Daily High-Risk Vuln Digest 2026-09-29 (3)

Daily High-Risk Vulnerability Digest · 2026-09-29

3 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-101894 — 9.1 — The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted syml…
  • CVE-2026-101860 — 9.0 — A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Pe…
  • CVE-2026-86950 — 0.0 — Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. [KEV]

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.