Vulnfeed

Archives
Log in
Subscribe
September 21, 2026

[vulnfeed] 3 critical CVEs — 2026-09-21 20:00 UTC

vulnfeed Critical alert — 2026-09-21 20:30 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-79920CRITICAL
Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /
Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins
CVSS 9.9
CVE-2026-85751CRITICAL
Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mai
Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER
CVSS 9.8
CVE-2026-61674CRITICAL
Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. F
Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the serve
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 7 critical CVEs — 2026-09-21 20:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-09-20 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.