[vulnfeed] 1 critical CVE — 2026-09-23 16:00 UTC
vulnfeed
Critical alert — 2026-09-23 19:45 UTC
1 new critical CVE
in the last 5 hours — 1 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-85724CRITICAL
Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS
moquette is reachable by untrusted MQTT clients (anonymous by default), so every byte from any client, including pre-authentication, is untrusted. This is a memory-safe JVM: the ceiling is authorizati
CVSS 9.6
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: