Vulnfeed

Archives
Log in
Subscribe
September 14, 2026

[vulnfeed] 11 critical CVEs — 2026-09-14 20:00 UTC

vulnfeed Critical alert — 2026-09-14 20:25 UTC
11 new critical CVEs in the last 5 hours — 11 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-57124CRITICAL
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mc
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args v
CVSS 9.8
CVE-2026-57127CRITICAL
PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAut
PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware fo
CVSS 9.8
CVE-2026-57131CRITICAL
PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jo
PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization
CVSS 9.8
CVE-2026-20353CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatewa
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive in
CVSS 9.8
CVE-2026-76440CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatewa
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive in
CVSS 9.8
CVE-2026-76441CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatewa
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive in
CVSS 9.8
CVE-2026-76443CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatewa
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive in
CVSS 9.8
CVE-2026-76461CRITICAL
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an u
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the
CVSS 9.8
CVE-2026-90943CRITICAL
parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body
parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can
CVSS 9.3
CVE-2026-57145CRITICAL
PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes th
PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without trave
CVSS 9.1
CVE-2026-61534CRITICAL
Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyS
Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-ob
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 11 critical CVEs — 2026-09-14 20:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-09-13 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.