Vulnfeed

Archives
Log in
Subscribe
September 11, 2026

[vulnfeed] 10 critical CVEs — 2026-09-11 20:00 UTC

vulnfeed Critical alert — 2026-09-11 22:43 UTC
10 new critical CVEs in the last 5 hours — 10 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-82617CRITICAL
The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX
The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifier
CVSS 10.0
CVE-2026-59971CRITICAL
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS R
## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host
CVSS 10.0
CVE-2026-62103CRITICAL
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
CVSS 9.8
CVE-2026-62105CRITICAL
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
CVSS 9.8
CVE-2026-79395CRITICAL
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within t
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earli
CVSS 9.8
CVE-2026-53952CRITICAL
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS.
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below)
CVSS 9.8
CVE-2026-59151CRITICAL
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
## SAML Tenant Binding Enables Cross-Tenant Account Takeover ### Summary Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should rece
CVSS 9.6
CVE-2026-54072CRITICAL
Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, t
Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `Allowed
CVSS 9.3
CVE-2026-90456CRITICAL
An example environment-configuration file for a bundled inventory-management component ships with a fixed, pub
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into activ
CVSS 9.2
CVE-2026-61534CRITICAL
yayson: Prototype pollution in Store/LegacyStore deserialization
# Summary `Store`/`LegacyStore` key internal lookup tables by the `type`, `id`, and relationship names from a JSON:API document. Because these were plain objects, a document with `type: "__proto__"` w
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-09-12 04:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-09-07 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.