Vulnfeed

Archives
Log in
Subscribe
September 14, 2026

[vulnfeed] 11 critical CVEs — 2026-09-14 20:00 UTC

vulnfeed Critical alert — 2026-09-14 23:19 UTC
11 new critical CVEs in the last 5 hours — 11 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-16338CRITICAL
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perfo
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.
CVSS 9.9
CVE-2026-59178CRITICAL
ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0
ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESP
CVSS 9.8
CVE-2026-54333CRITICAL
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not
CVSS 9.8
CVE-2026-54334CRITICAL
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Num
CVSS 9.8
CVE-2026-55209CRITICAL
resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9,
resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and arra
CVSS 9.8
CVE-2026-12944CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privilege
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib impo
CVSS 9.6
CVE-2026-90942CRITICAL
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-ce
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Atta
CVSS 9.3
CVE-2026-90945CRITICAL
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid adminis
CVSS 9.3
CVE-2026-67399CRITICAL
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
CVSS 9.3
CVE-2026-50006CRITICAL
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticat
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE
CVSS 9.1
CVE-2026-53713CRITICAL
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based applicati
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/l
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 16 critical CVEs — 2026-09-15 16:00 UTC Older → [vulnfeed] 11 critical CVEs — 2026-09-14 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.