Live feed All digests
← 2026-06-21 2026-08-19

Security Digest — 2026-08-19

12138
Total vulnerabilities
887
Critical
4433
High
5
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-67282Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker CRITICAL10.0NVD2026-08-12
CVE-2026-73299Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks rCRITICAL10.0NVD2026-08-12
CVE-2024-27253IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to performCRITICAL10.0NVD2026-08-12
CVE-2026-15413The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-CRITICAL10.0NVD2026-08-13
CVE-2026-59500CWE-287: Improper AuthenticationCRITICAL10.0NVD2026-08-13
CVE-2026-27544Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.CRITICAL10.0NVD2026-08-13
CVE-2026-61962Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.CRITICAL10.0NVD2026-08-13
CVE-2026-19188A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulCRITICAL10.0NVD2026-08-14
CVE-2026-73678MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that aCRITICAL10.0NVD2026-08-14
CVE-2026-72407In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_groCRITICAL10.0NVD2026-08-15
CVE-2026-72408In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_gro_complete() on gCRITICAL10.0NVD2026-08-15
CVE-2026-72421In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error route in local/main tCRITICAL10.0NVD2026-08-15
CVE-2026-74279In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wrong loCRITICAL10.0NVD2026-08-15
CVE-2026-74280In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix DMA cleanup using wrCRITICAL10.0NVD2026-08-15
CVE-2026-74309In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupCRITICAL10.0NVD2026-08-15
CVE-2026-74475In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircuiCRITICAL10.0NVD2026-08-15
CVE-2026-74764Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submittedCRITICAL10.0NVD2026-08-15
CVE-2026-74253Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 -CRITICAL10.0NVD2026-08-17
CVE-2026-75874Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.CRITICAL10.0NVD2026-08-18
CVE-2026-73343Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.CRITICAL10.0NVD2026-08-18
CVE-2026-61241Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL10.0NVD2026-08-18
CVE-2026-70880Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuCRITICAL10.0NVD2026-08-18
CVE-2026-70921Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL10.0NVD2026-08-18
CVE-2026-76008A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-CRITICAL10.0NVD2026-08-19
GHSA-m5w8-4gq2-6f8xvm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (CRITICAL10.0GitHub2026-08-17
CVE-2026-55107kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)CRITICAL10.0GitHub2026-08-18
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-57106Data Quality Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58275Azure DNS Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-66803Azure Cosmos DB Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-42960Possible cache poisoning via promiscuous records for the authority sectionCRITICAL10.0Microsoft2026-05-12
CVE-2026-46595Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshCRITICAL10.0Microsoft2026-05-12
CVE-2026-39821Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaCRITICAL10.0Microsoft2026-05-12
CVE-2026-40412Azure Orbital Spatio Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-05-12