| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-71376 | OS Command Injection Vulnerability in Cosminexus Component Container | Hitachi | Cosminexus Component Container | Critical | 9.8 | 2026-09-08 08:02:13 | Deep Dive |
| CVE-2026-71374 | Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container | Hitachi | Cosminexus Component Container | Critical | 9.8 | 2026-09-08 07:47:29 | Deep Dive |
| CVE-2026-86510 | D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write | D-Link | DIR-822A | Critical | 9.9 | 2026-09-08 01:15:09 | Deep Dive |
| CVE-2026-86509 | D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow | D-Link | DIR-895L | Critical | 9.6 | 2026-09-08 00:45:15 | Deep Dive |
| CVE-2026-76969 | Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) | SAP_SE | SAP Cloud Application Programming Model (CAP) | Critical | 9.4 | 2026-09-08 00:12:56 | Deep Dive |
| CVE-2026-66768 | Improper Access Control in SAP NetWeaver (SAP GUI for Java) | SAP_SE | SAP NetWeaver (SAP GUI for Java) | Critical | 9.0 | 2026-09-08 00:11:16 | Deep Dive |
| CVE-2026-58240 | Missing Authentication check in SAP NetWeaver (Message Server) | SAP_SE | SAP NetWeaver (Message Server) | Critical | 9.8 | 2026-09-08 00:10:55 | Deep Dive |
| CVE-2026-44756 | Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing | SAP_SE | SAP Extended Passport (EPP) Processing | Critical | 10.0 | 2026-09-08 00:10:16 | Deep Dive |
| CVE-2026-86543 | knowns before 0.30.0 Unauthenticated Management API Exposure | knowns-dev | knowns | Critical | 9.8 | 2026-09-07 23:03:21 | Deep Dive |
| CVE-2026-86542 | knowns before 0.30.0 Path Traversal via Import Name | knowns-dev | knowns | Critical | 9.1 | 2026-09-07 23:03:20 | Deep Dive |
| CVE-2026-75650 KEV | Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) | Adobe | Adobe Commerce | Critical | 10.0 | 2026-09-07 20:17:17 | Deep Dive |
| CVE-2026-86480 | JetBrains Hub 授权问题漏洞 | JetBrains | Hub | Critical | 9.8 | 2026-09-07 16:26:42 | Deep Dive |
| CVE-2026-86478 | JetBrains YouTrack 授权问题漏洞 | JetBrains | YouTrack | Critical | 9.8 | 2026-09-07 16:26:41 | Deep Dive |
| CVE-2026-7861 | Code Injection in Next4Biz's CSM (Customer Service Management) | Next4Biz Information Technologies Inc. | CSM (Customer Service Management) | Critical | 9.8 | 2026-09-07 14:19:17 | Deep Dive |
| CVE-2026-18922 | 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property | Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | Critical | 9.8 | 2026-09-07 14:14:54 | Deep Dive |
| CVE-2026-80238 | Dell Secure Connect Gateway 权限许可和访问控制问题漏洞 | Dell | Secure Connect Gateway 5.0 - Application | Critical | 9.3 | 2026-09-07 12:58:20 | Deep Dive |
| CVE-2026-86426 📌 💣 | LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion | librenms | librenms | Critical | 9.2 | 2026-09-07 12:53:48 | Deep Dive |
| CVE-2026-6223 | OTP Bypass in Bahçelievler Muncipality's BiHayat App | Bahçelievler Muncipality | BiHayat App | Critical | 9.4 | 2026-09-07 12:30:26 | Deep Dive |
| CVE-2026-61410 | Dell Secure Connect Gateway 授权问题漏洞 | Dell | Secure Connect Gateway 5.0 - Application | Critical | 9.4 | 2026-09-07 12:24:54 | Deep Dive |
| CVE-2026-76578 | Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci | Red Hat | Red Hat Enterprise Linux 10 | Critical | 9.8 | 2026-09-07 12:01:36 | Deep Dive |