[vulnfeed] 4 critical CVEs — 2026-09-07 20:00 UTC
vulnfeed
Critical alert — 2026-09-07 20:02 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-18922CRITICAL
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyru
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connectio
CVSS 9.8
CVE-2026-7861CRITICAL
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Servic
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection.
This issue affects CSM (Customer Service Management)
CVSS 9.8
CVE-2026-86478CRITICAL
In JetBrains YouTrack before 2025.3.161254,
2026.1.14042 improper authentication in YouTrack Helpdesk allowed
In JetBrains YouTrack before 2025.3.161254,
2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address
CVSS 9.8
CVE-2026-86480CRITICAL
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain sup
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
CVSS 9.8
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: