Vulnfeed

Archives
Log in
Subscribe
September 27, 2026

[vulnfeed] 2 critical CVEs — 2026-09-27 04:00 UTC

vulnfeed Critical alert — 2026-09-27 05:36 UTC
2 new critical CVEs in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-100721CRITICAL
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder co
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolve
CVSS 9.5
CVE-2026-100835CRITICAL
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestati
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and sof
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-09-27 16:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-09-26 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.