Vulnfeed

Archives
Log in
Subscribe
September 12, 2026

[vulnfeed] 2 critical CVEs — 2026-09-12 12:00 UTC

vulnfeed Critical alert — 2026-09-12 12:18 UTC
2 new critical CVEs in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-78006CRITICAL
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient p
CVSS 9.8
CVE-2026-78159CRITICAL
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of
CVSS 9.8

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
Older → [vulnfeed] 2 critical CVEs — 2026-09-12 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.