Live feed All digests
← 2026-06-21 2026-09-30

Security Digest — 2026-09-30

10477
Total vulnerabilities
476
Critical
3611
High
8
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-59167SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, theCRITICAL10.0NVD2026-09-23
CVE-2026-86708ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud serviCRITICAL10.0NVD2026-09-23
CVE-2026-97359HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows uCRITICAL10.0NVD2026-09-24
CVE-2026-97360HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticatCRITICAL10.0NVD2026-09-24
CVE-2026-61732Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output ofCRITICAL10.0NVD2026-09-24
CVE-2026-100382Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia FoCRITICAL10.0NVD2026-09-25
CVE-2026-97163Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29CRITICAL10.0NVD2026-09-26
CVE-2026-96587The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These crCRITICAL10.0NVD2026-09-29
CVE-2026-71379The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POCRITICAL10.0NVD2026-09-29
CVE-2026-61732Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM contextCRITICAL10.0GitHub2026-09-24
CVE-2026-59167SunEditor: Critical XSS vulnerability - sanitizer bypassCRITICAL10.0GitHub2026-09-24
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-57106Data Quality Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58275Azure DNS Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-66803Azure Cosmos DB Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2025-62168Squid vulnerable to information disclosure via authentication credential leakage in error handlingCRITICAL10.0Microsoft2025-10-14
CVE-2025-59503Azure Compute Resource Provider Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-10-14
CVE-2025-53767Azure OpenAI Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-08-12
CVE-2025-29813Azure DevOps Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-05-13
CVE-2025-65041Microsoft Partner Center Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-12-09
CVE-2025-65037Azure Container Apps Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2025-12-09
CVE-2026-45480Azure Active Directory Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-06-09
CVE-2026-48567Azure HorizonDB Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-06-09
CVE-2026-32169Azure Cloud Shell Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-03-10
CVE-2026-19599ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerabilityCRITICAL9.9NVD2026-09-23
CVE-2026-77602OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. CRITICAL9.9NVD2026-09-23
CVE-2026-84474A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (hostCRITICAL9.9NVD2026-09-23
CVE-2026-84502A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validCRITICAL9.9NVD2026-09-23
CVE-2026-84719A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deeCRITICAL9.9NVD2026-09-23
CVE-2026-89078GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1CRITICAL9.9NVD2026-09-24
CVE-2026-93577GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 1CRITICAL9.9NVD2026-09-24
CVE-2026-19072Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each eCRITICAL9.9NVD2026-09-24
CVE-2026-93425Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procCRITICAL9.9NVD2026-09-24
CVE-2026-82377Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content beloCRITICAL9.9NVD2026-09-28
CVE-2026-85526Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with inCRITICAL9.9NVD2026-09-28
CVE-2026-87799Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10,CRITICAL9.9NVD2026-09-28
CVE-2026-84154A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through ReleaseCRITICAL9.9NVD2026-09-29