<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>runZero Rapid Responses</title>
    <link>https://help.runzero.com/docs/em-rapid-response/</link>
    <description>Latest runZero Rapid Response queries for emerging threats</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 14 Sep 2026 20:25:52 +0000</lastBuildDate>
    <item>
      <title>Rapid Response: Cisco Secure Email Gateway SQL Injection (CVE-2026-76461)</title>
      <link>https://help.runzero.com/docs/em-rapid-response/</link>
      <description>&lt;p&gt;Cisco Secure Email Gateway is a secure email security appliance that allows organizations to handle email securely and potentially quarantine malicious or unwanted emails for analysis.&#xA;&#xA;Certain versions of the Secure Email Gateway are affected by an unauthenticated SQL injection vulnerability, that could allow an unauthenticated actor to execute commands with administrative privileges on the underlying operating system.&#xA;&#xA;There is evidence that these vulnerabilities are being actively *exploited in the wild* and the vulnerability has been added to the CISA KEV list September 14, 2026.&#xA;&#xA;The following versions are affected&#xA;- 15.5.4-012 and earlier&#xA;- 16.0.3-044 and earlier&#xA;- 16.5.0 before 16.5.0-780&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Query:&lt;/strong&gt; &lt;code&gt;_asset.protocol:=http AND protocol:=http AND last.html.title:&amp;#34;Cisco%Gateway%C&amp;#34; AND NOT last.html.title:&amp;#34;Cloud&amp;#34;&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Type: services · Category: Rapid Response · Severity: Info&lt;/p&gt;</description>
      <pubDate>Mon, 14 Sep 2026 20:25:52 +0000</pubDate>
      <guid>https://help.runzero.com/docs/em-rapid-response/#a2836506-aad1-4d79-a6c7-2a581462ff0f</guid>
    </item>
    <item>
      <title>Rapid Response: GitLab Unauthenticated Path Traversal (CVE-2026-85706)</title>
      <link>https://help.runzero.com/docs/em-rapid-response/</link>
      <description>&lt;p&gt;GitLab Community Edition (CE) provides core Git repository management and CI/CD pipelines, while Enterprise Edition&#xA;(EE) includes all CE capabilities alongside advanced security, compliance, and enterprise scalability features.&#xA;&#xA;Self-managed installations of GitLab Community Edition (CE) and Enterprise Edition (EE) contain a critical path&#xA;traversal vulnerability in the repository commits API. Due to improper path confinement and missing authentication&#xA;enforcement, a remote, unauthenticated attacker can read arbitrary server files. Successful exploitation may lead to&#xA;the exposure of sensitive configuration data, system credentials, or source code.&#xA;&#xA;There is evidence that this vulnerability is being actively *exploited in the wild*, and it was added to the CISA&#xA;Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026.&#xA;&#xA;The following versions are affected:&#xA;- GitLab CE &amp;amp; EE 18.x - 19.1.x: Versions 18.7.0 through 19.1.7&#xA;- GitLab CE &amp;amp; EE 19.2.x: Versions 19.2.0 through 19.2.5&#xA;- GitLab CE &amp;amp; EE 19.3.x: Versions 19.3.0 through 19.3.1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Query:&lt;/strong&gt; &lt;code&gt;vendor:=&amp;#34;GitLab&amp;#34; AND product:=&amp;#34;GitLab&amp;#34;&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Type: software · Category: Rapid Response · Severity: Info&lt;/p&gt;</description>
      <pubDate>Fri, 11 Sep 2026 21:18:34 +0000</pubDate>
      <guid>https://help.runzero.com/docs/em-rapid-response/#6fd01ecf-ba6e-4025-806b-bfc700afebff</guid>
    </item>
    <item>
      <title>Rapid Response: N-Able N-Central Multiple Vulnerabilities (2026-09)</title>
      <link>https://help.runzero.com/docs/em-rapid-response/</link>
      <description>&lt;p&gt;N-able N-central is an enterprise remote monitoring and management (RMM) software platform used by managed service&#xA;providers (MSPs) and internal IT teams to discover, automate, patch, and secure network infrastructure and endpoints&#xA;across Windows, macOS, Linux, and cloud environments.&#xA;&#xA;Certain versions of N-Central are affected by multiple vulnerabilities:&#xA;&#xA;- CVE-2026-86206: An access control bypass vulnerability in the internal API access control filter allows a remote,&#xA;unauthenticated attacker to obtain unauthorized access to internal APIs.&#xA;&#xA;- CVE-2026-86207: An authentication bypass vulnerability in the internal API allows a remote, low-privileged attacker&#xA;to obtain unauthorized privileges.&#xA;&#xA;- CVE-2026-86218: A pre-authentication remote code execution (RCE) vulnerability allows a remote, unauthenticated&#xA;attacker to execute arbitrary commands on the target server.&#xA;&#xA;There is evidence that CVE-2026-86218 is being actively *exploited in the wild*, prompting its addition to the CISA&#xA;KEV catalog on September 8, 2026.&#xA;&#xA;The following versions are affected:&#xA;- N-Central: Versions prior to 2026.3 Hotfix 4 (Build 2026.3.1.14)&#xA;&#xA;Note: CVE-2026-86218 is resolved in 2026.3 Hotfix 4 (Build 2026.3.1.14), which supersedes 2026.3 Hotfix 3&#xA;(Build 2026.3.1.13) (the patch for CVE-2026-86206 and CVE-2026-86207).&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Query:&lt;/strong&gt; &lt;code&gt;vendor:=&amp;#34;N-able&amp;#34; AND product:=&amp;#34;N-central&amp;#34; AND source:runzero&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Type: software · Category: Rapid Response · Severity: Info&lt;/p&gt;</description>
      <pubDate>Wed, 09 Sep 2026 13:55:32 +0000</pubDate>
      <guid>https://help.runzero.com/docs/em-rapid-response/#4515d25d-00b6-4c94-a57f-709adfce42bd</guid>
    </item>
    <item>
      <title>Rapid Response: Multiple Vulnerabilities In Mikrotik RouterOS</title>
      <link>https://help.runzero.com/docs/em-rapid-response/</link>
      <description>&lt;p&gt;Mikrotik RouterOS versions prior to 6.49.21, 7.23.4, 7.24.2, or 7.25 beta 3 are affected by multiple vulnerabilities:&#xA;&#xA;- CVE-2026-67276: RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.&#xA;&#xA;- CVE-2026-67277: RouterOS accepts a &amp;#34;related&amp;#34; btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With &amp;#34;random-data=false&amp;#34;, the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.&#xA;&#xA;- CVE-2026-67278: MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation.&#xA;&#xA;- CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.&#xA;&#xA;- CVE-2026-67281: RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.&#xA;&#xA;- CVE-2026-86060: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.&#xA;&#xA;There is evidence that these vulnerabilities are being actively *exploited in the wild* as of September 6th, 2026.&#xA;&#xA;The following versions are affected&#xA;- From 6.0.0 below 6.49.21&#xA;- From 7.0.0 below 7.23.4&#xA;- From 7.24 below 7.24.2&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Query:&lt;/strong&gt; &lt;code&gt;os:=&amp;#34;MikroTik RouterOS&amp;#34; AND ((os_version:&amp;gt;=&amp;#34;6.0.0&amp;#34; AND os_version:&amp;lt;=&amp;#34;6.49.21&amp;#34;) OR (os_version:&amp;gt;&amp;#34;7.0.0&amp;#34; AND os_version:&amp;lt;=&amp;#34;7.23.4&amp;#34;) OR (os_version:&amp;gt;&amp;#34;7.24&amp;#34; AND os_version:&amp;lt;=&amp;#34;7.24.2&amp;#34;))&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Type: software · Category: Rapid Response · Severity: Info&lt;/p&gt;</description>
      <pubDate>Mon, 07 Sep 2026 20:38:21 +0000</pubDate>
      <guid>https://help.runzero.com/docs/em-rapid-response/#00414b6a-6b03-4717-9918-e0b0d023fffc</guid>
    </item>
    <item>
      <title>Rapid Response: Multiple Vulnerabilities In SonicWall SMA 1000 Series Products</title>
      <link>https://help.runzero.com/docs/em-rapid-response/</link>
      <description>&lt;p&gt;SonicWall Secure Mobile Access (SMA) 1000 series appliances are hardware security devices that provide zero-trust and secure access gateway support for businesses.&#xA;&#xA;Certain versions of the SonicWall SMA1000 appliances are affected by multiple vulnerabilities:&#xA;&#xA;- CVE-2026-83548: An Server-Side Request Forgery (SSRF) vulnerability allows a remote unauthenticated attacker to access internal server resources and unintented locations.&#xA;&#xA;- CVE-2026-83549: An authenticated remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console (AMC) could allow an attacker with valid permissions to execute OS commands. &#xA;&#xA;There is evidence that these vulnerabilities are being actively *exploited in the wild* and the vulnerability has been added to the CISA KEV list September 3rd, 2026.&#xA;&#xA;The following versions are affected&#xA;- SMA1000 Models - 6210, 7210, 8200v&#xA;  - 12.4.3-03453&#xA;  - 12.5.0-02835&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Query:&lt;/strong&gt; &lt;code&gt;hw:=&amp;#34;SonicWall SMA1000&amp;#34; AND os_version:&amp;gt;0 AND (os_version:=12.4.3 OR os_version:=12.5.0)&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Type: software · Category: Rapid Response · Severity: Info&lt;/p&gt;</description>
      <pubDate>Thu, 03 Sep 2026 14:17:19 +0000</pubDate>
      <guid>https://help.runzero.com/docs/em-rapid-response/#4e588feb-2c31-41bc-9daf-6f7b8c14966f</guid>
    </item>
    <item>
      <title>Rapid Response: Plex Media Server &amp; Desktop Undisclosed Vulnerabilities (2026-09)</title>
      <link>https://help.runzero.com/docs/em-rapid-response/</link>
      <description>&lt;p&gt;Plex Media Server and Plex Desktop form a client-server media system where the server organizes and streams personal&#xA;media files from a central storage device, and the desktop application serves as a frontend interface for browsing and&#xA;playing that content on a computer.&#xA;&#xA;Plex has issued a security update addressing multiple undisclosed vulnerabilities across Plex Media Server and Plex&#xA;Desktop. While formal CVE identifiers have been requested, specific technical details and CVSS ratings remain&#xA;undisclosed. Unpatched installations may expose systems to unauthorized access or remote security risks depending on&#xA;the specific attack vector.&#xA;&#xA;The following versions are affected:&#xA;- Plex Media Server: Versions prior to 1.43.3&#xA;- Plex Desktop: Versions prior to 1.115.0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Query:&lt;/strong&gt; &lt;code&gt;vendor:=Plex AND product:&amp;#34;Media Server&amp;#34;&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Type: software · Category: Rapid Response · Severity: Info&lt;/p&gt;</description>
      <pubDate>Wed, 02 Sep 2026 14:08:37 +0000</pubDate>
      <guid>https://help.runzero.com/docs/em-rapid-response/#c3966fe4-b436-4ff3-afd1-60e1c56c1b9d</guid>
    </item>
    <item>
      <title>Rapid Response: BMC Vulnerabilities - runZero Research</title>
      <link>https://help.runzero.com/docs/em-rapid-response/</link>
      <description>&lt;p&gt;runZero has identified multiple vulnerabilities in a large subset of major baseboard management controllers (BMCs) that can lead to device compromise or segmentation breakdowns. Details of individual vulnerabilities will be published as the disclosure process completes.&#xA;&#xA;BMCs are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer&amp;#39;s ground-breaking research in 2013. Since Farmer&amp;#39;s original research into Cipher Zero authentication bypass and RAKP password hash disclosure, dozens of new vulnerabilities have been identified in these devices, but none of this research revisits the IPMI protocol itself.&#xA;&#xA;High level details of our findings will be presented at Black Hat 2026 &amp;amp; DEF CON 34. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Query:&lt;/strong&gt; &lt;code&gt;(protocol:ipmi OR type:=BMC) AND ( hw:=OpenBMC OR  hw:=&amp;#34;Super Micro IPMI&amp;#34; OR  hw:=&amp;#34;HP% iLO%&amp;#34; OR  hw:=&amp;#34;Dell iDRAC%&amp;#34; OR  hw:=&amp;#34;AMI MegaRAC&amp;#34; OR  (hw:=&amp;#34;Raritan%&amp;#34; AND type:=&amp;#34;Power Device&amp;#34;) OR  hw:=&amp;#34;H3C HDM&amp;#34; OR  hw:=&amp;#34;Fujitsu%&amp;#34;)&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Type: assets · Category: Rapid Response · Severity: Info&lt;/p&gt;</description>
      <pubDate>Tue, 04 Aug 2026 15:51:19 +0000</pubDate>
      <guid>https://help.runzero.com/docs/em-rapid-response/#4fc6f56c-587a-4742-ab40-542cd6aee1be</guid>
    </item>
  </channel>
</rss>