Daily High-Risk Vuln Digest 2026-10-10 (4)
Daily High-Risk Vulnerability Digest · 2026-10-10
4 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).
今日收录
- CVE-2026-56857 —
9.8— On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This … - CVE-2026-100730 —
9.8— A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on system… - CVE-2026-105278 —
9.8— The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and… - CVE-2026-108109 —
9.1— PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Atta…
Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.