Live feed All digests
← 2026-06-21 2026-09-25

Security Digest — 2026-09-25

11972
Total vulnerabilities
671
Critical
4247
High
10
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-93603vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridgeCRITICAL10.0NVD2026-09-18
CVE-2026-93605vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chiCRITICAL10.0NVD2026-09-18
CVE-2026-93606vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host APICRITICAL10.0NVD2026-09-18
CVE-2025-15399IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croCRITICAL10.0NVD2026-09-18
CVE-2026-10747IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due toCRITICAL10.0NVD2026-09-18
CVE-2026-77521MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skilCRITICAL10.0NVD2026-09-21
CVE-2026-80155Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, CRITICAL10.0NVD2026-09-22
CVE-2026-73369Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75699Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75703Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75721Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75723Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary codeCRITICAL10.0NVD2026-09-22
CVE-2026-77244MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, thCRITICAL10.0NVD2026-09-22
CVE-2026-7866Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issCRITICAL10.0NVD2026-09-22
CVE-2026-84412Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-89275Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75745Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrarCRITICAL10.0NVD2026-09-22
CVE-2026-59167SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, theCRITICAL10.0NVD2026-09-23
CVE-2026-86708ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud serviCRITICAL10.0NVD2026-09-23
CVE-2026-97359HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows uCRITICAL10.0NVD2026-09-24
CVE-2026-97360HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticatCRITICAL10.0NVD2026-09-24
CVE-2026-61732Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output ofCRITICAL10.0NVD2026-09-24
CVE-2026-61732Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM contextCRITICAL10.0GitHub2026-09-24
CVE-2026-77244[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty tokenCRITICAL10.0GitHub2026-09-22
CVE-2026-59167SunEditor: Critical XSS vulnerability - sanitizer bypassCRITICAL10.0GitHub2026-09-24
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65770Azure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65801Microsoft Exchange Online Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65816Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69502Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69555Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69836Microsoft Entra ID Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-45480Azure Active Directory Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-06-09
CVE-2026-48567Azure HorizonDB Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-06-09
CVE-2026-62874Azure Billing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-69399Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-69843Microsoft Fabric Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-69865Microsoft Container Registry Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08