[vulnfeed] 6 critical CVEs — 2026-09-04 20:00 UTC
vulnfeed
Critical alert — 2026-09-04 22:25 UTC
6 new critical CVEs
in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-75913HIGH
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 9a34b5034d29f05
CVSS 9.3
CVE-2026-9317CRITICAL
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unau
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start p
CVSS 9.2
CVE-2026-78327CRITICAL
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authe
CVSS 9.1
CVE-2026-78328CRITICAL
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management inter
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
CVSS 9.1
CVE-2026-81939CRITICAL
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive proce
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination d
CVSS 9.1
CVE-2026-73842CRITICAL
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane
### Summary
The OpenChoreo control-plane cluster-gateway exposes internal management APIs (`/api/proxy/`, `/api/exec/`, `/api/wirelogs/`) that tunnel requests through to connected data planes' Kubern
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: