[vulnfeed] 3 critical CVEs — 2026-09-16 04:00 UTC
vulnfeed
Critical alert — 2026-09-16 05:05 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-15640CRITICAL
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
CVSS 9.5
CVE-2026-15639CRITICAL
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
CVSS 9.3
CVE-2026-15638CRITICAL
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt dat
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: