
🎯 Most likely to be exploited next (EPSS): • CVE-2026-12269 — EPSS 7% · CVSS 8.8 • CVE-2026-12268 — EPSS 4.7% · CVSS 8.8 • CVE-2026-100852 — EPSS 3.7% · CVSS 8.8 📄 Full weekly tables → https://github.com/notcve/reports/blob/main/weekly/2026-10-01.md
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🎯 Most likely to be exploited next (EPSS): • CVE-2026-12269 — EPSS 7% · CVSS 8.8 • CVE-2026-12268 — EPSS 4.7% · CVSS 8.8 • CVE-2026-100852 — EPSS 3.7% · CVSS 8.8 📄 Full weekly tables → https://github.com/notcve/reports/blob/main/weekly/2026-10-01.md