Daily High-Risk Vuln Digest 2026-09-07 (4)
Daily High-Risk Vulnerability Digest · 2026-09-07
4 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).
今日收录
- CVE-2026-19931 —
9.8— A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent ove… - CVE-2026-86219 —
9.8— Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing… - CVE-2026-80238 —
9.3— Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local acces… - CVE-2026-18924 —
9.1— A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.