← Back to the live CVE advisory feed

CVE-2026-101085: Product identification pending

Severity
7.1 (HIGH)
Affected versions
Before 2.3.8
Fixed version
2.3.8
Patch status
Patched
Published
2026-09-27T21:17:02.307
Modified
2026-09-28T14:17:14.197

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 28, 2026 08:00 PM UTC
263 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-82377
Apache Roller PATCH
Reporter: SECURITY
9.9
CRITICAL
VIEW RECORD
CVE-2026-85526
LXD
Reporter: SECURITY
9.9
CRITICAL
VIEW RECORD
CVE-2026-87799
Product identification pending PATCH
Reporter: SECURITY
9.9
CRITICAL
VIEW RECORD
CVE-2026-82384
Apache Roller PATCH
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-90924
Product identification pending PATCH
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-85185
Product identification pending PATCH
Reporter: SECURITY
9.6
CRITICAL
VIEW RECORD
CVE-2026-12342
IdentityIQ
Reporter: PSIRT
9.6
CRITICAL
VIEW RECORD
CVE-2026-88804
Product identification pending PATCH
Reporter: MEISSNER
9.6
CRITICAL
VIEW RECORD
CVE-2026-19759
Application Integration PATCH
Reporter: F45CBF4E-4146-4068-B7E1-655FFC2C548C
9.4
CRITICAL
VIEW RECORD
CVE-2026-81867
Application Integration PATCH
Reporter: F45CBF4E-4146-4068-B7E1-655FFC2C548C
9.4
CRITICAL
VIEW RECORD
CVE-2026-101065
obot
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-101084
obot PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-101090
nezha
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-100886
T8108
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101000
NBR100V2
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101001
NBR200V2
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101039
FAC1900R
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101072
NR289-GE
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-73640
Payroll
Reporter: CVD
9.3
CRITICAL
VIEW RECORD
CVE-2026-101075
NR289-GE
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101076
NR289-GE
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101077
NR289-GE
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101891
WatchGuard AP
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.3
CRITICAL
VIEW RECORD
CVE-2026-86102
WatchGuard AP
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.3
CRITICAL
VIEW RECORD
CVE-2026-100752
Real Estate Manager (Free) extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-101108
Vehicle Manager (Free) extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-101110
Book Library (Free) extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-73642
Payroll
Reporter: CVD
9.2
CRITICAL
VIEW RECORD
CVE-2026-101894
decompress PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-49994
bluehood PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-82378
Apache Roller PATCH
Reporter: SECURITY
9
CRITICAL
VIEW RECORD
CVE-2026-101074
NR289-GE
Reporter: CNA
8.9
HIGH
VIEW RECORD
CVE-2026-85134
Product identification pending PATCH
Reporter: ILETISIM
8.8
HIGH
VIEW RECORD
CVE-2026-12268
DDI Central
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-12269
DDI Central
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-12264
Product identification pending PATCH
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-78424
Product identification pending PATCH
Reporter: MEISSNER
8.8
HIGH
VIEW RECORD
CVE-2026-12265
Product identification pending PATCH
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-86595
Product identification pending PATCH
Reporter: ILETISIM
8.8
HIGH
VIEW RECORD
CVE-2026-90926
Product identification pending PATCH
Reporter: ILETISIM
8.8
HIGH
VIEW RECORD
CVE-2026-88808
Product identification pending PATCH
Reporter: MEISSNER
8.8
HIGH
VIEW RECORD
CVE-2026-101062
obot PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-95104
WSR-300HP
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-96538
Product identification pending PATCH
Reporter: 20BE33E2-BF35-4D13-8FAD-18BD2F3E3659
8.7
HIGH
VIEW RECORD
CVE-2026-48100
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-54675
security-reporting PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-100896
N150RT
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-101002
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-86530
WSR-300HP
Reporter: VULTURES
8.6
HIGH
VIEW RECORD
CVE-2026-101037
FAC1200R
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-101038
FAC1200R
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-93348
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-87969
WatchGuard AP
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
8.6
HIGH
VIEW RECORD
CVE-2026-54674
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-54708
security-reporting PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-54710
security-reporting PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-75600
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-100750
Product identification pending
Reporter: SECURITY
8.5
HIGH
VIEW RECORD
CVE-2026-101007
BaoTa
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-101008
BaoTa
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-101009
BaoTa
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-101081
DI-8400
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-55157
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-101064
obot PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-81375
Product identification pending PATCH
Reporter: F45CBF4E-4146-4068-B7E1-655FFC2C548C
8.3
HIGH
VIEW RECORD
CVE-2026-101909
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.3
HIGH
VIEW RECORD
CVE-2026-82383
Product identification pending PATCH
Reporter: SECURITY
8.2
HIGH
VIEW RECORD
CVE-2026-91043
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
8.2
HIGH
VIEW RECORD
CVE-2026-101292
Product identification pending PATCH
Reporter: SECALERT
8.2
HIGH
VIEW RECORD
CVE-2026-54160
nut PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-101901
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-101903
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-101906
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-82380
Product identification pending PATCH
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-82323
Product identification pending
Reporter: ILETISIM
8.1
HIGH
VIEW RECORD
CVE-2026-88805
Product identification pending PATCH
Reporter: MEISSNER
8.1
HIGH
VIEW RECORD
CVE-2026-4556
Exam4
Reporter: 41C37E40-543D-43A2-B660-2FEE83EA851A
7.8
HIGH
VIEW RECORD
CVE-2026-100908
Eyeplus
Reporter: CNA
7.7
HIGH
VIEW RECORD
CVE-2026-82348
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-82376
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-82379
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-82386
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-82928
Product identification pending PATCH
Reporter: CVD
7.7
HIGH
VIEW RECORD
CVE-2026-97335
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-45562
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-101905
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-55160
stringer PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-96280
Product identification pending
Reporter: SECALERT
7.5
HIGH
VIEW RECORD
CVE-2026-100751
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-82375
Product identification pending PATCH
Reporter: SECURITY
7.4
HIGH
VIEW RECORD
CVE-2026-12267
DDI Central
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
7.2
HIGH
VIEW RECORD
CVE-2026-86330
Product identification pending
Reporter: SECALERT
7.2
HIGH
VIEW RECORD
CVE-2026-101085
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-101086
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-94286
Product identification pending PATCH
Reporter: MEISSNER
7.1
HIGH
VIEW RECORD
CVE-2026-52748
AR2140
Reporter: CVD
7.1
HIGH
VIEW RECORD
CVE-2026-15952
Product identification pending
Reporter: CYBERSECURITY
7.1
HIGH
VIEW RECORD
CVE-2026-90925
Product identification pending PATCH
Reporter: ILETISIM
7.1
HIGH
VIEW RECORD
CVE-2026-93538
Product identification pending PATCH
Reporter: MEISSNER
7.1
HIGH
VIEW RECORD
CVE-2026-55096
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.1
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.