Vulnfeed

Archives
Log in
Subscribe
September 29, 2026

[vulnfeed] 3 critical CVEs — 2026-09-29 12:00 UTC

vulnfeed Critical alert — 2026-09-29 14:58 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-8065CRITICAL
An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 allows an unau
An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successf
CVSS 9.1
CVE-2026-8066CRITICAL
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauth
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depend
CVSS 9.1
CVE-2026-15390CRITICAL
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete da
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by se
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-09-29 20:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-09-29 00:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.