| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-89448 | iommu/vt-d: Force requesting ACS when tboot is enabled | Linux | Linux | Critical | 9.3 | 2026-09-11 19:43:15 | Deep Dive |
| CVE-2026-81002 | xdp: fix zero-copy frame layout | Linux | Linux | Critical | 9.8 | 2026-09-11 19:42:56 | Deep Dive |
| CVE-2026-80986 | net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages | Linux | Linux | Critical | 9.8 | 2026-09-11 19:42:45 | Deep Dive |
| CVE-2026-80981 | net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() | Linux | Linux | Critical | 9.8 | 2026-09-11 19:42:42 | Deep Dive |
| CVE-2026-80980 | net/smc: stop killed, freed and out_of_sync sharing a byte | Linux | Linux | Critical | 9.8 | 2026-09-11 19:42:41 | Deep Dive |
| CVE-2026-80976 | seg6: reset IP6CB after IPv6 decapsulation | Linux | Linux | Critical | 9.8 | 2026-09-11 19:42:38 | Deep Dive |
| CVE-2026-80945 | crypto: iaa - unmap dst before software fallback on decompress | Linux | Linux | Critical | 9.1 | 2026-09-11 19:42:17 | Deep Dive |
| CVE-2026-80926 | ksmbd: fix use-after-free in oplock break notification | Linux | Linux | Critical | 9.8 | 2026-09-11 19:37:30 | Deep Dive |
| CVE-2026-53952 | GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw | GetSimpleCMS-CE | GetSimpleCMS-CE | Critical | 9.8 | 2026-09-11 19:23:31 | Deep Dive |
| CVE-2026-54072 | Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL | authorizerdev | authorizer | Critical | 9.3 | 2026-09-11 18:41:53 | Deep Dive |
| CVE-2026-62105 🧪 | WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability | ThemeRex | ThemeREX Addons | Critical | 9.8 | 2026-09-11 18:12:04 | Deep Dive |
| CVE-2026-62103 | WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability | wpeverest | Everest Forms | Critical | 9.8 | 2026-09-11 18:12:03 | Deep Dive |
| CVE-2026-82617 | Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns | Apache Software Foundation | Apache OpenNLP | Critical | 10.0 | 2026-09-11 17:50:54 | Deep Dive |
| CVE-2026-72710 | SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection | SPIP | SPIP | Critical | 9.8 | 2026-09-11 16:39:23 | Deep Dive |
| CVE-2026-72709 | SPIP < 4.4.18 Missing Authorization via ecrire/action/ | SPIP | SPIP | Critical | 9.8 | 2026-09-11 16:38:19 | Deep Dive |
| CVE-2026-54047 | Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation | LaciSynchroni | server | Critical | 9.2 | 2026-09-11 16:23:48 | Deep Dive |
| CVE-2026-3869 | Schneider Electric Modicon M580 授权问题漏洞 | Schneider Electric | Modicon M580 | Critical | 9.2 | 2026-09-11 15:13:18 | Deep Dive |
| CVE-2026-89010 | WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server | WAVLINK Technology | WN535M1 | Critical | 9.8 | 2026-09-11 14:57:56 | Deep Dive |
| CVE-2026-89009 | WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server | WAVLINK Technology | WN535M1 | Critical | 9.1 | 2026-09-11 14:56:10 | Deep Dive |
| CVE-2026-87988 | Mistral AI Mistral Vibe 权限许可和访问控制问题漏洞 | mistralai | mistral-vibe | Critical | 10.0 | 2026-09-11 14:35:34 | Deep Dive |