Live feed All digests
← 2026-06-21 2026-09-23

Security Digest — 2026-09-23

14164
Total vulnerabilities
804
Critical
5188
High
11
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-70416Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticaCRITICAL10.0NVD2026-09-16
CVE-2026-20130As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISECRITICAL10.0NVD2026-09-16
CVE-2026-20192As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISECRITICAL10.0NVD2026-09-16
CVE-2026-76423A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain aCRITICAL10.0NVD2026-09-16
CVE-2026-92808A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unCRITICAL10.0NVD2026-09-16
CVE-2026-76460A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypCRITICAL10.0NVD2026-09-16
CVE-2026-62104Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.CRITICAL10.0NVD2026-09-17
CVE-2026-92937vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GCRITICAL10.0NVD2026-09-17
CVE-2026-92940vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is eCRITICAL10.0NVD2026-09-17
CVE-2026-92941vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tlsCRITICAL10.0NVD2026-09-17
CVE-2026-92946vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit reCRITICAL10.0NVD2026-09-17
CVE-2026-92947vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by BufferCRITICAL10.0NVD2026-09-17
CVE-2026-92955vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ gCRITICAL10.0NVD2026-09-17
CVE-2026-92956vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on CRITICAL10.0NVD2026-09-17
CVE-2026-92960vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbCRITICAL10.0NVD2026-09-17
CVE-2026-54734Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplCRITICAL10.0NVD2026-09-17
CVE-2026-69399Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0NVD2026-09-17
CVE-2026-69865Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevCRITICAL10.0NVD2026-09-17
CVE-2026-70200Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorizeCRITICAL10.0NVD2026-09-17
CVE-2026-83944Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.CRITICAL10.0NVD2026-09-17
CVE-2026-85889Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges oCRITICAL10.0NVD2026-09-17
CVE-2026-62874Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges ovCRITICAL10.0NVD2026-09-18
CVE-2026-69843Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwoCRITICAL10.0NVD2026-09-18
CVE-2026-93603vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridgeCRITICAL10.0NVD2026-09-18
CVE-2026-93605vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chiCRITICAL10.0NVD2026-09-18
CVE-2026-93606vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host APICRITICAL10.0NVD2026-09-18
CVE-2025-15399IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croCRITICAL10.0NVD2026-09-18
CVE-2026-10747IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due toCRITICAL10.0NVD2026-09-18
CVE-2026-77521MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skilCRITICAL10.0NVD2026-09-21
CVE-2026-80155Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB88CRITICAL10.0NVD2026-09-22
CVE-2026-73369Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75699Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75703Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75721Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75723Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary codeCRITICAL10.0NVD2026-09-22
CVE-2026-77244MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, thCRITICAL10.0NVD2026-09-22
CVE-2026-7866Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issCRITICAL10.0NVD2026-09-22
CVE-2026-84412Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-89275Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75745Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrarCRITICAL10.0NVD2026-09-22