Vulnfeed

Archives
Log in
Subscribe
September 6, 2026

[vulnfeed] 6 critical CVEs — 2026-09-06 04:00 UTC

vulnfeed Critical alert — 2026-09-06 04:53 UTC
6 new critical CVEs in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-86152CRITICAL
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can
CVSS 10.0
CVE-2026-86218CRITICAL
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CVSS 10.0
CVE-2026-16310CRITICAL
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled
CVSS 9.8
CVE-2026-75816CRITICAL
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeov
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value func
CVSS 9.8
CVE-2026-86151CRITICAL
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipul
CVSS 9.4
CVE-2026-86153CRITICAL
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEn
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege mana
CVSS 9.4

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-09-06 12:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-09-05 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.