Vulnfeed

Archives
Log in
Subscribe
September 21, 2026

[vulnfeed] 7 critical CVEs — 2026-09-21 20:00 UTC

vulnfeed Critical alert — 2026-09-21 23:32 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-77521CRITICAL
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell to
CVSS 10.0
CVE-2026-94571CRITICAL
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 po
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes c
CVSS 9.4
CVE-2026-94572CRITICAL
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_cip
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configur
CVSS 9.4
CVE-2026-58491CRITICAL
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/ss
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POS
CVSS 9.3
CVE-2026-94424CRITICAL
A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function
A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulat
CVSS 9.3
CVE-2026-46649CRITICAL
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prio
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO
CVSS 9.1
CVE-2026-79916CRITICAL
MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can
MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-09-22 04:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-09-21 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.