[vulnfeed] 17 critical CVEs — 2026-09-23 20:00 UTC
vulnfeed
Critical alert — 2026-09-23 23:03 UTC
17 new critical CVEs
in the last 5 hours — 17 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-77602CRITICAL
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content
CVSS 9.9
CVE-2026-84474CRITICAL
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The provisioning-callback se
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The provisioning-callback secret (host_config_key) is exposed to
users holding only the read-level view_jobtemplate pe
CVSS 9.9
CVE-2026-84502CRITICAL
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The Project scm_url field is
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The Project scm_url field is not validated against values that
begin with a dash and is stored and passed verbatim to
CVSS 9.9
CVE-2026-84719CRITICAL
A flaw was found in the Ansible Automation Platform automation-controller. When a
WorkflowJobTemplate is copie
A flaw was found in the Ansible Automation Platform automation-controller. When a
WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory,
unified_job_template,
CVSS 9.9
CVE-2026-6721CRITICAL
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input t
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the unde
CVSS 9.8
CVE-2026-6730CRITICAL
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A loca
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
CVSS 9.8
CVE-2026-6928CRITICAL
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory
CVSS 9.8
CVE-2026-87898CRITICAL
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
CVSS 9.4
CVE-2026-87899CRITICAL
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code wi
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
CVSS 9.4
CVE-2026-87900CRITICAL
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
CVSS 9.4
CVE-2026-95601CRITICAL
Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
CVSS 9.3
CVE-2026-96770CRITICAL
All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server list
All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This mode check
CVSS 9.3
CVE-2026-93352CRITICAL
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extensio
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist
CVSS 9.3
CVE-2026-63132CRITICAL
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRec
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary
CVSS 9.2
CVE-2026-67404CRITICAL
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Whe
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bundle is available, ssl_options/1 falls back to [{verify, verify_none}] with no w
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: