The National Vulnerability Database (NVD) published 4 CVEs rated Critical under CVSS v3 in the 26 hours to this report. Descriptions below are quoted directly from NVD. Scores are NVD or CNA base scores; always confirm against the vendor advisory before prioritizing.
Critical CVEs (NVD)
| CVE | CVSS | Description (NVD) |
|---|---|---|
| CVE-2026-93674 | 9.8 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. |
| CVE-2026-104334 | 9.8 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of code generation. |
| CVE-2026-104070 | 9.8 | The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skel… |
| CVE-2026-106037 | 9.8 | Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or delete objects, and mount attacker-described segments. |
New advisories from CERTs and vendors
Canonical (Ubuntu)
- USN-8893-1: Libwebsockets vulnerabilities
- USN-8892-1: Ubuntu Pro for WSL vulnerability
- USN-8890-1: libsoup vulnerabilities
- USN-8884-1: U-Boot vulnerabilities
- USN-8889-1: Linux kernel (OEM) vulnerabilities
- USN-8888-1: Linux kernel (Azure) vulnerabilities
- USN-8885-1: FluidSynth vulnerabilities
- USN-8887-1: Linux kernel vulnerabilities
- USN-8886-1: Linux kernel (NVIDIA Tegra) vulnerabilities
- USN-8883-1: Go vulnerability
- USN-8882-1: Tesseract vulnerabilities
- USN-8881-1: FreeType vulnerability
- USN-8880-1: FreeRDP vulnerabilities
- USN-8874-1: sg3_utils vulnerability
- USN-8869-1: RabbitMQ Server vulnerability
Microsoft MSRC
- Chromium: CVE-2025-0611 Object corruption in V8
- CVE-2026-50387 Windows GDI Elevation of Privilege Vulnerability
- CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability
- CVE-2026-62698 Microsoft Digest Authentication Elevation of Privilege Vulnerability
- CVE-2026-73009 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2026-69582 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability
- CVE-2026-69844 Windows Win32k Elevation of Privilege Vulnerability
- CVE-2026-72999 Windows USB Hub Driver Elevation of Privilege Vulnerability
- CVE-2026-68894 Windows Error Reporting Elevation of Privilege Vulnerability
- CVE-2026-69265 Windows NTFS Elevation of Privilege Vulnerability
- CVE-2026-78501 Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
- CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability
- CVE-2026-61927 Windows Bind Filter Driver Elevation of Privilege Vulnerability
- CVE-2026-71343 Windows Remote Access Connection Manager Remote Code Execution Vulnerability
Canadian Centre for Cyber Security
- Progress security advisory (AV26-1005)
- Rapid7 security advisory (AV26-1004)
- Android security advisory – October 2026 monthly rollup (AV26-1003)
- Atlassian security advisory (AV26-1002)
CISA
Debian
- DSA-6546-1 rails – security update
- DSA-6547-1 ruby-jwt – security update
- DSA-6548-1 node-shell-quote – security update
