[vulnfeed] 4 critical CVEs — 2026-09-04 04:00 UTC
vulnfeed
Critical alert — 2026-09-04 04:49 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-75754CRITICAL
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Creden
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via a
CVSS 10.0
CVE-2026-85146CRITICAL
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthentica
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the
CVSS 9.3
CVE-2026-85148CRITICAL
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthentica
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
CVSS 9.3
CVE-2026-67402CRITICAL
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is block
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: