Vulnfeed

Archives
Log in
Subscribe
September 30, 2026

[vulnfeed] 14 critical CVEs — 2026-09-30 12:00 UTC

vulnfeed Critical alert — 2026-09-30 15:08 UTC
14 new critical CVEs in the last 5 hours — 14 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-96349CRITICAL
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
CVSS 10.0
CVE-2026-76504CRITICAL
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allo
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the
CVSS 9.8
CVE-2026-96350CRITICAL
Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
CVSS 9.8
CVE-2026-97248CRITICAL
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
CVSS 9.8
CVE-2026-97274CRITICAL
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
CVSS 9.8
CVE-2026-82307CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Sop
CVSS 9.8
CVE-2026-93903CRITICAL
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "cor
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
CVSS 9.4
CVE-2026-74864CRITICAL
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user"
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Ngi
CVSS 9.3
CVE-2026-96822CRITICAL
Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
CVSS 9.3
CVE-2026-74865CRITICAL
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be b
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the use
CVSS 9.2
CVE-2026-77185CRITICAL
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java li
CVSS 9.1
CVE-2026-94052CRITICAL
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java
CVSS 9.1
CVE-2026-94053CRITICAL
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 a
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server
CVSS 9.1
CVE-2026-94389CRITICAL
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 16 critical CVEs — 2026-09-30 20:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-09-30 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.