Vulnfeed

Archives
Log in
Subscribe
September 1, 2026

[vulnfeed] 9 critical CVEs — 2026-09-01 12:00 UTC

vulnfeed Critical alert — 2026-09-01 13:34 UTC
9 new critical CVEs in the last 5 hours — 9 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-84147CRITICAL
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type v
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulne
CVSS 10.0
CVE-2026-18550CRITICAL
The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover
The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token vali
CVSS 9.8
CVE-2026-18765CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before
CVSS 9.8
CVE-2026-4813CRITICAL
A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticate
A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT processing configuration does not
CVSS 9.4
CVE-2026-84200CRITICAL
Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mod
Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence,
CVSS 9.4
CVE-2023-54356CRITICAL
Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA an
Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vu
CVSS 9.3
CVE-2026-84189CRITICAL
LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-co
LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without
CVSS 9.2
CVE-2026-84148CRITICAL
This vulnerability exists in the ERP system due to improper authentication and authorization controls in the A
This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipu
CVSS 9.2
CVE-2026-84149CRITICAL
This vulnerability exists in the ERP system due to exposure of repository information through a publicly acces
This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-09-01 16:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-09-01 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.