[vulnfeed] 10 critical CVEs — 2026-08-24 20:00 UTC
vulnfeed
Critical alert — 2026-08-24 20:55 UTC
10 new critical CVEs
in the last 5 hours — 10 CVSS ≥ 9.0
New vulnerabilities
CVE-2025-36939CRITICAL
Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same
Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These is
CVSS 10.0
CVE-2026-19685CRITICAL
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-v
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged
CVSS 9.8
CVE-2026-39975CRITICAL
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during th
CVSS 9.4
CVE-2026-78555CRITICAL
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration pag
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full
CVSS 9.4
CVE-2026-76070CRITICAL
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unaut
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base
CVSS 9.3
CVE-2026-76071CRITICAL
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unaut
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destH
CVSS 9.3
CVE-2026-77915CRITICAL
rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attack
rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare A
CVSS 9.3
CVE-2026-71914CRITICAL
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulne
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TES
CVSS 9.3
CVE-2026-71921CRITICAL
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field be
CVSS 9.3
CVE-2026-76835CRITICAL
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authent
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: