| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-59167 | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the | CRITICAL | 10.0 | NVD | 2026-09-23 |
| CVE-2026-86708 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud servi | CRITICAL | 10.0 | NVD | 2026-09-23 |
| CVE-2026-97359 | HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows u | CRITICAL | 10.0 | NVD | 2026-09-24 |
| CVE-2026-97360 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticat | CRITICAL | 10.0 | NVD | 2026-09-24 |
| CVE-2026-61732 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of | CRITICAL | 10.0 | NVD | 2026-09-24 |
| CVE-2026-100382 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Fo | CRITICAL | 10.0 | NVD | 2026-09-25 |
| CVE-2026-97163 | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | CRITICAL | 10.0 | NVD | 2026-09-26 |
| CVE-2026-96587 | The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These cr | CRITICAL | 10.0 | NVD | 2026-09-29 |
| CVE-2026-71379 | The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted PO | CRITICAL | 10.0 | NVD | 2026-09-29 |
| CVE-2026-61732 | Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context | CRITICAL | 10.0 | GitHub | 2026-09-24 |
| CVE-2026-59167 | SunEditor: Critical XSS vulnerability - sanitizer bypass | CRITICAL | 10.0 | GitHub | 2026-09-24 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2025-62168 | Squid vulnerable to information disclosure via authentication credential leakage in error handling | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2025-59503 | Azure Compute Resource Provider Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2025-53767 | Azure OpenAI Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-08-12 |
| CVE-2025-29813 | Azure DevOps Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-05-13 |
| CVE-2025-65041 | Microsoft Partner Center Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-12-09 |
| CVE-2025-65037 | Azure Container Apps Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-12-09 |
| CVE-2026-45480 | Azure Active Directory Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-06-09 |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-06-09 |
| CVE-2026-32169 | Azure Cloud Shell Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-03-10 |
| CVE-2026-19599 | ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability | CRITICAL | 9.9 | NVD | 2026-09-23 |
| CVE-2026-77602 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. | CRITICAL | 9.9 | NVD | 2026-09-23 |
| CVE-2026-84474 | A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The provisioning-callback secret (host | CRITICAL | 9.9 | NVD | 2026-09-23 |
| CVE-2026-84502 | A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The Project scm_url field is not valid | CRITICAL | 9.9 | NVD | 2026-09-23 |
| CVE-2026-84719 | A flaw was found in the Ansible Automation Platform automation-controller. When a
WorkflowJobTemplate is copied, the dee | CRITICAL | 9.9 | NVD | 2026-09-23 |
| CVE-2026-89078 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1 | CRITICAL | 9.9 | NVD | 2026-09-24 |
| CVE-2026-93577 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1 | CRITICAL | 9.9 | NVD | 2026-09-24 |
| CVE-2026-19072 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each e | CRITICAL | 9.9 | NVD | 2026-09-24 |
| CVE-2026-93425 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC proc | CRITICAL | 9.9 | NVD | 2026-09-24 |
| CVE-2026-82377 | Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belo | CRITICAL | 9.9 | NVD | 2026-09-28 |
| CVE-2026-85526 | Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with in | CRITICAL | 9.9 | NVD | 2026-09-28 |
| CVE-2026-87799 | Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, | CRITICAL | 9.9 | NVD | 2026-09-28 |
| CVE-2026-84154 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release | CRITICAL | 9.9 | NVD | 2026-09-29 |