27 vulnerabilities across 15 products scored HIGH or above on September 03, 2026.
- ๐ HIGH: 27
๐ [HIGH] google/chrome
8 CVEs | CVSS 3.1: 9.6 | AAS 11.4
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*(< 152.0.7977.82)
Google Chrome is affected by eight vulnerabilities addressed in the latest stable channel update, including multiple high-severity issues. The most critical, rated CVSS 9.6, involves improper input validation in the Transactions Platform on iOS that could allow a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page. Additional flaws span multiple Chrome components and are considered exploitable.
All organizations and individuals running Google Chrome across desktop and iOS platforms should prioritize this update. Security teams should ensure all managed Chrome installations are updated to version 152.0.7977.82 or later immediately. Consult the vendor advisory at chromereleases.googleblog.com for the full list of resolved issues and affected versions.
- ๐ CVE-2026-85047 (CVSS 3.1: 9.6)
- ๐ CVE-2026-85050 (CVSS 3.1: 9.6)
- ๐ CVE-2026-85042 (CVSS 3.1: 9.6)
- ๐ CVE-2026-85053 (CVSS 3.1: 8.8)
- ๐ CVE-2026-85051 (CVSS 3.1: 8.8)
- ๐ CVE-2026-85049 (CVSS 3.1: 8.8)
- ๐ CVE-2026-85046 (CVSS 3.1: 8.8)
- ๐ CVE-2026-85048 (CVSS 3.1: 8.3)
๐ [HIGH] maplibre/maplibre-gl-js
1 CVE | CVSS 3.1: 10.0 | AAS 11.3
cpe:2.3:a:maplibre:maplibre-gl-js:*:*:*:*:*:*:*:*(< 6.4.1)
MapLibre GL JS, a widely used open-source interactive vector tile map library for web browsers, contains a critical vulnerability rated CVSS 10.0 that allows cross-site scripting through a flaw in its DOM sanitization logic. The sanitizer iterates over element attributes as a live collection while simultaneously removing them, causing dangerous event handler attributes such as onload to be skipped and preserved in rendered output. An attacker who can influence style attribution strings or custom attribution content can exploit this to execute arbitrary JavaScript in users’ browsers.
Development and security teams using MapLibre GL JS in any web application should upgrade to version 6.4.1 or later immediately. Applications that render user-supplied or third-party attribution content are at particular risk and should be prioritized for patching.
- ๐ CVE-2026-85061 (CVSS 3.1: 10.0)
๐ [HIGH] sciphi-ai/r2r
2 CVEs | CVSS 4.0: 9.3 | AAS 11.1
cpe:2.3:a:sciphi-ai:r2r:*:*:*:*:*:*:*:*(< 3.6.7)
R2R (Retrieval-to-Reasoning), an open-source AI RAG framework by SciPhi-AI, is affected by two critical vulnerabilities through version 3.6.6, including multiple SQL injection flaws rated CVSS 9.3. The most severe allows unauthenticated attackers to execute arbitrary SQL statements by injecting into the vector index creation endpoint, where the index name is interpolated directly into queries without sanitization and runs under the PostgreSQL superuser account, enabling full database compromise.
Organizations deploying R2R in any environment should treat this as an emergency. Monitor the vendor issue tracker at the referenced GitHub link for a patched release, and in the interim restrict network access to R2R API endpoints to trusted sources only.
- ๐ CVE-2026-82526 (CVSS 4.0: 9.3)
- ๐ CVE-2026-82527 (CVSS 4.0: 8.7)
๐ [HIGH] microsoft/microsoft_entra
1 CVE | CVSS 3.1: 9.1 | AAS 11.0
cpe:2.3:a:microsoft:microsoft_entra:*:*:*:*:*:*:*:*
Microsoft Entra ID, the cloud identity and access management platform formerly known as Azure Active Directory, contains a critical authentication bypass vulnerability rated CVSS 9.1 that allows an unauthorized attacker to elevate privileges over a network by exploiting an alternate authentication path. Given Entra ID’s role as the central identity provider for Microsoft 365, Azure, and countless enterprise applications, successful exploitation could grant an attacker unauthorized access across an organization’s entire cloud environment.
All organizations relying on Microsoft Entra ID should immediately review the Microsoft Security Response Center advisory and apply any available mitigations or patches. Security teams should also audit Entra ID sign-in and audit logs for anomalous authentication activity.
- ๐ CVE-2026-62916 (CVSS 3.1: 9.1)
๐ [HIGH] wpfunnels/mail_mint
1 CVE | CVSS 3.1: 9.8 | AAS 10.9
cpe:2.3:a:wpfunnels:mail_mint:*:*:*:*:*:*:*:*(< 1.31.1)
Mail Mint, a WordPress email marketing and automation plugin by WPFunnels, contains a critical unauthenticated PHP object injection vulnerability rated CVSS 9.8 affecting versions 1.31.0 and earlier. This flaw requires no authentication to exploit, meaning any internet-facing WordPress site running the vulnerable plugin is at risk of remote code execution, data exfiltration, or full site compromise depending on the object chains available in the environment.
WordPress administrators using Mail Mint should update to a patched version immediately. If an update is not yet available, consider temporarily deactivating the plugin and review server logs for signs of exploitation. Consult the Patchstack advisory for additional details.
- ๐ CVE-2026-84753 (CVSS 3.1: 9.8)
๐ [HIGH] ollama/ollama
1 CVE | CVSS 4.0: 8.7 | AAS 10.8
cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*(< 0.6.1)
Ollama, the widely deployed open-source local large language model runtime, contains a high-severity server-side request forgery vulnerability rated CVSS 8.7 stemming from a failure to validate redirect destinations when pulling tensor-layer models. An attacker controlling a malicious model registry can redirect blob download requests to arbitrary internal hosts, including cloud metadata endpoints, potentially exposing credentials, API keys, and other sensitive infrastructure data.
Organizations running Ollama, particularly in cloud environments, should monitor the project’s GitHub repository for a patched release and upgrade as soon as one is available. In the interim, restrict Ollama’s ability to pull models from untrusted registries and apply network-level controls to block outbound requests from the Ollama process to internal metadata services.
- ๐ CVE-2026-85180 (CVSS 4.0: 8.7)
๐ [HIGH] misp/misp
2 CVEs | CVSS 4.0: 9.5 | AAS 10.6
cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*(< 2.5.8)
MISP, the open-source threat intelligence sharing platform, is affected by two critical vulnerabilities rated up to CVSS 9.5, including multiple authentication bypass flaws in its LDAP and LinOTP authentication components. The custom authentication handlers failed to replicate CakePHP’s credential validation checks, allowing attackers to bypass authentication using empty or malformed credential values, potentially gaining unauthorized access to the platform and its stored threat intelligence data.
Organizations running MISP with LDAP or LinOTP authentication should apply the referenced patch immediately. Security teams should also review MISP access logs for anomalous login activity, particularly authentication attempts with empty or unusual credential formats, to identify potential prior exploitation.
- ๐ CVE-2026-85216 (CVSS 4.0: 9.5)
- ๐ CVE-2026-85236 (CVSS 4.0: 8.8)
๐ [HIGH] wwbn/avideo
2 CVEs | CVSS 4.0: 9.3 | AAS 10.5
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
WWBN AVideo, an open-source video streaming platform, is affected by two critical vulnerabilities rated up to CVSS 9.3, including multiple authentication flaws. The most severe involves the video_id_hash credential functioning as a non-expiring, non-revocable bearer token that grants full administrator-level access to the video owner’s account, and critically, the token remains valid even after a password change, allowing indefinite replay by any attacker who obtains it.
Organizations running AVideo should review the GitHub security advisory and apply any available patches immediately. Administrators should assume that any previously exposed video_id_hash values are compromised and cannot be invalidated through password rotation alone until the underlying token mechanism is fixed.
- ๐ CVE-2026-85154 (CVSS 4.0: 9.3)
- ๐ CVE-2026-85155 (CVSS 4.0: 8.7)
๐ [HIGH] paolo/geodirectory
1 CVE | CVSS 3.1: 9.3 | AAS 10.3
cpe:2.3:a:paolo:geodirectory:*:*:*:*:*:*:*:*(< 2.8.175)
GeoDirectory, a popular WordPress business directory plugin with widespread use on local listing and directory sites, contains a critical unauthenticated SQL injection vulnerability rated CVSS 9.3 affecting versions 2.8.174 and earlier. Because the flaw requires no authentication, any internet-facing WordPress site running the vulnerable plugin is exposed to database extraction, modification, or full compromise by remote attackers.
WordPress administrators using GeoDirectory should update to a patched version immediately. If a fix is not yet available, consider temporarily deactivating the plugin and auditing database logs for signs of injection attempts. Refer to the Patchstack advisory for further details.
- ๐ CVE-2026-84813 (CVSS 3.1: 9.3)
๐ [HIGH] totolink/cp450
1 CVE | CVSS 4.0: 8.6 | AAS 10.2
cpe:2.3:a:totolink:cp450:*:*:*:*:*:*:*:*
TOTOLINK CP450 running firmware version 4.1.0 contains a critical remotely exploitable buffer overflow vulnerability rated CVSS 8.6 in the web management interface’s CGI handler. An attacker can trigger the overflow by manipulating the topicurl parameter in requests to cstecgi.cgi, potentially achieving remote code execution or denial of service on the device.
Network administrators using TOTOLINK CP450 devices should check for firmware updates from the vendor and apply them immediately. If no patch is available, restrict access to the device’s web management interface to trusted networks only and monitor for anomalous traffic targeting the CGI endpoint.
- ๐ CVE-2026-85031 (CVSS 4.0: 8.6)
๐ [HIGH] n8n-io/n8n
3 CVEs | CVSS 4.0: 8.7 | AAS 10.1
cpe:2.3:a:n8n-io:n8n:*:*:*:*:*:*:*:*(< 1.123.73)cpe:2.3:a:n8n-io:n8n:*:*:*:*:*:*:*:*(>= 2.0.0, < 2.35.4)cpe:2.3:a:n8n-io:n8n:*:*:*:*:*:*:*:*(>= 2.36.0, < 2.36.2)
n8n, the widely used open-source workflow automation platform, is affected by three high-severity vulnerabilities rated up to CVSS 8.7, including multiple expression sandbox escape flaws. The most critical allows an attacker with workflow-build privileges to exploit prototype chain traversal in the $fromAI handler to reach the Function constructor and execute arbitrary code in the main n8n process, achieving full remote code execution on the host.
Organizations running n8n should upgrade immediately to versions 1.123.73, 2.35.4, or 2.36.2 or later, depending on their release track. Security teams should also audit who has workflow-build access and review existing workflows for suspicious expression patterns that may indicate prior exploitation.
- ๐ CVE-2026-85169 (CVSS 4.0: 8.7)
- ๐ CVE-2026-85168 (CVSS 4.0: 7.7)
- ๐ CVE-2026-85166 (CVSS 4.0: 7.2)
๐ [HIGH] yith/yith_request_a_quote_for_woocommerce_premium
1 CVE | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:yith:yith_request_a_quote_for_woocommerce_premium:*:*:*:*:*:*:*:*(< 4.46.0)
YITH Request a Quote for WooCommerce Premium, a commercial WordPress plugin used on WooCommerce storefronts to manage customer quote requests, contains a critical unauthenticated broken access control vulnerability rated CVSS 9.8 affecting versions prior to 4.46.0. The flaw requires no authentication to exploit, allowing remote attackers to bypass access restrictions and perform unauthorized actions on any affected WooCommerce site.
Site administrators running this plugin should update to version 4.46.0 or later immediately. Review site activity logs for any unauthorized access or unexpected changes to quote data, and consult the Patchstack advisory for additional technical details.
- ๐ CVE-2026-84238 (CVSS 3.1: 9.8)
๐ [HIGH] peppermint-lab/peppermint
1 CVE | CVSS 4.0: 9.3 | AAS 9.7
cpe:2.3:a:peppermint-lab:peppermint:*:*:*:*:*:*:*:*
Peppermint, an open-source helpdesk and ticket management system, through version 0.5.5 contains a critical hardcoded JWT signing secret in its docker-compose.yml rated CVSS 9.3. Since this secret is publicly available in the project’s source code, any remote attacker can forge valid session tokens for arbitrary user accounts, including administrators, gaining full unauthenticated access to the platform and all ticket data.
Organizations running Peppermint should immediately replace the default JWT secret with a unique, randomly generated value in their deployment configuration and restart the service to invalidate all existing tokens. Monitor the project’s GitHub repository for a patched release and audit access logs for any suspicious authentication activity.
- ๐ CVE-2026-85391 (CVSS 4.0: 9.3)
๐ [HIGH] fastify/fast-uri
1 CVE | CVSS 3.1: 7.5 | AAS 9.6
cpe:2.3:a:fastify:fast-uri:*:*:*:*:*:*:*:*
fast-uri, a high-performance URI parser widely used in the Node.js ecosystem including by the Fastify web framework, contains a host validation bypass vulnerability rated CVSS 7.5. The parser accepts URIs with unbalanced authority brackets without reporting an error, returning a host value that differs from how Node.js’s built-in URL parser and HTTP clients resolve the same string, enabling server-side request forgery and access control bypasses in applications that rely on the parsed host for security decisions.
Development teams using fast-uri directly or through Fastify and other dependent packages should update to a patched version as soon as one is available. Review the OpenJS Foundation security advisory and audit any application logic that uses fast-uri’s parsed host output for allowlist checks, SSRF protection, or routing decisions.
- ๐ CVE-2026-84394 (CVSS 3.1: 7.5)
๐ [HIGH] suse/rancher
1 CVE | CVSS 3.1: 8.7 | AAS 9.5
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*(>= 2.7.0, < 2.7.16)cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*(>= 2.8.0, < 2.8.11)cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*(>= 2.9.0, < 2.9.5)cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*(>= 2.10.0, < 2.10.3)
SUSE Rancher Manager contains a critical privilege escalation vulnerability rated CVSS 8.7 in its GlobalRole controller, which derives target ClusterRole names from a user-settable annotation without verifying ownership. An attacker with delegated GlobalRole create or update permissions can point the annotation at any existing ClusterRole, such as cluster-admin, overwriting its rules and revoking permissions for every principal bound to it, with the damage persisting even after the malicious GlobalRole is deleted.
Organizations running Rancher Manager should apply the fix referenced in the vendor pull request immediately, as this flaw enables both privilege escalation and denial of administrative access across managed clusters. Security teams should audit GlobalRole objects and their annotations for unauthorized modifications, and verify that critical ClusterRoles such as cluster-admin retain their expected rule sets.
- ๐ CVE-2026-71404 (CVSS 3.1: 8.7)