Live feed All digests
← 2026-06-21 2026-10-03

Security Digest — 2026-10-03

10389
Total vulnerabilities
599
Critical
4086
High
7
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-97163Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29CRITICAL10.0NVD2026-09-26
CVE-2026-96587The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These crCRITICAL10.0NVD2026-09-29
CVE-2026-71379The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POCRITICAL10.0NVD2026-09-29
CVE-2026-96349Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.CRITICAL10.0NVD2026-09-30
CVE-2026-76570Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The fronCRITICAL10.0NVD2026-09-30
CVE-2026-102427Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.CRITICAL10.0NVD2026-09-30
CVE-2026-55107Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted CRITICAL10.0NVD2026-09-30
CVE-2026-101148The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treCRITICAL10.0NVD2026-10-01
CVE-2026-55393Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLoCRITICAL10.0NVD2026-10-01
CVE-2026-103956Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remotCRITICAL10.0NVD2026-10-02
CVE-2026-69085SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write withCRITICAL10.0GitHub2026-10-01
GHSA-v2f8-6655-7grjVibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chainCRITICAL10.0GitHub2026-10-02
GHSA-jqmf-mx4f-hfr6Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRFCRITICAL10.0GitHub2026-10-02
CVE-2026-92940vm2 exposes host HTTPS credentials and TLS traffic through globalAgentCRITICAL10.0GitHub2026-10-01
CVE-2026-92937vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirectionCRITICAL10.0GitHub2026-10-01
CVE-2026-92941vm2 NodeVM can replace the host process TLS trust storeCRITICAL10.0GitHub2026-10-01
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65770Azure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65801Microsoft Exchange Online Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65816Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69502Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69555Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69836Microsoft Entra ID Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-62874Azure Billing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-69399Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-69843Microsoft Fabric Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-69865Microsoft Container Registry Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-70200Azure Logic Apps Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-70352Azure AI Language Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-83711Microsoft Azure Active Directory B2C Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-83944Azure Logic Apps Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-85889Azure AI Foundry Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-09-08
CVE-2026-32169Azure Cloud Shell Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-03-10
CVE-2025-49752Azure Bastion Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-11-11
CVE-2025-62168Squid vulnerable to information disclosure via authentication credential leakage in error handlingCRITICAL10.0Microsoft2025-10-14
CVE-2025-59503Azure Compute Resource Provider Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-10-14
CVE-2026-82377Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content beloCRITICAL9.9NVD2026-09-28
CVE-2026-85526Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with inCRITICAL9.9NVD2026-09-28