Live feed All digests
← 2026-06-21 2026-09-17

Security Digest — 2026-09-17

14465
Total vulnerabilities
919
Critical
5547
High
10
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-77770The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validCRITICAL10.0NVD2026-09-10
CVE-2026-14560The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a clCRITICAL10.0NVD2026-09-11
CVE-2026-80462A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gainCRITICAL10.0NVD2026-09-11
CVE-2026-87985An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ACRITICAL10.0NVD2026-09-11
CVE-2026-87986An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using sCRITICAL10.0NVD2026-09-11
CVE-2026-87987An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using eCRITICAL10.0NVD2026-09-11
CVE-2026-87988An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commaCRITICAL10.0NVD2026-09-11
CVE-2026-82617The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDCRITICAL10.0NVD2026-09-11
CVE-2026-85706GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1CRITICAL10.0NVD2026-09-12
CVE-2026-81648The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX CRITICAL10.0NVD2026-09-13
CVE-2026-82434Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.paylCRITICAL10.0NVD2026-09-14
CVE-2026-65381A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the proCRITICAL10.0NVD2026-09-14
CVE-2026-59971MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2CRITICAL10.0NVD2026-09-15
CVE-2026-53710MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_saCRITICAL10.0NVD2026-09-15
CVE-2026-71133Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL10.0NVD2026-09-15
CVE-2026-83020Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized ThirdCRITICAL10.0NVD2026-09-15
CVE-2026-83021Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported vCRITICAL10.0NVD2026-09-15
CVE-2026-83059Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL10.0NVD2026-09-15
CVE-2026-83099Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL10.0NVD2026-09-15
CVE-2026-87230Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL10.0NVD2026-09-15
CVE-2026-70416Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticaCRITICAL10.0NVD2026-09-16
CVE-2026-20130As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISECRITICAL10.0NVD2026-09-16
CVE-2026-20192As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISECRITICAL10.0NVD2026-09-16
CVE-2026-76423A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain aCRITICAL10.0NVD2026-09-16
CVE-2026-92808A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unCRITICAL10.0NVD2026-09-16
CVE-2026-76460A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypCRITICAL10.0NVD2026-09-16
CVE-2026-59971MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding /CRITICAL10.0GitHub2026-09-11
CVE-2026-70352Azure AI Language Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-83711Microsoft Azure Active Directory B2C Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65770Azure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65801Microsoft Exchange Online Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65816Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69502Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69555Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69836Microsoft Entra ID Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14