[vulnfeed] 2 critical CVEs — 2026-09-27 04:00 UTC
vulnfeed
Critical alert — 2026-09-27 05:36 UTC
2 new critical CVEs
in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-100721CRITICAL
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder co
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolve
CVSS 9.5
CVE-2026-100835CRITICAL
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestati
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and sof
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: