE-2026-86207, CVE-2026-18556, CVE-2026-18577, Pre-Authenticated CVSS 10.0 RCE Zero-Day and Dual Auth Bypass in N-able N-central (CISA KEV, Actively Exploited, Hotfix 4 Required).
- Adobe Commerce & Magento: CVE-2026-75650, CVE-2026-7565, Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CISA KEV, Actively Exploited, Composer Hotfix Required).
- MikroTrick: CVE-2026-67276, CVE-2026-86060, CVE-2026-67277, CVE-2026-67281, CVE-2026-67279, CVE-2026-67278, Six-Vulnerability Set Enabling Unauthenticated RouterOS Takeover (Active Exploitation Confirmed).
- Fortinet - Sep2026 [Suspected]: CVE-2026-84393, CVE-2026-84391, CVE-2026-22575, Improper Certificate Validation and Authenticated DoS in FortiOS, FortiProxy, FortiAnalyzer, and FortiManager.
- MSSQL - Sep2026: CVE-2026-47297, CVE-2026-65669, and 59 additional CVEs, Largest Single-Month SQL Server Disclosure Batch with Unauthenticated RCE.
- SharePoint - Sep2026: CVE-2026-69464, CVE-2026-69716, CVE-2026-69268, and 13 additional CVEs, Six Independent RCE Pathways via Low-Privilege Auth in SharePoint Server.
- Exchange Server - Sep2026: CVE-2026-69356, CVE-2026-69641, CVE-2026-69355, CVE-2026-55007, and 5 additional CVEs, Unauthenticated XSS Spoofing and Multiple RCE in Microsoft Exchange Server.
- MongoDB - Sep2026: CVE-2026-82067, CVE-2026-82075, CVE-2026-82064, and 18 additional CVEs, Silent Authorization Bypass and Unauthenticated DoS in MongoDB Server 7.0, 8.0, and 8.3.
References
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
https://www.cve.org/CVERecord?id=CVE-2025-6543
https://www.cve.org/CVERecord?id=CVE-2026-88779
https://www.cve.org/CVERecord?id=CVE-2026-88771
https://www.cve.org/CVERecord?id=CVE-2026-88772
https://www.cve.org/CVERecord?id=CVE-2026-88778
https://www.cve.org/CVERecord?id=CVE-2026-102255
https://www.cve.org/CVERecord?id=CVE-2026-102256
https://www.cve.org/CVERecord?id=CVE-2026-102257
https://www.cve.org/CVERecord?id=CVE-2026-102258
https://www.cve.org/CVERecord?id=CVE-2026-83548
https://www.cve.org/CVERecord?id=CVE-2026-83549
https://www.cve.org/CVERecord?id=CVE-2026-96940
https://msrc.microsoft.com/update-guide/
https://www.cve.org/CVERecord?id=CVE-2026-76471
https://sec.cloudapps.cisco.com/security/center/publicationListing.x
https://www.cve.org/CVERecord?id=CVE-2026-21589
https://www.atlassian.com/trust/security/advisories
https://www.cve.org/CVERecord?id=CVE-2026-104334
https://www.cve.org/CVERecord?id=CVE-2026-93674
https://www.cve.org/CVERecord?id=CVE-2026-97655
https://www.cve.org/CVERecord?id=CVE-2026-93675
https://www.ibm.com/support/pages/node/langflow-october-2026
https://www.cve.org/CVERecord?id=CVE-2026-102406
https://www.cve.org/CVERecord?id=CVE-2026-103007