Redpacketsecurity CVE-2026-90925 and CVE-2026-90926 Affect Innotim Logsign SIEM
Article Content
- •Two vulnerabilities in Logsign SIEM: CVE-2026-90925 and CVE-2026-90926.
- •Both CVEs affect versions 6.4.101 to 6.4.116 and were published on 2026-09-28.
- •Immediate upgrade to patched versions is recommended to mitigate risks.
Innotim Software's Logsign SIEM has two critical vulnerabilities: CVE-2026-90925 (Path Traversal) and CVE-2026-90926 (Code Injection). Both vulnerabilities affect versions 6.4.101 to 6.4.116 and were published on 2026-09-28. CVE-2026-90925 allows attackers to alter files or resources, potentially disrupting monitoring and investigations. CVE-2026-90926 enables code execution, which could tamper with security data and expose sensitive logs. Both vulnerabilities require low-level privileges for exploitation, making deployments accessible from the internet particularly at risk. Urgency is noted but cannot be elevated due to lack of exploitation evidence. Organizations are advised to upgrade to the fixed release and restrict access until patched.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Logsign and CVE-2026-90925 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…