Vulnfeed

Archives
Log in
Subscribe
September 1, 2026

[vulnfeed] 10 critical CVEs — 2026-09-01 20:00 UTC

vulnfeed Critical alert — 2026-09-01 22:41 UTC
10 new critical CVEs in the last 5 hours — 10 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-76657CRITICAL
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Succes
CVSS 10.0
CVE-2026-76658CRITICAL
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an un
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Succe
CVSS 10.0
CVE-2026-73749CRITICAL
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specia
CVSS 9.8
CVE-2026-84372CRITICAL
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until versio
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an al
CVSS 9.8
CVE-2026-79675CRITICAL
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-
## Vulnerability The fix for CVE-2026-12841 (CWE-88, JVM argument injection) added `_validate_java_options()` to block dangerous JVM flags such as `-agentlib`, `-agentpath`, `-javaagent`, `-Xrunjdwp`
CVSS 9.8
CVE-2026-19766CRITICAL
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Comp
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute
CVSS 9.6
CVE-2023-54391CRITICAL
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-acc
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any exis
CVSS 9.3
CVE-2026-73700CRITICAL
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authent
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack a
CVSS 9.0
CVE-2026-73701CRITICAL
An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networ
An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attack
CVSS 9.0
CVE-2026-75604CRITICAL
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, N
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-h
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-09-02 04:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-09-01 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.