Daily High-Risk Vuln Digest 2026-10-03 (9)

Daily High-Risk Vulnerability Digest · 2026-10-03

9 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-90970 — 9.9 — GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, coul…
  • CVE-2026-14378 — 9.8 — The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the revert_switch handler trusting the att…
  • CVE-2026-19660 — 9.8 — The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The process_paypal_callback function, hooked to the init action, accepts a base64-encoded `…
  • CVE-2026-97637 — 9.8 — The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-…
  • CVE-2026-94541 — 9.8 — The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is author…
  • CVE-2026-19652 — 9.8 — The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the dmem_form_submit_handler() function determining the new user's role by iteratin…
  • CVE-2026-103628 — 9.6 — Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
  • CVE-2026-102795 — 9.3 — Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.…
  • CVE-2026-15896 — 9.1 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticate…

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.