Daily High-Risk Vuln Digest 2026-09-08 (12)

Daily High-Risk Vulnerability Digest · 2026-09-08

12 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-12645 — 9.9 — A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
  • CVE-2026-12646 — 9.9 — A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
  • CVE-2026-12647 — 9.9 — A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
  • CVE-2026-12650 — 9.9 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
  • CVE-2026-12744 — 9.8 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
  • CVE-2026-12745 — 9.8 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
  • CVE-2026-79576 — 9.8 — An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.
  • CVE-2026-73309 — 9.1 — XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_v…
  • CVE-2026-75650 — 0.0 — Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. [KEV]
  • CVE-2026-81963 — 0.0 — Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM. [KEV]
  • CVE-2026-86218 — 0.0 — N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. [KEV]
  • CVE-2026-85880 — 0.0 — Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. [KEV]

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.