[vulnfeed] 3 critical CVEs — 2026-09-02 04:00 UTC
vulnfeed
Critical alert — 2026-09-02 04:49 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-84695CRITICAL
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint t
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers
CVSS 9.3
CVE-2026-84696CRITICAL
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypas
CVSS 9.3
CVE-2026-84699CRITICAL
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account pass
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authentic
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: