Deep Security Center

RULE UPDATE: 26-050 (September 8, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

IBM Cognos TM1 Admin Server
1012650 - IBM Planning Analytics Code Injection Vulnerability (CVE-2019-4716)


JFrog
1012668 - JFrog Artifactory Authentication Bypass Vulnerability (CVE-2026-82329)


Kentico Xperience
1012646 - Kentico Xperience Directory Traversal Vulnerability (CVE-2025-2749)


SmarterTools SmarterMail
1012647 - SmarterMail ConnectToHub Unauthenticated RCE (CVE-2026-24423)


Web Application Common
1012659 - Kestra Authentication Bypass Vulnerability (CVE-2026-49869)


Web Application PHP Based
1012656 - Mirasvit Cache Warmer Deserialization Vulnerability (CVE-2026-45247)


Web Server Common
1012662 - Gitea Diffpatch API Git Hook Remote Code Execution Vulnerability (CVE-2026-60004)
1012653 - Sitecore Cms Insecure Deserialization Vulnerability (CVE-2019-9874)
1012655 - Sitecore Cms Insecure Deserialization Vulnerability (CVE-2019-9875)


Web Server HTTPS
1012657 - ATEN Unizon writeFileToHttp Directory Traversal Information Disclosure Vulnerability (CVE-2026-9776)
1012658 - Laravel Livewire Code Injection Vulnerability (CVE-2025-54068)
1012664 - Sangoma Switchvox SQL Injection Vulnerability (CVE-2026-9586)


Web Server SharePoint
1012652 - Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2026-20963)


ZohoCorp ManageEngine Desktop Central
1012642 - Zoho ManageEngine Desktop Central Filter Configuration Authentication Bypass Vulnerability (CVE-2021-44515)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-049 (September 3, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DHCP Server
1012640 - Windows DHCP Server Remote Code Execution Vulnerability (CVE-2026-50518)


Kentico Xperience
1012648 - Kentico Xperience Staging Service Authentication Bypass Vulnerability (CVE-2025-2746)


PaperCut
1012649 - PaperCut Authentication Bypass and RCE Vulnerability (CVE-2026-81578 and CVE-2026-82078)


Web Server Common
1012643 - Zabbix Authentication Bypass Vulnerability (CVE-2022-23134)


Web Server HTTPS
1012645 - Adminer Server-Side Request Forgery Vulnerability (CVE-2021-21311)
1012654 - SimpleHelp OpenID Connect Authentication Bypass Vulnerability (CVE-2026-48558)


Web Server Oracle
1012624 - Oracle Java SE Sandbox Bypass Vulnerability (CVE-2025-30761)


Integrity Monitoring Rules:

1002853* - Application - Apache Tomcat


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-048 (September 1, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Web Server Common
1012644 - Qlik Sense Enterprise Transfer-Encoding Request Smuggling Vulnerability (CVE-2023-48365)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-047 (August 27, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Web Server Common
1011265* - Apache Log4j Remote Code Execution Vulnerability (CVE-2021-45046)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-046 (August 25, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

JetBrains TeamCity
1012637 - JetBrains TeamCity Insecure Deserialization Vulnerability (CVE-2026-63077)


Web Server HTTPS
1012639 - Metabase Unauthenticated Attack Code Injection Vulnerability (CVE-2026-72898)
1012638 - WordPress Cross-Site Scripting Vulnerability (CVE-2026-64638)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-045 (August 20, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Langflow
1012619 - Langflow Code Injection Remote Code Execution Vulnerability (CVE-2025-3248)


NFS Server
1012627 - Linux Kernel Nfsv4.0 Lock Replay Cache Heap Overflow Vulnerability (CVE-2026-31402)


cPanel
1012628 - WebPros cPanel Code Injection Vulnerability (CVE-2026-29202)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-044 (August 18, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Web Server HTTPS
1012636 - Draytek Vigorconnect Directory Traversal Vulnerability (CVE-2021-20124)
1012632 - ServiceNow Code Injection Vulnerability (CVE-2026-6875)
1012631 - Sitecore Experience Commerce Insecure Deserialization Vulnerability (CVE-2025-53690)


Web Server SharePoint
1012629 - Microsoft SharePoint Server Authentication Bypass Vulnerability (CVE-2023-29357)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-043 (August 13, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DHCP Client
1012634 - Windows DHCP Server Remote Code Execution Vulnerability (CVE-2026-62823)


Oracle E-Business Suite Web Interface
1012600* - Oracle E-Business Suite Payments Authentication Bypass Vulnerability (CVE-2026-46817)


Web Application Common
1012625 - GLPI htmLawed Code Injection Vulnerability (CVE-2022-35914)


Web Server Adobe ColdFusion
1012630 - Adobe ColdFusion Untrusted Data Deserialization Vulnerability (CVE-2023-29300)


Web Server Common
1012623 - Joomla JMedia Arbitrary File Upload Vulnerability (CVE-2026-60032)


Web Server HTTPS
1012633 - JoomShaper SP Page Builder Arbitrary File Upload Vulnerability (CVE-2026-48908)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-042 (August 11, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Web Server Common
1012626 - Foundation Agents MetaGPT Code Injection Vulnerability (CVE-2026-0761)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-041 (August 6, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Paperclip AI
1012622 - PaperclipAI Paperclip Code Injection Vulnerability (CVE-2026-41679)


Web Application Common
1009350* - Telerik UI for ASP.NET AJAX Multiple Arbitrary File Upload Vulnerabilities (CVE-2017-11357 and CVE-2017-11317)


Web Server Common
1012617 - Jenkins Deserialization Vulnerability (CVE-2026-53435)


Web Server HTTPS
1012605 - Cacti Command Injection Vulnerability (CVE-2024-29895)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.