Vulnfeed

Archives
Log in
Subscribe
September 25, 2026

[vulnfeed] 7 critical CVEs — 2026-09-25 20:00 UTC

vulnfeed Critical alert — 2026-09-25 23:25 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-100382CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wi
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This i
CVSS 10.0
CVE-2026-48482CRITICAL
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can us
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the i
CVSS 9.4
CVE-2026-97063CRITICAL
X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET
X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attacker
CVSS 9.3
CVE-2026-97064CRITICAL
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by defaul
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitti
CVSS 9.3
CVE-2026-100389CRITICAL
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's att
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can
CVSS 9.2
CVE-2026-84458CRITICAL
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic accoun
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) id
CVSS 9.1
CVE-2026-100390CRITICAL
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-09-26 04:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-09-25 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.