[vulnfeed] 16 critical CVEs — 2026-09-30 20:00 UTC
vulnfeed
Critical alert — 2026-09-30 20:56 UTC
16 new critical CVEs
in the last 5 hours — 16 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-102427CRITICAL
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent)
CVSS 10.0
CVE-2026-55107CRITICAL
Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of
Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-part
CVSS 10.0
CVE-2026-55494CRITICAL
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not co
CVSS 9.8
CVE-2026-100512CRITICAL
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
CVSS 9.8
CVE-2026-102489CRITICAL
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code executi
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3
CVSS 9.4
CVE-2026-102490CRITICAL
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
CVSS 9.4
CVE-2026-55181CRITICAL
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc
CVSS 9.4
CVE-2026-103470CRITICAL
In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in t
In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.
CVSS 9.3
CVE-2026-103475CRITICAL
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can a
CVSS 9.3
CVE-2026-19445CRITICAL
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callba
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certif
CVSS 9.2
CVE-2026-103473CRITICAL
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process w
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS command
CVSS 9.2
CVE-2026-102992CRITICAL
piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadP
piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applica
CVSS 9.2
CVE-2026-103547CRITICAL
In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are
In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. Afte
CVSS 9.2
CVE-2026-62308CRITICAL
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to ar
CVSS 9.1
CVE-2026-75969CRITICAL
Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade
Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware upd
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: