Vulnfeed

Archives
Log in
Subscribe
September 28, 2026

[vulnfeed] 12 critical CVEs — 2026-09-28 16:00 UTC

vulnfeed Critical alert — 2026-09-28 16:55 UTC
12 new critical CVEs in the last 5 hours — 12 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-85526CRITICAL
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated us
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories
CVSS 9.9
CVE-2026-87799CRITICAL
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.1
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instan
CVSS 9.9
CVE-2026-90924CRITICAL
Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co
Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects L
CVSS 9.8
CVE-2026-85185CRITICAL
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10,
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instan
CVSS 9.6
CVE-2026-12342CRITICAL
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API co
CVSS 9.6
CVE-2026-88804CRITICAL
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-si
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.1
CVSS 9.6
CVE-2026-101072CRITICAL
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the fil
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to o
CVSS 9.3
CVE-2026-73640CRITICAL
Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unaut
Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an a
CVSS 9.3
CVE-2026-101075CRITICAL
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipula
CVSS 9.3
CVE-2026-101076CRITICAL
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_n
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip res
CVSS 9.3
CVE-2026-101077CRITICAL
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible
CVSS 9.3
CVE-2026-73642CRITICAL
Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker
Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute local
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-09-29 00:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-09-27 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.