Daily High-Risk Vuln Digest 2026-10-10 (4)

Daily High-Risk Vulnerability Digest · 2026-10-10

4 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-56857 — 9.8 — On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This …
  • CVE-2026-100730 — 9.8 — A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on system…
  • CVE-2026-105278 — 9.8 — The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and…
  • CVE-2026-108109 — 9.1 — PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Atta…

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.