Live feed All digests
← 2026-06-21 2026-09-26

Security Digest — 2026-09-26

11928
Total vulnerabilities
562
Critical
4266
High
10
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-77521MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skilCRITICAL10.0NVD2026-09-21
CVE-2026-80155Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, CRITICAL10.0NVD2026-09-22
CVE-2026-73369Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75699Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75703Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75721Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75723Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary codeCRITICAL10.0NVD2026-09-22
CVE-2026-77244MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, thCRITICAL10.0NVD2026-09-22
CVE-2026-7866Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issCRITICAL10.0NVD2026-09-22
CVE-2026-84412Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-89275Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability tCRITICAL10.0NVD2026-09-22
CVE-2026-75745Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrarCRITICAL10.0NVD2026-09-22
CVE-2026-59167SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, theCRITICAL10.0NVD2026-09-23
CVE-2026-86708ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud serviCRITICAL10.0NVD2026-09-23
CVE-2026-97359HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows uCRITICAL10.0NVD2026-09-24
CVE-2026-97360HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticatCRITICAL10.0NVD2026-09-24
CVE-2026-61732Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output ofCRITICAL10.0NVD2026-09-24
CVE-2026-100382Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia FoCRITICAL10.0NVD2026-09-25
CVE-2026-61732Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM contextCRITICAL10.0GitHub2026-09-24
CVE-2026-77244[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty tokenCRITICAL10.0GitHub2026-09-22
CVE-2026-59167SunEditor: Critical XSS vulnerability - sanitizer bypassCRITICAL10.0GitHub2026-09-24
CVE-2026-32186Microsoft Bing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-32213Azure AI Foundry Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33105Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33107Azure Databricks Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33819Microsoft Bing Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-35431Microsoft Entra ID Entitlement Management Spoofing VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2017-20230Storable versions before 3.05 for Perl has a stack overflowCRITICAL10.0Microsoft2026-04-14
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65770Azure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65801Microsoft Exchange Online Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65816Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69502Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69555Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69836Microsoft Entra ID Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-62874Azure Billing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-69399Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-69843Microsoft Fabric Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08