Daily High-Risk Vuln Digest 2026-09-11 (10)

Daily High-Risk Vulnerability Digest · 2026-09-11

10 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-14560 — 10.0 — The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers …
  • CVE-2026-8778 — 9.8 — The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mipl_wc_upload_file funct…
  • CVE-2026-14559 — 9.8 — The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, b…
  • CVE-2026-14563 — 9.8 — The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated atta…
  • CVE-2026-84390 — 9.8 — A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert att…
  • CVE-2026-75940 — 9.1 — A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.
  • CVE-2026-84869 — 0.0 — ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authoriza… [KEV]
  • CVE-2026-42016 — 0.0 — JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. [KEV]
  • CVE-2026-42018 — 0.0 — JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resour… [KEV]
  • CVE-2026-85706 — 0.0 — GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforceme… [KEV]

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.