Daily High-Risk Vuln Digest 2026-09-07 (4)

Daily High-Risk Vulnerability Digest · 2026-09-07

4 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-19931 — 9.8 — A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent ove…
  • CVE-2026-86219 — 9.8 — Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing…
  • CVE-2026-80238 — 9.3 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local acces…
  • CVE-2026-18924 — 9.1 — A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.