Vulnfeed

Archives
Log in
Subscribe
September 16, 2026

[vulnfeed] 6 critical CVEs — 2026-09-16 16:00 UTC

vulnfeed Critical alert — 2026-09-16 19:39 UTC
6 new critical CVEs in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-70416CRITICAL
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An un
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, le
CVSS 10.0
CVE-2025-59953CRITICAL
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq
CVSS 9.8
CVE-2026-77411CRITICAL
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returni
CVSS 9.5
CVE-2026-77405CRITICAL
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose def
CVSS 9.4
CVE-2026-77408CRITICAL
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts t
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values lo
CVSS 9.1
CVE-2026-92395CRITICAL
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse prox
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a t
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 34 critical CVEs — 2026-09-16 20:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-09-16 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.