[vulnfeed] 5 critical CVEs — 2026-09-24 04:00 UTC
vulnfeed
Critical alert — 2026-09-24 05:12 UTC
5 new critical CVEs
in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-89078CRITICAL
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authentica
CVSS 9.9
CVE-2026-93577CRITICAL
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authentica
CVSS 9.9
CVE-2026-18467CRITICAL
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in al
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals
CVSS 9.8
CVE-2026-96891CRITICAL
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the fi
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname lead
CVSS 9.3
CVE-2026-97055CRITICAL
SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via
SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and C
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: