Live feed All digests
← 2026-06-21 2026-09-05

Security Digest — 2026-09-05

10298
Total vulnerabilities
619
Critical
3488
High
10
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-82456argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller cCRITICAL10.0NVD2026-08-29
CVE-2026-82970Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivaCRITICAL10.0NVD2026-08-31
CVE-2026-81779Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software ICRITICAL10.0NVD2026-08-31
CVE-2026-81780Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.CRITICAL10.0NVD2026-08-31
CVE-2026-84147This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation CRITICAL10.0NVD2026-09-01
CVE-2026-76657Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthCRITICAL10.0NVD2026-09-01
CVE-2026-76658A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticaCRITICAL10.0NVD2026-09-01
CVE-2026-83548A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternCRITICAL10.0NVD2026-09-01
CVE-2026-4357The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as welCRITICAL10.0NVD2026-09-02
CVE-2026-85061MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/doCRITICAL10.0NVD2026-09-03
CVE-2026-70352Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges CRITICAL10.0NVD2026-09-03
CVE-2026-83711Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attackerCRITICAL10.0NVD2026-09-03
CVE-2026-75754Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ACRITICAL10.0NVD2026-09-04
CVE-2026-72811SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (clieCRITICAL10.0GitHub2026-09-03
CVE-2026-69083SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachabCRITICAL10.0GitHub2026-09-03
CVE-2026-69084SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on CRITICAL10.0GitHub2026-09-03
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-57106Data Quality Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58275Azure DNS Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-66803Azure Cosmos DB Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65770Azure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65801Microsoft Exchange Online Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65816Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69502Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69555Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69836Microsoft Entra ID Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2025-29813Azure DevOps Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-05-13
CVE-2022-37968Azure Arc-enabled Kubernetes cluster Connect Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2022-10-11
CVE-2017-20230Storable versions before 3.05 for Perl has a stack overflowCRITICAL10.0Microsoft2026-04-14
CVE-2026-32186Microsoft Bing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-32213Azure AI Foundry Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33105Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33107Azure Databricks Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33819Microsoft Bing Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-04-14