Daily High-Risk Vuln Digest 2026-09-23 (9)
Daily High-Risk Vulnerability Digest · 2026-09-23
9 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).
今日收录
- CVE-2026-82331 —
9.8— Improper link resolution before file access ('link following') vulnerability in thetarsource plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the… - CVE-2026-76183 —
9.8— Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10… - CVE-2026-86248 —
9.8— CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 1… - CVE-2026-86059 —
9.6— Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.… - CVE-2026-89282 —
9.1— The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authe… - CVE-2026-86350 —
9.1— Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apa… - CVE-2026-86246 —
9.1— Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and A… - CVE-2026-75799 —
9.0— The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server… - CVE-2026-82843 —
9.0— The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belongi…
Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.