Vulnfeed

Archives
Log in
Subscribe
September 17, 2026

[vulnfeed] 18 critical CVEs — 2026-09-17 20:00 UTC

vulnfeed Critical alert — 2026-09-17 22:59 UTC
18 new critical CVEs in the last 5 hours — 18 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-54734CRITICAL
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the
CVSS 10.0
CVE-2026-54617CRITICAL
GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticat
GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default
CVSS 9.8
CVE-2026-54626CRITICAL
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC p
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 alloc
CVSS 9.8
CVE-2026-54627CRITICAL
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC p
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/hel
CVSS 9.8
CVE-2026-45140CRITICAL
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticate
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does
CVSS 9.8
CVE-2026-54460CRITICAL
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Pr
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied
CVSS 9.8
CVE-2026-54053CRITICAL
Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault i
Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames contai
CVSS 9.6
CVE-2026-54752CRITICAL
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache
CVSS 9.6
CVE-2026-54618CRITICAL
Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an
Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can excha
CVSS 9.4
CVE-2026-54501CRITICAL
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or us
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly
CVSS 9.4
CVE-2026-54237CRITICAL
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php a
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installat
CVSS 9.3
CVE-2026-92943CRITICAL
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Devic
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-t
CVSS 9.2
CVE-2026-93393CRITICAL
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Win
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to, or an attacker a
CVSS 9.2
CVE-2026-54670CRITICAL
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metod
CVSS 9.1
CVE-2026-54767CRITICAL
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only a
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 4 critical CVEs — 2026-09-18 04:00 UTC Older → [vulnfeed] 6 critical CVEs — 2026-09-17 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.