Live feed All digests
← 2026-06-21 2026-10-06

Security Digest — 2026-10-06

8399
Total vulnerabilities
431
Critical
3154
High
6
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-96587The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These crCRITICAL10.0NVD2026-09-29
CVE-2026-71379The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POCRITICAL10.0NVD2026-09-29
CVE-2026-96349Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.CRITICAL10.0NVD2026-09-30
CVE-2026-76570Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The fronCRITICAL10.0NVD2026-09-30
CVE-2026-102427Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.CRITICAL10.0NVD2026-09-30
CVE-2026-55107Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted CRITICAL10.0NVD2026-09-30
CVE-2026-101148The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treCRITICAL10.0NVD2026-10-01
CVE-2026-55393Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLoCRITICAL10.0NVD2026-10-01
CVE-2026-103956Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remotCRITICAL10.0NVD2026-10-02
CVE-2026-100103Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented deCRITICAL10.0NVD2026-10-05
CVE-2026-69085SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write withCRITICAL10.0GitHub2026-10-01
GHSA-v2f8-6655-7grjVibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chainCRITICAL10.0GitHub2026-10-02
GHSA-jqmf-mx4f-hfr6Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRFCRITICAL10.0GitHub2026-10-02
CVE-2026-100721vm2: NodeVM custom resolution bypasses external path boundariesCRITICAL10.0GitHub2026-10-05
CVE-2026-92955vm2: Sandbox Escape (NodeVM)CRITICAL10.0GitHub2026-10-05
CVE-2026-92953vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fixCRITICAL10.0GitHub2026-10-05
CVE-2026-92946vm2: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCCRITICAL10.0GitHub2026-10-05
CVE-2026-92947vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer poolCRITICAL10.0GitHub2026-10-05
CVE-2026-92956vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypassCRITICAL10.0GitHub2026-10-05
CVE-2026-92940vm2 exposes host HTTPS credentials and TLS traffic through globalAgentCRITICAL10.0GitHub2026-10-01
CVE-2026-92937vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirectionCRITICAL10.0GitHub2026-10-01
CVE-2026-92941vm2 NodeVM can replace the host process TLS trust storeCRITICAL10.0GitHub2026-10-01
CVE-2025-29813Azure DevOps Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-05-13
CVE-2025-54914Azure Networking Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-09-09
CVE-2025-55241Azure Entra ID Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-09-09
CVE-2026-32169Azure Cloud Shell Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-03-10
CVE-2022-49043xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.CRITICAL10.0Microsoft2025-01-14
CVE-2024-56719net: stmmac: fix TSO DMA API usage causing oopsCRITICAL10.0Microsoft2024-12-10
CVE-2025-68121Unexpected session resumption in crypto/tlsCRITICAL10.0Microsoft2026-02-10
CVE-2026-27211Cloud Hypervisor: Host File Exfiltration via QCOW Backing File AbuseCRITICAL10.0Microsoft2026-02-10
CVE-2025-65041Microsoft Partner Center Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-12-09
CVE-2025-65037Azure Container Apps Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2025-12-09
CVE-2026-84154A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through ReleaseCRITICAL9.9NVD2026-09-29
CVE-2026-79901In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-accounCRITICAL9.9NVD2026-10-01
CVE-2026-96658A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCECRITICAL9.9NVD2026-10-01
CVE-2026-93698Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.CRITICAL9.9NVD2026-10-02
CVE-2026-90970GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 1CRITICAL9.9NVD2026-10-02
CVE-2026-105636Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webCRITICAL9.9NVD2026-10-05
CVE-2026-105691Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlleCRITICAL9.9NVD2026-10-05
CVE-2026-105697Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio traCRITICAL9.9NVD2026-10-05