Vulnfeed

Archives
Log in
Subscribe
September 2, 2026

[vulnfeed] 7 critical CVEs — 2026-09-02 16:00 UTC

vulnfeed Critical alert — 2026-09-02 19:25 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-4357CRITICAL
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plug
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to u
CVSS 10.0
CVE-2026-77009CRITICAL
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which exe
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to ru
CVSS 9.9
CVE-2025-9314CRITICAL
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerabi
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
CVSS 9.8
CVE-2026-53611CRITICAL
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fron
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC
CVSS 9.8
CVE-2026-72920CRITICAL
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
### Impact The filer registered the IAM gRPC service (`SeaweedIdentityAccessManagement`) with no authentication. Any client able to reach the filer gRPC port could invoke IAM RPCs — `CreateUser`, `Cre
CVSS 9.8
CVE-2026-78689CRITICAL
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, rea
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trig
CVSS 9.2
CVE-2026-82955CRITICAL
In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD i
In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 6 critical CVEs — 2026-09-02 20:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-09-02 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.