The National Vulnerability Database (NVD) published 12 CVEs rated Critical under CVSS v3 in the 26 hours to this report. Descriptions below are quoted directly from NVD. Scores are NVD or CNA base scores; always confirm against the vendor advisory before prioritizing.
Critical CVEs (NVD)
| CVE | CVSS | Description (NVD) |
|---|---|---|
| CVE-2026-53988 | 10 | Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with … |
| CVE-2026-102911 | 9.9 | A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79… |
| CVE-2026-102455 | 9.8 | EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content. |
| CVE-2026-102458 | 9.8 | EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API. |
| CVE-2026-103040 | 9.8 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with –enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue. |
| CVE-2026-103041 | 9.8 | LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges. |
| CVE-2023-54400 | 9.8 | Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for furt… |
| CVE-2026-102794 | 9.1 | A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
| CVE-2026-102793 | 9.1 | A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
| CVE-2026-102792 | 9.1 | A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
| CVE-2026-84436 | 9.1 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges. |
| CVE-2026-103056 | 9 | AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on man… |
New advisories from CERTs and vendors
Canonical (Ubuntu)
- USN-8851-1: Linux kernel vulnerabilities
- USN-8850-1: Linux kernel (BlueField) vulnerabilities
- USN-8849-1: Linux kernel (NVIDIA Tegra) vulnerabilities
- USN-8818-4: Linux kernel vulnerabilities
- USN-8819-4: Linux kernel (FIPS) vulnerabilities
- USN-8730-7: Linux kernel (FIPS) vulnerability
- USN-8817-2: Linux kernel (AWS FIPS) vulnerabilities
- USN-8847-2: OpenSSL vulnerabilities
- USN-8847-1: OpenSSL vulnerabilities
- USN-8846-1: libheif vulnerabilities
- USN-8844-1: c-ares vulnerability
- USN-8843-1: FreeIPMI vulnerabilities
- USN-8840-1: libevent vulnerabilities
CERT-FR
- Point de situation de l’opération REACTIV – septembre 2026 (30 septembre 2026)
- Vulnérabilité dans les produits Apple (29 septembre 2026)
Debian
- DSA-6531-1 openssl – security update
- DSA-6528-1 linux – security update
- DSA-6529-1 libwebsockets – security update
- DSA-6530-1 pcre2 – security update
Canadian Centre for Cyber Security
- TeamViewer security advisory (AV26-977)
- Mozilla security advisory (AV26-976)
- Hitachi security advisory (AV26-975)
- SUSE Linux security advisory (AV26-974)
- FreePBX security advisory (AV26-973)
- WatchGuard security advisory (AV26-972)
- Apple security advisory (AV26-971)
Microsoft MSRC
- CVE-2026-50332 Windows Kernel Elevation of Privilege Vulnerability
- CVE-2026-69307 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability
- CVE-2026-50357 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
- CVE-2026-50375 DirectX Graphics Kernel Elevation of Privilege Vulnerability
- CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability
- CVE-2026-57095 Win32k Elevation of Privilege Vulnerability
- CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability
- CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability
- CVE-2026-61930 Windows Kernel Elevation of Privilege Vulnerability
- CVE-2026-68880 Windows Win32k Elevation of Privilege Vulnerability
- CVE-2026-56172 Windows VHD miniport driver Elevation of Privilege Vulnerability
- CVE-2026-50414 Windows Media Elevation of Privilege Vulnerability
- CVE-2026-50400 Windows App Package Installer Elevation of Privilege Vulnerability
CISA
- ICSA-26-272-01: Lantronix G520 Series Cellular Gateway
- ICSA-26-272-02: Toptech TMS7 and TopHAT
- ICSA-26-272-03: VIVOTEK Camera Firmware
- ICSA-26-272-04: Baicells Nova 430H
- ICSA-26-272-05: Anjvision YSSD-RTMP-H5
- ICSA-26-272-06: MikroTik RouterOS
- ICSA-26-272-07: Viidure Dashcam Android Application
