[vulnfeed] 4 critical CVEs — 2026-09-18 04:00 UTC
vulnfeed
Critical alert — 2026-09-18 05:01 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-62874CRITICAL
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate pri
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-69843CRITICAL
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges ov
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-85878CRITICAL
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges ov
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
CVE-2026-93467CRITICAL
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized conten
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: