Vulnfeed

Archives
Log in
Subscribe
August 28, 2026

[vulnfeed] 3 critical CVEs — 2026-08-28 08:00 UTC

vulnfeed Critical alert — 2026-08-28 11:34 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-76581CRITICAL
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction betw
CVSS 9.8
CVE-2026-78032CRITICAL
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an att
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
CVSS 9.3
CVE-2026-40541CRITICAL
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extra
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, vi
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 17 critical CVEs — 2026-08-28 20:00 UTC Older → [vulnfeed] 8 critical CVEs — 2026-08-27 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.