The National Vulnerability Database (NVD) published 8 CVEs rated Critical under CVSS v3 in the 26 hours to this report. Descriptions below are quoted directly from NVD. Scores are NVD or CNA base scores; always confirm against the vendor advisory before prioritizing.
Critical CVEs (NVD)
| CVE | CVSS | Description (NVD) |
|---|---|---|
| CVE-2026-104610 | 10 | A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. |
| CVE-2026-82041 | 9.9 | UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, resulting in command e… |
| CVE-2026-82042 | 9.8 | UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtain the key value can… |
| CVE-2023-54405 | 9.8 | H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token parameter to upload a… |
| CVE-2026-19652 | 9.8 | The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes… |
| CVE-2026-92084 | 9.1 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation req… |
| CVE-2026-87115 | 9.1 | The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exp… |
| CVE-2026-104611 | 9.1 | A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
New advisories from CERTs and vendors
Microsoft MSRC
- Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE
- CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability
Cisco PSIRT
Canadian Centre for Cyber Security
- [Control Systems] Moxa security advisory (AV26-995)
- GitLab security advisory (AV26-994)
- [Control systems] Hitachi security advisory (AV26-993)
- MikroTik security advisory (AV26-992)
- [Control Systems] Johnson Controls security advisory (AV26-991)
- WatchGuard security advisory (AV26-990)
Debian
- DSA-6539-1 php-mongodb – security update
- DSA-6540-1 radsecproxy – security update
- DSA-6538-1 redis – security update
- DSA-6534-2 webkit2gtk – regression update
- DSA-6534-1 webkit2gtk – security update
- DSA-6535-1 chromium – security update
- DSA-6536-1 thunderbird – security update
- DSA-6537-1 libpng1.6 – security update
CERT-FR
- Multiples vulnérabilités dans le noyau Linux de SUSE (02 octobre 2026)
- Multiples vulnérabilités dans Tenable Nessus (02 octobre 2026)
- Multiples vulnérabilités dans les produits IBM (02 octobre 2026)
- Multiples vulnérabilités dans Apache HTTP Server (02 octobre 2026)
- Multiples vulnérabilités dans les produits VMware (02 octobre 2026)
- Multiples vulnérabilités dans le noyau Linux de Debian (02 octobre 2026)
- Multiples vulnérabilités dans le noyau Linux de Red Hat (02 octobre 2026)
- Multiples vulnérabilités dans Microsoft Edge (02 octobre 2026)
- Multiples vulnérabilités dans le noyau Linux d'Ubuntu (02 octobre 2026)
- Multiples vulnérabilités dans les produits Moxa (02 octobre 2026)
- Vulnérabilité dans Fortinet FortiMail (02 octobre 2026)
