[vulnfeed] 7 critical CVEs — 2026-09-02 16:00 UTC
vulnfeed
Critical alert — 2026-09-02 19:25 UTC
7 new critical CVEs
in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-4357CRITICAL
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plug
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to u
CVSS 10.0
CVE-2026-77009CRITICAL
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which exe
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to ru
CVSS 9.9
CVE-2025-9314CRITICAL
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerabi
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
CVSS 9.8
CVE-2026-53611CRITICAL
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fron
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC
CVSS 9.8
CVE-2026-72920CRITICAL
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
### Impact
The filer registered the IAM gRPC service (`SeaweedIdentityAccessManagement`) with no authentication. Any client able to reach the filer gRPC port could invoke IAM RPCs — `CreateUser`, `Cre
CVSS 9.8
CVE-2026-78689CRITICAL
Description
NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, rea
Description
NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trig
CVSS 9.2
CVE-2026-82955CRITICAL
In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD i
In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: