Redpacketsecurity Multiple CVEs Disclosed for HUBzero and RosarioSIS CMS Vulnerabilities
Article Content
- •CVE-2026-92984 allows session hijacking via session fixation.
- •CVE-2026-92970 enables path traversal for file manipulation by authenticated users.
- •CVE-2026-93014 permits file deletion through path traversal in RosarioSIS.
On September 17, 2026, four critical vulnerabilities were published affecting HUBzero CMS and RosarioSIS. CVE-2026-92984 allows session fixation attacks, enabling unauthenticated attackers to hijack user sessions. CVE-2026-92970 exposes a path traversal vulnerability that could lead to unauthorized file creation and potential code execution by authenticated users. CVE-2026-93014 in RosarioSIS permits authenticated users to delete files via path traversal, risking data integrity. Lastly, CVE-2026-92980 in HortusFox-Web allows remote code execution by authenticated administrators through the Import/Export functionality. All vulnerabilities are classified as high priority for remediation due to their potential impact on sensitive data and system integrity. Current exploitation status remains unconfirmed for all CVEs, but they require immediate attention from affected organizations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-92970 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…