Vulnfeed

Archives
Log in
Subscribe
September 16, 2026

[vulnfeed] 3 critical CVEs — 2026-09-16 04:00 UTC

vulnfeed Critical alert — 2026-09-16 05:05 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-15640CRITICAL
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
CVSS 9.5
CVE-2026-15639CRITICAL
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
CVSS 9.3
CVE-2026-15638CRITICAL
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt dat
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 6 critical CVEs — 2026-09-16 16:00 UTC Older → [vulnfeed] 122 critical CVEs — 2026-09-15 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.