Daily High-Risk Vuln Digest 2026-09-29 (3)
Daily High-Risk Vulnerability Digest · 2026-09-29
3 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).
今日收录
- CVE-2026-101894 —
9.1— The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted syml… - CVE-2026-101860 —
9.0— A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Pe… - CVE-2026-86950 —
0.0— Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. [KEV]
Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.