Tuesday, September 29, 2026 Newsletter Advertise
Breaking
Advisories

Vulnerability Watch, September 26, 2026: 4 critical CVEs and 6 new vendor and CERT advisories

Every critical-severity CVE NIST published in the past day, plus the latest advisories from national CERTs and vendors.

4 critical CVEs , 6 advisories , NIST NVD, CERTs & vendors

The National Vulnerability Database (NVD) published 4 CVEs rated Critical under CVSS v3 in the 26 hours to this report. Descriptions below are quoted directly from NVD. Scores are NVD or CNA base scores; always confirm against the vendor advisory before prioritizing.

Critical CVEs (NVD)

CVE CVSS Description (NVD)
CVE-2026-100740 9.9 A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.
CVE-2026-100716 9.9 Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: FroxlorFileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component with is_link(). An…
CVE-2026-100717 9.9 froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or change_serversettings p…
CVE-2026-100715 9.6 Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because makeCorrectDir() appen…

New advisories from CERTs and vendors

Canadian Centre for Cyber Security

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Advisories