[vulnfeed] 3 critical CVEs — 2026-09-27 20:00 UTC
vulnfeed
Critical alert — 2026-09-27 23:17 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-101065CRITICAL
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker q
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080
CVSS 9.3
CVE-2026-101084CRITICAL
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any a
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Atta
CVSS 9.3
CVE-2026-101090CRITICAL
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oaut
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: