Vulnfeed

Archives
Log in
Subscribe
September 4, 2026

[vulnfeed] 4 critical CVEs — 2026-09-04 04:00 UTC

vulnfeed Critical alert — 2026-09-04 04:49 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-75754CRITICAL
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Creden
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via a
CVSS 10.0
CVE-2026-85146CRITICAL
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthentica
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the
CVSS 9.3
CVE-2026-85148CRITICAL
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthentica
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
CVSS 9.3
CVE-2026-67402CRITICAL
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is block
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 11 critical CVEs — 2026-09-04 16:00 UTC Older → [vulnfeed] 10 critical CVEs — 2026-09-03 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.