Live feed All digests
← 2026-06-21 2026-09-13

Security Digest — 2026-09-13

14056
Total vulnerabilities
657
Critical
5051
High
14
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-75650Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability thaCRITICAL10.0NVD2026-09-07
CVE-2026-44756A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditioCRITICAL10.0NVD2026-09-08
CVE-2026-82004Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS CoCRITICAL10.0NVD2026-09-08
CVE-2026-28659In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could CRITICAL10.0NVD2026-09-08
CVE-2026-49883In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due toCRITICAL10.0NVD2026-09-08
CVE-2026-79696A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through CRITICAL10.0NVD2026-09-09
CVE-2026-85978An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A patCRITICAL10.0NVD2026-09-09
CVE-2026-87827Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfacCRITICAL10.0NVD2026-09-09
CVE-2026-77770The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validCRITICAL10.0NVD2026-09-10
CVE-2026-14560The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a clCRITICAL10.0NVD2026-09-11
CVE-2026-80462A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gainCRITICAL10.0NVD2026-09-11
CVE-2026-87985An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ACRITICAL10.0NVD2026-09-11
CVE-2026-87986An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using sCRITICAL10.0NVD2026-09-11
CVE-2026-87987An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using eCRITICAL10.0NVD2026-09-11
CVE-2026-87988An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commaCRITICAL10.0NVD2026-09-11
CVE-2026-82617The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDCRITICAL10.0NVD2026-09-11
CVE-2026-85706GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1CRITICAL10.0NVD2026-09-12
CVE-2026-59971MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding /CRITICAL10.0GitHub2026-09-11
CVE-2026-85061MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal SkipCRITICAL10.0GitHub2026-09-08
CVE-2017-20230Storable versions before 3.05 for Perl has a stack overflowCRITICAL10.0Microsoft2026-04-14
CVE-2026-32186Microsoft Bing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-32213Azure AI Foundry Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33105Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33107Azure Databricks Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33819Microsoft Bing Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-35431Microsoft Entra ID Entitlement Management Spoofing VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2025-65041Microsoft Partner Center Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-12-09
CVE-2025-65037Azure Container Apps Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2025-12-09
CVE-2025-53767Azure OpenAI Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-08-12
CVE-2026-32169Azure Cloud Shell Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-03-10
CVE-2025-29813Azure DevOps Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-05-13
CVE-2026-70352Azure AI Language Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-83711Microsoft Azure Active Directory B2C Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65770Azure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65801Microsoft Exchange Online Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65816Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69502Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11