Daily High-Risk Vuln Digest 2026-09-03 (6)

Daily High-Risk Vulnerability Digest · 2026-09-03

6 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-85031 — 9.9 — A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote explo…
  • CVE-2026-20212 — 9.8 — A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 4…
  • CVE-2026-20274 — 9.8 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software harde…
  • CVE-2026-20279 — 9.8 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software harde…
  • CVE-2026-80726 — 9.3 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.invalid when deriving a child shadow page's role from …
  • CVE-2026-85221 — 9.1 — MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value effec…

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.