| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-16498 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-H | CRITICAL | 10.0 | NVD | 2026-07-28 |
| CVE-2026-65883 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo | CRITICAL | 10.0 | NVD | 2026-07-29 |
| CVE-2026-65884 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provide | CRITICAL | 10.0 | NVD | 2026-07-29 |
| CVE-2026-65887 | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method | CRITICAL | 10.0 | NVD | 2026-07-29 |
| CVE-2026-65888 | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows acto | CRITICAL | 10.0 | NVD | 2026-07-29 |
| CVE-2026-54735 | Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0 | CRITICAL | 10.0 | NVD | 2026-07-29 |
| CVE-2026-16326 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may all | CRITICAL | 10.0 | NVD | 2026-07-29 |
| CVE-2026-67429 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fi | CRITICAL | 10.0 | NVD | 2026-07-29 |
| CVE-2026-48449 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code | CRITICAL | 10.0 | NVD | 2026-07-30 |
| CVE-2026-66803 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | CRITICAL | 10.0 | NVD | 2026-07-30 |
| CVE-2026-18452 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote att | CRITICAL | 10.0 | NVD | 2026-07-31 |
| CVE-2026-33591 | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass
security r | CRITICAL | 10.0 | NVD | 2026-08-03 |
| CVE-2026-48323 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vul | CRITICAL | 10.0 | NVD | 2026-08-03 |
| CVE-2026-48330 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL | CRITICAL | 10.0 | NVD | 2026-08-03 |
| CVE-2026-48331 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv | CRITICAL | 10.0 | NVD | 2026-08-03 |
| CVE-2026-64633 | A vulnerability allowing remote unauthenticated code execution on the agent host. | CRITICAL | 10.0 | NVD | 2026-08-04 |
| CVE-2026-54735 | prebid-server's request forgery vulnerability allows for possible host environment data extraction | CRITICAL | 10.0 | GitHub | 2026-07-29 |
| CVE-2026-67429 | Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) | CRITICAL | 10.0 | GitHub | 2026-07-30 |
| CVE-2026-52887 | NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE | CRITICAL | 10.0 | GitHub | 2026-07-31 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-33819 | Microsoft Bing Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-32186 | Microsoft Bing Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33107 | Azure Databricks Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-35431 | Microsoft Entra ID Entitlement Management Spoofing Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-32213 | Azure AI Foundry Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-40175 | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-40412 | Azure Orbital Spatio Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-23652 | Microsoft Power Pages Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-47280 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42822 | Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |