| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-62104 | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-92937 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for G | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-92940 | vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is e | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-92941 | vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-92946 | vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit re | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-92947 | vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-92955 | vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ g | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-92956 | vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-92960 | vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandb | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-54734 | Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-suppl | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-69399 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-69865 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elev | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-70200 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-83944 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-85889 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges o | CRITICAL | 10.0 | NVD | 2026-09-17 |
| CVE-2026-62874 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges ov | CRITICAL | 10.0 | NVD | 2026-09-18 |
| CVE-2026-69843 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwo | CRITICAL | 10.0 | NVD | 2026-09-18 |
| CVE-2026-93603 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge | CRITICAL | 10.0 | NVD | 2026-09-18 |
| CVE-2026-93605 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chi | CRITICAL | 10.0 | NVD | 2026-09-18 |
| CVE-2026-93606 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API | CRITICAL | 10.0 | NVD | 2026-09-18 |
| CVE-2025-15399 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | CRITICAL | 10.0 | NVD | 2026-09-18 |
| CVE-2026-10747 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to | CRITICAL | 10.0 | NVD | 2026-09-18 |
| CVE-2026-77521 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skil | CRITICAL | 10.0 | NVD | 2026-09-21 |
| CVE-2026-80155 | Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB88 | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-73369 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-75699 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-75703 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-75721 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-75723 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-77244 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-7866 | Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This iss | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-84412 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-89275 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability t | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-75745 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrar | CRITICAL | 10.0 | NVD | 2026-09-22 |
| CVE-2026-59167 | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the | CRITICAL | 10.0 | NVD | 2026-09-23 |
| CVE-2026-86708 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud servi | CRITICAL | 10.0 | NVD | 2026-09-23 |
| CVE-2026-77244 | [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token | CRITICAL | 10.0 | GitHub | 2026-09-22 |
| CVE-2026-62874 | Azure Billing Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-69399 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-69843 | Microsoft Fabric Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |