Live feed All digests
← 2026-06-21 2026-08-04

Security Digest — 2026-08-04

9821
Total vulnerabilities
533
Critical
3367
High
5
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-16498The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HCRITICAL10.0NVD2026-07-28
CVE-2026-65883Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A foCRITICAL10.0NVD2026-07-29
CVE-2026-65884Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provideCRITICAL10.0NVD2026-07-29
CVE-2026-65887Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword methodCRITICAL10.0NVD2026-07-29
CVE-2026-65888Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actoCRITICAL10.0NVD2026-07-29
CVE-2026-54735Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0CRITICAL10.0NVD2026-07-29
CVE-2026-16326In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allCRITICAL10.0NVD2026-07-29
CVE-2026-67429Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fiCRITICAL10.0NVD2026-07-29
CVE-2026-48449Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary codeCRITICAL10.0NVD2026-07-30
CVE-2026-66803Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.CRITICAL10.0NVD2026-07-30
CVE-2026-18452DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attCRITICAL10.0NVD2026-07-31
CVE-2026-33591A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security rCRITICAL10.0NVD2026-08-03
CVE-2026-48323Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulCRITICAL10.0NVD2026-08-03
CVE-2026-48330Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL CRITICAL10.0NVD2026-08-03
CVE-2026-48331Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privCRITICAL10.0NVD2026-08-03
CVE-2026-64633A vulnerability allowing remote unauthenticated code execution on the agent host.CRITICAL10.0NVD2026-08-04
CVE-2026-54735prebid-server's request forgery vulnerability allows for possible host environment data extractionCRITICAL10.0GitHub2026-07-29
CVE-2026-67429Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)CRITICAL10.0GitHub2026-07-30
CVE-2026-52887NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCECRITICAL10.0GitHub2026-07-31
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-66803Azure Cosmos DB Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-57106Data Quality Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58275Azure DNS Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-33819Microsoft Bing Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-32186Microsoft Bing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33107Azure Databricks Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-35431Microsoft Entra ID Entitlement Management Spoofing VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-32213Azure AI Foundry Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33105Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-40175Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainCRITICAL10.0Microsoft2026-04-14
CVE-2026-42960Possible cache poisoning via promiscuous records for the authority sectionCRITICAL10.0Microsoft2026-05-12
CVE-2026-46595Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshCRITICAL10.0Microsoft2026-05-12
CVE-2026-39821Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaCRITICAL10.0Microsoft2026-05-12
CVE-2026-40412Azure Orbital Spatio Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-23652Microsoft Power Pages Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-47280Azure Resource Manager Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-42822Azure Local Disconnected Operations (ALDO) Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-05-12