Daily High-Risk Vuln Digest 2026-09-23 (9)

Daily High-Risk Vulnerability Digest · 2026-09-23

9 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-82331 — 9.8 — Improper link resolution before file access ('link following') vulnerability in the tar source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the…
  • CVE-2026-76183 — 9.8 — Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10…
  • CVE-2026-86248 — 9.8 — CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 1…
  • CVE-2026-86059 — 9.6 — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.…
  • CVE-2026-89282 — 9.1 — The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authe…
  • CVE-2026-86350 — 9.1 — Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apa…
  • CVE-2026-86246 — 9.1 — Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and A…
  • CVE-2026-75799 — 9.0 — The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server…
  • CVE-2026-82843 — 9.0 — The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belongi…

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.