Vulnfeed

Archives
Log in
Subscribe
September 24, 2026

[vulnfeed] 6 critical CVEs — 2026-09-24 20:00 UTC

vulnfeed Critical alert — 2026-09-24 23:18 UTC
6 new critical CVEs in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-13249CRITICAL
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interfa
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker c
CVSS 9.8
CVE-2026-13016CRITICAL
ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. Thi
ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute
CVSS 9.3
CVE-2026-86860CRITICAL
ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platf
ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to
CVSS 9.3
CVE-2026-93291CRITICAL
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle atta
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
CVSS 9.3
CVE-2026-81630CRITICAL
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The up
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integri
CVSS 9.2
CVE-2026-93289CRITICAL
The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker
The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 4 critical CVEs — 2026-09-25 20:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-09-24 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.