The National Vulnerability Database (NVD) published 13 CVEs rated Critical under CVSS v3 in the 26 hours to this report. Descriptions below are quoted directly from NVD. Scores are NVD or CNA base scores; always confirm against the vendor advisory before prioritizing.
Critical CVEs (NVD)
| CVE | CVSS | Description (NVD) |
|---|---|---|
| CVE-2026-103244 | 9.8 | ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover. |
| CVE-2026-75957 | 9.8 | The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible `wu_ajax_nopriv_wu_validate_form` AJAX handler accepting a freely obtainable checkout nonce, and the `checkout_form=wu-finish-… |
| CVE-2026-15989 | 9.8 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administr… |
| CVE-2025-41753 | 9.8 | The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise. |
| CVE-2026-18782 | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.
This issue affects Trex MES: through 2026-09-29. |
| CVE-2026-103395 | 9.8 | LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges. |
| CVE-2026-82307 | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection.
This issue affects SOPLOG: before Soplog 2026.9.4.1. |
| CVE-2026-76504 | 9.8 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint.… |
| CVE-2026-103264 | 9.1 | Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration. |
| CVE-2026-92966 | 9.1 | The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Th… |
| CVE-2026-103475 | 9.1 | yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory. |
| CVE-2026-103255 | 9 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security and enabling unauth… |
| CVE-2026-103248 | 9 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request. |
New advisories from CERTs and vendors
Canadian Centre for Cyber Security
Canonical (Ubuntu)
- USN-8858-1: Authen::SASL vulnerability
- USN-8859-1: ImageMagick vulnerabilities
- USN-8855-1: GStreamer Bad Plugins vulnerability
- USN-8856-1: Kdenlive, MLT vulnerability
- USN-8845-1: GVfs vulnerabilities
- USN-8817-3: Linux kernel (AWS) vulnerabilities
- USN-8816-3: Linux kernel (Oracle) vulnerabilities
- USN-8818-5: Linux kernel (NVIDIA Tegra) vulnerabilities
- USN-8854-1: OpenStack Keystone vulnerabilities
- USN-8853-1: OpenSBI vulnerability
- USN-8852-1: OpenVPN vulnerabilities
Cisco PSIRT
- Cisco Advance Notification for Publication of October 7, 2026, Security Advisories
- Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
Microsoft MSRC
- CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
- CVE-2026-62758 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
- CVE-2026-62784 Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability
- CVE-2026-70562 Windows Audio Service Elevation of Privilege Vulnerability
- CVE-2026-69605 Microsoft Install Service Elevation of Privilege Vulnerability
- CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability
- CVE-2026-69451 Windows Management Instrumentation Elevation of Privilege Vulnerability
- CVE-2026-49800 Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
- CVE-2026-65787 Desktop Window Manager Elevation of Privilege Vulnerability
- CVE-2026-61938 Windows Installer Elevation of Privilege Vulnerability
- CVE-2026-70125 Microsoft Office Outlook Remote Code Execution Vulnerability
- CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability
- CVE-2026-69586 Microsoft Windows PDF Remote Code Execution Vulnerability
- CVE-2026-69328 Windows Storage Elevation of Privilege Vulnerability
- CVE-2026-69288 Windows GDI+ Information Disclosure Vulnerability
- CVE-2026-69712 Windows Key Distribution Center Remote Code Execution Vulnerability
- CVE-2026-69504 Windows NTFS Information Disclosure Vulnerability
Debian
CERT-FR
- Multiples vulnérabilités dans les produits Mozilla (30 septembre 2026)
- Multiples vulnérabilités dans HPE Aruba Networking Instant On (30 septembre 2026)
- Multiples vulnérabilités dans Google Chrome (30 septembre 2026)
- Multiples vulnérabilités dans OpenSSL (30 septembre 2026)
- Multiples vulnérabilités dans GitLab (30 septembre 2026)
- Vulnérabilité dans CPython (30 septembre 2026)
