Deep Security Center
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Splunk API
1012615 - Splunk Secure Gateway Deserialization Vulnerability (CVE-2026-20251)
Web Server Adobe ColdFusion
1012602 - Adobe ColdFusion Path Traversal Vulnerability (CVE-2026-48282)
Web Server Common
1012618 - Dolibarr ERP/CRM PHP Code Injection Vulnerability (CVE-2023-30253)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Splunk API
1012615 - Splunk Secure Gateway Deserialization Vulnerability (CVE-2026-20251)
Web Server Adobe ColdFusion
1012602 - Adobe ColdFusion Path Traversal Vulnerability (CVE-2026-48282)
Web Server Common
1012618 - Dolibarr ERP/CRM PHP Code Injection Vulnerability (CVE-2023-30253)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Ivanti Endpoint Manager
1012616 - Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability (CVE-2026-5786)
JetBrains TeamCity
1012612 - JetBrains TeamCity Command Injection Vulnerability (CVE-2026-49373)
Web Application PHP Based
1012611 - ThinkPHP Framework Local File Inclusion Vulnerability (CVE-2022-47945)
Zimbra Proxy
1012607 - Zimbra Collaboration Local File Inclusion Vulnerability (CVE-2025-68645)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Ivanti Endpoint Manager
1012616 - Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability (CVE-2026-5786)
JetBrains TeamCity
1012612 - JetBrains TeamCity Command Injection Vulnerability (CVE-2026-49373)
Web Application PHP Based
1012611 - ThinkPHP Framework Local File Inclusion Vulnerability (CVE-2022-47945)
Zimbra Proxy
1012607 - Zimbra Collaboration Local File Inclusion Vulnerability (CVE-2025-68645)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Git Push
1012584* - GitHub Enterprise Server Command Injection Vulnerability (CVE-2026-3854)
Tomcat Tribes NioReceiver
1012610 - Apache Tomcat EncryptInterceptor Bypass Vulnerability (CVE-2026-34486)
Web Server Common
1012596* - Microsoft Exchange Server HTTP NTLM Password Spray
Web Server HTTPS
1012592* - Allegra Cross-Site Scripting Authentication Bypass Vulnerability(CVE-2026-11443)
1012613 - WordPress REST API Batch Route Confusion SQL Injection Vulnerability (CVE-2026-63030)
Web Server Nagios
1012614 - Nagios Log Server Command Injection Vulnerability (CVE-2025-34322)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Git Push
1012584* - GitHub Enterprise Server Command Injection Vulnerability (CVE-2026-3854)
Tomcat Tribes NioReceiver
1012610 - Apache Tomcat EncryptInterceptor Bypass Vulnerability (CVE-2026-34486)
Web Server Common
1012596* - Microsoft Exchange Server HTTP NTLM Password Spray
Web Server HTTPS
1012592* - Allegra Cross-Site Scripting Authentication Bypass Vulnerability(CVE-2026-11443)
1012613 - WordPress REST API Batch Route Confusion SQL Injection Vulnerability (CVE-2026-63030)
Web Server Nagios
1012614 - Nagios Log Server Command Injection Vulnerability (CVE-2025-34322)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Linux Kernel Netfilter
1012603 - Linux Kernel Netfilter Nf_Conntrack_H323 Out-Of-Bounds Read Vulnerability (CVE-2026-23455)
Web Application PHP Based
1012606 - JoomShaper Helix3 Improper Access Control Vulnerability (CVE-2026-49049)
1012604 - Tassos Novarain Framework Improper Access Control Vulnerability (CVE-2026-21627)
Web Server Common
1012591 - Ivanti Sentry OS Command Injection Vulnerability (CVE-2026-10520)
Web Server HTTPS
1012599 - Cacti Unauthenticated Local File Inclusion Vulnerability (CVE-2026-39938)
Web Server SharePoint
1012609 - Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2026-50522)
1012608 - Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2026-56164)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Linux Kernel Netfilter
1012603 - Linux Kernel Netfilter Nf_Conntrack_H323 Out-Of-Bounds Read Vulnerability (CVE-2026-23455)
Web Application PHP Based
1012606 - JoomShaper Helix3 Improper Access Control Vulnerability (CVE-2026-49049)
1012604 - Tassos Novarain Framework Improper Access Control Vulnerability (CVE-2026-21627)
Web Server Common
1012591 - Ivanti Sentry OS Command Injection Vulnerability (CVE-2026-10520)
Web Server HTTPS
1012599 - Cacti Unauthenticated Local File Inclusion Vulnerability (CVE-2026-39938)
Web Server SharePoint
1012609 - Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2026-50522)
1012608 - Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2026-56164)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Oracle E-Business Suite Web Interface
1012600 - Oracle E-Business Suite Payments Authentication Bypass Vulnerability (CVE-2026-46817)
Web Server Common
1012590 - Apache Ofbiz Code Injection Vulnerability (CVE-2026-46586)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Oracle E-Business Suite Web Interface
1012600 - Oracle E-Business Suite Payments Authentication Bypass Vulnerability (CVE-2026-46817)
Web Server Common
1012590 - Apache Ofbiz Code Injection Vulnerability (CVE-2026-46586)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Web Server HTTPS
1012598 - ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability (CVE-2026-9775)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Web Server HTTPS
1012598 - ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability (CVE-2026-9775)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Splunk Enterprise
1012595 - Splunk Enterprise Authentication Bypass Vulnerability (CVE-2026-20253)
Web Application PHP Based
1012574* - WordPress 'StoryChief' Plugin Unauthenticated RCE (CVE-2025-7441)
Web Server HTTPS
1012597 - Allegra Directory Traversal Information Disclosure Vulnerability (CVE-2026-11442)
Web Server Miscellaneous
1012572* - Adobe Commerce Improper Input Validation (CVE-2025-54236)
1012579* - Crawl4AI Hooks Code Execution Vulnerability (CVE-2026-26216)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Splunk Enterprise
1012595 - Splunk Enterprise Authentication Bypass Vulnerability (CVE-2026-20253)
Web Application PHP Based
1012574* - WordPress 'StoryChief' Plugin Unauthenticated RCE (CVE-2025-7441)
Web Server HTTPS
1012597 - Allegra Directory Traversal Information Disclosure Vulnerability (CVE-2026-11442)
Web Server Miscellaneous
1012572* - Adobe Commerce Improper Input Validation (CVE-2025-54236)
1012579* - Crawl4AI Hooks Code Execution Vulnerability (CVE-2026-26216)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Oracle PeopleSoft PIA
1012585* - Oracle PeopleSoft Untrusted Data Deserialization Vulnerability (ZDI-CAN-31817)
Web Server Common
1012596 - Microsoft Exchange Server HTTP NTLM Password Spray
Web Server HTTPS
1012575 - WordPress 'Starter Templates' Plugin real_mimes Arbitrary File Upload (CVE-2025-13065)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Oracle PeopleSoft PIA
1012585* - Oracle PeopleSoft Untrusted Data Deserialization Vulnerability (ZDI-CAN-31817)
Web Server Common
1012596 - Microsoft Exchange Server HTTP NTLM Password Spray
Web Server HTTPS
1012575 - WordPress 'Starter Templates' Plugin real_mimes Arbitrary File Upload (CVE-2025-13065)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
OfficeScan
1012561* - Apex One Management Console Multiple Directory Traversal Vulnerabilities (CVE-2025-71210 & CVE-2025-71211)
Web Server Common
1012594 - CMS Made Simple News Module SQL Injection Vulnerability (CVE-2019-9053)
Web Server HTTPS
1012593 - Progress Software Kemp LoadMaster (CVE-2026-8037)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
OfficeScan
1012561* - Apex One Management Console Multiple Directory Traversal Vulnerabilities (CVE-2025-71210 & CVE-2025-71211)
Web Server Common
1012594 - CMS Made Simple News Module SQL Injection Vulnerability (CVE-2019-9053)
Web Server HTTPS
1012593 - Progress Software Kemp LoadMaster (CVE-2026-8037)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Web Server Common
1012589 - Control Web Panel Command Injection Vulnerability (CVE-2025-67888)
1012578 - Fuxa Path Traversal Vulnerability (CVE-2026-25895)
1012559* - Microsoft Windows LNK Spoofing Vulnerability (CVE-2026-32202)
Web Server HTTPS
1012592 - Allegra Cross-Site Scripting Authentication Bypass Vulnerability(CVE-2026-11443)
1012588 - Drupal Core SQL Injection Vulnerability (CVE-2026-9082)
Web Server Miscellaneous
1012398* - XWiki SQL Injection Vulnerability (CVE-2025-32969)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Web Server Common
1012589 - Control Web Panel Command Injection Vulnerability (CVE-2025-67888)
1012578 - Fuxa Path Traversal Vulnerability (CVE-2026-25895)
1012559* - Microsoft Windows LNK Spoofing Vulnerability (CVE-2026-32202)
Web Server HTTPS
1012592 - Allegra Cross-Site Scripting Authentication Bypass Vulnerability(CVE-2026-11443)
1012588 - Drupal Core SQL Injection Vulnerability (CVE-2026-9082)
Web Server Miscellaneous
1012398* - XWiki SQL Injection Vulnerability (CVE-2025-32969)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.