Vulnfeed

Archives
Log in
Subscribe
September 27, 2026

[vulnfeed] 3 critical CVEs — 2026-09-27 20:00 UTC

vulnfeed Critical alert — 2026-09-27 23:17 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-101065CRITICAL
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker q
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080
CVSS 9.3
CVE-2026-101084CRITICAL
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any a
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Atta
CVSS 9.3
CVE-2026-101090CRITICAL
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oaut
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 12 critical CVEs — 2026-09-28 16:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-09-27 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.