Vulnfeed

Archives
Log in
Subscribe
September 20, 2026

[vulnfeed] 4 critical CVEs — 2026-09-20 20:00 UTC

vulnfeed Critical alert — 2026-09-20 22:37 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-88856CRITICAL
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery e
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_os
CVSS 9.4
CVE-2026-88857CRITICAL
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery e
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into
CVSS 9.4
CVE-2026-88854CRITICAL
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Jooml
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsear
CVSS 9.3
CVE-2026-94089CRITICAL
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulatio
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-09-21 20:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-09-20 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.