| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-89783 | xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full | Linux | Linux | Critical | 9.8 | 2026-09-16 08:48:22 | Deep Dive |
| CVE-2026-89779 | fs/ntfs3: validate ef->size covers the record's name and value | Linux | Linux | Critical | 9.1 | 2026-09-16 08:48:19 | Deep Dive |
| CVE-2026-89778 | isofs: fix out-of-bounds page array access on empty zisofs block | Linux | Linux | Critical | 9.8 | 2026-09-16 08:48:18 | Deep Dive |
| CVE-2026-89775 | KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation | Linux | Linux | Critical | 9.3 | 2026-09-16 08:39:16 | Deep Dive |
| CVE-2026-81642 | Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY | NLnet Labs | Unbound | Critical | 9.1 | 2026-09-16 08:30:59 | Deep Dive |
| CVE-2026-27565 | Remote code execution via uploading a malicious IODD file | Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D | Critical | 9.8 | 2026-09-16 07:52:23 | Deep Dive |
| CVE-2026-27546 | Authentication Bypass in _account_log | Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D | Critical | 9.8 | 2026-09-16 07:48:15 | Deep Dive |
| CVE-2026-73447 | Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request | Arista Networks | EOS | Critical | 9.1 | 2026-09-16 06:04:26 | Deep Dive |
| CVE-2026-12793 | JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | Critical | 9.8 | 2026-09-16 03:28:19 | Deep Dive |
| CVE-2026-14349 | TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action | themetechmount | TrueBooker – Appointment Booking and Scheduler System | Critical | 9.8 | 2026-09-16 03:28:18 | Deep Dive |
| CVE-2026-15640 | Authentication Bypass via SAML Response Manipulation | Delinea | Secret Server (On-Prem) | Critical | 9.5 | 2026-09-15 23:22:15 | Deep Dive |
| CVE-2026-15639 | Reflected Cross-Site Scripting | Delinea | Secret Server (On-Prem) | Critical | 9.3 | 2026-09-15 23:21:38 | Deep Dive |
| CVE-2026-15638 | Cryptographic Padding Oracle | Delinea | Secret Server (On-Prem) | Critical | 9.1 | 2026-09-15 23:20:56 | Deep Dive |
| CVE-2026-73807 | mySCADA myPRO Manager Missing Authorization | mySCADA Technologies | mySCADA myPRO | Critical | 9.8 | 2026-09-15 21:42:56 | Deep Dive |
| CVE-2026-81855 | Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key | Wärtsilä | FOS-Onboard | Critical | 9.1 | 2026-09-15 21:32:00 | Deep Dive |
| CVE-2026-78225 | Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key | Wärtsilä | FOS-Onboard | Critical | 9.0 | 2026-09-15 21:29:44 | Deep Dive |
| CVE-2026-61560 | @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover | zereight | gitlab-mcp | Critical | 9.8 | 2026-09-15 21:09:00 | Deep Dive |
| CVE-2026-73437 | On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper/destinat | Arista Networks | EOS | Critical | 9.6 | 2026-09-15 21:02:49 | Deep Dive |
| CVE-2026-68491 | 符号链接导致任意文件覆写的检查不足 | Webpros | SolusVM | Critical | 9.4 | 2026-09-15 20:59:50 | Deep Dive |
| CVE-2026-61559 | @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery | zereight | gitlab-mcp | Critical | 9.6 | 2026-09-15 20:58:42 | Deep Dive |