Live feed All digests
← 2026-06-21 2026-08-10

Security Digest — 2026-08-10

9925
Total vulnerabilities
542
Critical
3444
High
6
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-33591A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security rCRITICAL10.0NVD2026-08-03
CVE-2026-48323Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulCRITICAL10.0NVD2026-08-03
CVE-2026-48330Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL CRITICAL10.0NVD2026-08-03
CVE-2026-48331Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privCRITICAL10.0NVD2026-08-03
CVE-2026-64633A vulnerability allowing remote unauthenticated code execution on the agent host.CRITICAL10.0NVD2026-08-04
CVE-2026-16940The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unCRITICAL10.0NVD2026-08-05
CVE-2026-48168PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnCRITICAL10.0NVD2026-08-05
CVE-2026-5430The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supportCRITICAL10.0NVD2026-08-06
CVE-2026-65553Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.CRITICAL10.0NVD2026-08-06
CVE-2026-66665Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.CRITICAL10.0NVD2026-08-06
CVE-2026-11976The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both CRITICAL10.0NVD2026-08-06
CVE-2026-14812The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator CRITICAL10.0NVD2026-08-06
CVE-2026-56162Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.CRITICAL10.0NVD2026-08-07
CVE-2026-63508Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevCRITICAL10.0NVD2026-08-07
CVE-2026-65667Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.CRITICAL10.0NVD2026-08-07
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-06
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-06
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-06
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-66803Azure Cosmos DB Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-57106Data Quality Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58275Azure DNS Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-32169Azure Cloud Shell Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-03-10
CVE-2026-42960Possible cache poisoning via promiscuous records for the authority sectionCRITICAL10.0Microsoft2026-05-12
CVE-2026-46595Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshCRITICAL10.0Microsoft2026-05-12
CVE-2026-39821Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaCRITICAL10.0Microsoft2026-05-12
CVE-2026-40412Azure Orbital Spatio Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-23652Microsoft Power Pages Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-47280Azure Resource Manager Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-42822Azure Local Disconnected Operations (ALDO) Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-42826Azure DevOps Information Disclosure VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-41104Microsoft Planetary Computer Pro Information Disclosure VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-42901Microsoft Entra ID Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2025-62168Squid vulnerable to information disclosure via authentication credential leakage in error handlingCRITICAL10.0Microsoft2025-10-14
CVE-2025-59503Azure Compute Resource Provider Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-10-14
CVE-2025-65041Microsoft Partner Center Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2025-12-09
CVE-2025-65037Azure Container Apps Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2025-12-09