[vulnfeed] 3 critical CVEs — 2026-08-28 08:00 UTC
vulnfeed
Critical alert — 2026-08-28 11:34 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-76581CRITICAL
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction betw
CVSS 9.8
CVE-2026-78032CRITICAL
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an att
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
CVSS 9.3
CVE-2026-40541CRITICAL
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extra
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, vi
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: