[vulnfeed] 16 critical CVEs — 2026-09-15 16:00 UTC
vulnfeed
Critical alert — 2026-09-15 19:46 UTC
16 new critical CVEs
in the last 5 hours — 16 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-59971CRITICAL
MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prio
MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct S
CVSS 10.0
CVE-2026-63695CRITICAL
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unau
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lead
CVSS 9.8
CVE-2026-55211CRITICAL
Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate
Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed.
CVSS 9.8
CVE-2026-39919CRITICAL
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a cr
CVSS 9.3
CVE-2026-46495CRITICAL
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-contro
CVSS 9.2
CVE-2026-91949CRITICAL
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthen
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. At
CVSS 9.2
CVE-2026-91988CRITICAL
atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factor
atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers ca
CVSS 9.2
CVE-2026-55158CRITICAL
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by i
CVSS 9.1
CVE-2026-63696CRITICAL
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Chec
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit t
CVSS 9.1
CVE-2026-61549CRITICAL
Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines
Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/back
CVSS 9.0
CVE-2023-54397CRITICAL
Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Lengt
Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with
CVSS 9.0
CVE-2024-14029CRITICAL
Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no mess
Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this
CVSS 9.0
CVE-2026-77866CRITICAL
Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated U
Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block.
Only IPv4 a
CVSS 9.0
CVE-2026-77972CRITICAL
Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's
Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected.
Validatio
CVSS 9.0
CVE-2026-91931CRITICAL
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authent
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServer
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: