| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-79696 | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through | CRITICAL | 10.0 | NVD | 2026-09-09 |
| CVE-2026-85978 | An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A pat | CRITICAL | 10.0 | NVD | 2026-09-09 |
| CVE-2026-87827 | Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfac | CRITICAL | 10.0 | NVD | 2026-09-09 |
| CVE-2026-77770 | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a valid | CRITICAL | 10.0 | NVD | 2026-09-10 |
| CVE-2026-14560 | The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a cl | CRITICAL | 10.0 | NVD | 2026-09-11 |
| CVE-2026-80462 | A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain | CRITICAL | 10.0 | NVD | 2026-09-11 |
| CVE-2026-87985 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using A | CRITICAL | 10.0 | NVD | 2026-09-11 |
| CVE-2026-87986 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using s | CRITICAL | 10.0 | NVD | 2026-09-11 |
| CVE-2026-87987 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using e | CRITICAL | 10.0 | NVD | 2026-09-11 |
| CVE-2026-87988 | An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through comma | CRITICAL | 10.0 | NVD | 2026-09-11 |
| CVE-2026-82617 | The two built-in name-finder patterns exposed by
opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FIND | CRITICAL | 10.0 | NVD | 2026-09-11 |
| CVE-2026-85706 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1 | CRITICAL | 10.0 | NVD | 2026-09-12 |
| CVE-2026-81648 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX | CRITICAL | 10.0 | NVD | 2026-09-13 |
| CVE-2026-82434 | Description
When ZooKeeper authentication is configured, Storm deliberately retains
`storm.zookeeper.topology.auth.payl | CRITICAL | 10.0 | NVD | 2026-09-14 |
| CVE-2026-59971 | MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2 | CRITICAL | 10.0 | NVD | 2026-09-15 |
| CVE-2026-53710 | MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sa | CRITICAL | 10.0 | NVD | 2026-09-15 |
| CVE-2026-71133 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 10.0 | NVD | 2026-09-15 |
| CVE-2026-83020 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third | CRITICAL | 10.0 | NVD | 2026-09-15 |
| CVE-2026-83021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported v | CRITICAL | 10.0 | NVD | 2026-09-15 |
| CVE-2026-83059 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 10.0 | NVD | 2026-09-15 |
| CVE-2026-83099 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 10.0 | NVD | 2026-09-15 |
| CVE-2026-87230 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 10.0 | NVD | 2026-09-15 |
| CVE-2026-59971 | MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / | CRITICAL | 10.0 | GitHub | 2026-09-11 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65770 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65801 | Microsoft Exchange Online Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65816 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-69502 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-69555 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-69836 | Microsoft Entra ID Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-70352 | Azure AI Language Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |