Vulnfeed

Archives
Log in
Subscribe
September 24, 2026

[vulnfeed] 4 critical CVEs — 2026-09-24 20:00 UTC

vulnfeed Critical alert — 2026-09-24 20:03 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-93425CRITICAL
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/rou
CVSS 9.9
CVE-2026-81549CRITICAL
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive in
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.
CVSS 9.6
CVE-2026-90481CRITICAL
In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypas
In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.
CVSS 9.2
CVE-2026-97404CRITICAL
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request wit
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target pro
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 6 critical CVEs — 2026-09-24 20:00 UTC Older → [vulnfeed] 5 critical CVEs — 2026-09-24 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.