Vulnfeed

Archives
Log in
Subscribe
September 17, 2026

[vulnfeed] 6 critical CVEs — 2026-09-17 16:00 UTC

vulnfeed Critical alert — 2026-09-17 19:48 UTC
6 new critical CVEs in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-86863CRITICAL
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or re
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuth
CVSS 9.3
CVE-2026-79752CRITICAL
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsB
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder:
CVSS 9.2
CVE-2026-76834CRITICAL
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negativ
CVSS 9.2
CVE-2026-63472CRITICAL
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCust
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authenti
CVSS 9.1
CVE-2026-88952CRITICAL
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs. AshAuthentic
CVSS 9.1
CVE-2026-91039CRITICAL
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who oper
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a loca
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
Older → [vulnfeed] 34 critical CVEs — 2026-09-16 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.