The National Vulnerability Database (NVD) published 3 CVEs rated Critical under CVSS v3 in the 26 hours to this report. Descriptions below are quoted directly from NVD. Scores are NVD or CNA base scores; always confirm against the vendor advisory before prioritizing.
Critical CVEs (NVD)
| CVE | CVSS | Description (NVD) |
|---|---|---|
| CVE-2026-105484 | 10 | A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote. |
| CVE-2026-105778 | 9.9 | A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
| CVE-2026-94293 | 9.8 | An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints. |
New advisories from CERTs and vendors
Canonical (Ubuntu)
- USN-8875-1: Linux kernel vulnerabilities
- USN-8879-1: Linux kernel (Oracle) vulnerabilities
- USN-8878-1: Linux kernel (GCP) vulnerabilities
- USN-8877-1: Linux kernel (GCP) vulnerabilities
- USN-8876-1: Linux kernel (Azure CVM) vulnerabilities
- USN-8873-1: Unbound vulnerabilities
- USN-8872-1: libxmltok vulnerabilities
- USN-8870-1: OpenStack Aodh and Watcher vulnerability
- USN-8871-1: Linux kernel (Raspberry Pi) vulnerabilities
- USN-8851-3: Linux kernel (Azure) vulnerabilities
- USN-8868-1: LibreOffice vulnerabilities
- USN-8867-1: Ceph vulnerability
- USN-8865-1: EDK II vulnerabilities
Debian
- DSA-6545-1 roundcube – security update
- DSA-6544-1 sabnzbdplus – security update
- DSA-6543-1 libreoffice – security update
Canadian Centre for Cyber Security
- Microsoft security advisory (AV26-1001)
- HPE security advisory (AV26-1000)
- Progress security advisory (AV26-999)
- [Control systems] GeoVision security advisory (AV26-998)
- IBM security advisory (AV26-997)
Microsoft MSRC
- CVE-2026-69267 Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability
CERT-FR
- Bulletin d'actualité CERTFR-2026-ACT-042 (05 octobre 2026)
- Multiples vulnérabilités dans OpenOffice (05 octobre 2026)
- Vulnérabilité dans Citrix NetScaler ADC et Gateway (05 octobre 2026)
- Multiples vulnérabilités dans Google Chrome (05 octobre 2026)
- Vulnérabilité dans Microsoft Exchange Server (05 octobre 2026)
- Vulnérabilité dans GitLab (05 octobre 2026)
- Multiples vulnérabilités dans Zabbix (05 octobre 2026)
