[vulnfeed] 3 critical CVEs — 2026-09-03 16:00 UTC
vulnfeed
Critical alert — 2026-09-03 19:20 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-85216CRITICAL
MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to i
MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials.
The custom LdapAuthenticate and LinO
CVSS 9.5
CVE-2026-85181CRITICAL
CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allo
CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for hea
CVSS 9.3
CVE-2026-85183CRITICAL
Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web
Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: