Vulnfeed

Archives
Log in
Subscribe
September 16, 2026

[vulnfeed] 34 critical CVEs — 2026-09-16 20:00 UTC

vulnfeed Critical alert — 2026-09-16 23:11 UTC
34 new critical CVEs in the last 5 hours — 1 actively exploited (CISA KEV) · 34 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-76460CRITICAL KEV
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attac
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication
CVSS 10.0
CVE-2026-20130CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services E
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have con
CVSS 10.0
CVE-2026-20192CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services E
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have cond
CVSS 10.0
CVE-2026-76423CRITICAL
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the
CVSS 10.0
CVE-2026-92808CRITICAL
A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Ser
A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP reque
CVSS 10.0
CVE-2026-20322CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbs
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review res
CVSS 9.9
CVE-2026-20324CRITICAL
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary command
CVSS 9.9
CVE-2026-20325CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbs
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review res
CVSS 9.9
CVE-2026-20329CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Sec
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure F
CVSS 9.9
CVE-2026-20330CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Sec
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure F
CVSS 9.9
CVE-2026-20332CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Sec
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure F
CVSS 9.9
CVE-2026-20242CRITICAL
A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Softw
A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as 
CVSS 9.8
CVE-2026-20326CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard eng
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted
CVSS 9.8
CVE-2026-92717CRITICAL
Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenti
Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can u
CVSS 9.3
CVE-2026-92720CRITICAL
Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthe
Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve stored
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 6 critical CVEs — 2026-09-17 16:00 UTC Older → [vulnfeed] 6 critical CVEs — 2026-09-16 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.