Vulnfeed

Archives
Log in
Subscribe
September 3, 2026

[vulnfeed] 10 critical CVEs — 2026-09-03 20:00 UTC

vulnfeed Critical alert — 2026-09-03 22:40 UTC
10 new critical CVEs in the last 5 hours — 10 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-85061CRITICAL
MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in s
MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() re
CVSS 10.0
CVE-2026-69083CRITICAL
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): read
**CVE:** This vulnerability corresponds to [CVE-2026-69083](https://nvd.nist.gov/vuln/detail/CVE-2026-69083). ### Summary The `/api/search/fullTextSearchAssetContent` endpoint exposes two SQL flaws
CVSS 10.0
CVE-2026-69084CRITICAL
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw sta
**CVE:** This vulnerability corresponds to [CVE-2026-69084](https://nvd.nist.gov/vuln/detail/CVE-2026-69084). ### Summary The `/api/search/searchEmbedBlock` endpoint passes a client-supplied SQL sta
CVSS 10.0
CVE-2026-85042CRITICAL
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitr
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS 9.6
CVE-2026-85047CRITICAL
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted H
CVSS 9.6
CVE-2026-85050CRITICAL
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker t
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security s
CVSS 9.6
CVE-2026-82526CRITICAL
R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to exec
R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index
CVSS 9.3
CVE-2026-85391CRITICAL
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthentic
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published se
CVSS 9.3
CVE-2026-85394CRITICAL
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-enc
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's publ
CVSS 9.3
CVE-2026-58400CRITICAL
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure proce
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 4 critical CVEs — 2026-09-04 04:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-09-03 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.