Live feed All digests
← 2026-06-21 2026-10-02

Security Digest — 2026-10-02

9730
Total vulnerabilities
479
Critical
3650
High
8
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-100382Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia FoCRITICAL10.0NVD2026-09-25
CVE-2026-97163Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29CRITICAL10.0NVD2026-09-26
CVE-2026-96587The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These crCRITICAL10.0NVD2026-09-29
CVE-2026-71379The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POCRITICAL10.0NVD2026-09-29
CVE-2026-96349Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.CRITICAL10.0NVD2026-09-30
CVE-2026-76570Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The fronCRITICAL10.0NVD2026-09-30
CVE-2026-102427Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.CRITICAL10.0NVD2026-09-30
CVE-2026-55107Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted CRITICAL10.0NVD2026-09-30
CVE-2026-101148The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treCRITICAL10.0NVD2026-10-01
CVE-2026-55393Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLoCRITICAL10.0NVD2026-10-01
CVE-2026-69085SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write withCRITICAL10.0GitHub2026-10-01
CVE-2026-92940vm2 exposes host HTTPS credentials and TLS traffic through globalAgentCRITICAL10.0GitHub2026-10-01
CVE-2026-92937vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirectionCRITICAL10.0GitHub2026-10-01
CVE-2026-92941vm2 NodeVM can replace the host process TLS trust storeCRITICAL10.0GitHub2026-10-01
CVE-2025-53767Azure OpenAI Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-08-12
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-57106Data Quality Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58275Azure DNS Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-66803Azure Cosmos DB Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2025-55241Azure Entra ID Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-09-09
CVE-2025-54914Azure Networking Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-09-09
CVE-2024-24576Rusts's `std::process::Command` did not properly escape arguments of batch files on WindowsCRITICAL10.0Microsoft2024-04-09
CVE-2025-62168Squid vulnerable to information disclosure via authentication credential leakage in error handlingCRITICAL10.0Microsoft2025-10-14
CVE-2025-59503Azure Compute Resource Provider Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-10-14
CVE-2022-49043xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.CRITICAL10.0Microsoft2025-01-14
CVE-2026-82377Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content beloCRITICAL9.9NVD2026-09-28
CVE-2026-85526Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with inCRITICAL9.9NVD2026-09-28
CVE-2026-87799Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10,CRITICAL9.9NVD2026-09-28
CVE-2026-84154A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through ReleaseCRITICAL9.9NVD2026-09-29
CVE-2026-79901In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-accounCRITICAL9.9NVD2026-10-01
CVE-2026-96658A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCECRITICAL9.9NVD2026-10-01
CVE-2026-92948vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escapeCRITICAL9.9GitHub2026-10-01
CVE-2026-92951vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host PackageCRITICAL9.9GitHub2026-10-01
CVE-2026-92957vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_processCRITICAL9.9GitHub2026-10-01
CVE-2026-92938vm2 allows a sandboxed plugin to execute native code through `node:sqlite`CRITICAL9.9GitHub2026-10-01
CVE-2026-92939vm2 crypto builtin loads attacker native code through setEngineCRITICAL9.9GitHub2026-10-01
CVE-2025-49747Azure Machine Learning Elevation of Privilege VulnerabilityCRITICAL9.9Microsoft2025-07-08