Vulnfeed

Archives
Log in
Subscribe
September 18, 2026

[vulnfeed] 22 critical CVEs — 2026-09-18 16:00 UTC

vulnfeed Critical alert — 2026-09-18 19:06 UTC
22 new critical CVEs in the last 5 hours — 22 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-93603CRITICAL
vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of
vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-m
CVSS 10.0
CVE-2026-93605CRITICAL
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require c
CVSS 10.0
CVE-2026-93606CRITICAL
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromis
CVSS 10.0
CVE-2025-15399CRITICAL
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnera
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u
CVSS 10.0
CVE-2026-10747CRITICAL
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary c
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
CVSS 10.0
CVE-2025-53837CRITICAL
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user
CVSS 9.9
CVE-2026-10858CRITICAL
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of servi
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing mu
CVSS 9.9
CVE-2026-61682CRITICAL
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workload
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User,
CVSS 9.9
CVE-2026-77240CRITICAL
WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-leve
WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated use
CVSS 9.9
CVE-2026-75031CRITICAL
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be inje
CVSS 9.8
CVE-2026-84383CRITICAL
libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or
libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_c
CVSS 9.8
CVE-2025-66455CRITICAL
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane
CVSS 9.8
CVE-2026-61550CRITICAL
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JS
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauth
CVSS 9.8
CVE-2026-93659CRITICAL
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in chec
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name,
CVSS 9.3
CVE-2026-81321CRITICAL
CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An
CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 27 critical CVEs — 2026-09-18 20:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-09-18 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.