Vulnfeed

Archives
Log in
Subscribe
September 29, 2026

[vulnfeed] 2 critical CVEs — 2026-09-29 00:00 UTC

vulnfeed Critical alert — 2026-09-29 00:28 UTC
2 new critical CVEs in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-102268CRITICAL
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py i
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by t
CVSS 9.1
CVE-2026-102334CRITICAL
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated a
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-09-29 12:00 UTC Older → [vulnfeed] 12 critical CVEs — 2026-09-28 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.