Live feed All digests
← 2026-06-21 2026-08-22

Security Digest — 2026-08-22

11936
Total vulnerabilities
967
Critical
4638
High
9
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-72407In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_groCRITICAL10.0NVD2026-08-15
CVE-2026-72408In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_gro_complete() on gCRITICAL10.0NVD2026-08-15
CVE-2026-72421In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error route in local/main tCRITICAL10.0NVD2026-08-15
CVE-2026-74279In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wrong loCRITICAL10.0NVD2026-08-15
CVE-2026-74280In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix DMA cleanup using wrCRITICAL10.0NVD2026-08-15
CVE-2026-74309In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupCRITICAL10.0NVD2026-08-15
CVE-2026-74475In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircuiCRITICAL10.0NVD2026-08-15
CVE-2026-74764Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submittedCRITICAL10.0NVD2026-08-15
CVE-2026-74253Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 -CRITICAL10.0NVD2026-08-17
CVE-2026-75874Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.CRITICAL10.0NVD2026-08-18
CVE-2026-73343Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.CRITICAL10.0NVD2026-08-18
CVE-2026-61241Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL10.0NVD2026-08-18
CVE-2026-70880Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuCRITICAL10.0NVD2026-08-18
CVE-2026-70921Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL10.0NVD2026-08-18
CVE-2026-76008A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-CRITICAL10.0NVD2026-08-19
CVE-2026-18051The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache filCRITICAL10.0NVD2026-08-19
CVE-2026-67364Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.CRITICAL10.0NVD2026-08-19
CVE-2026-74803Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbiCRITICAL10.0NVD2026-08-19
CVE-2026-75949Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - UCRITICAL10.0NVD2026-08-19
CVE-2026-20030As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team haCRITICAL10.0NVD2026-08-19
CVE-2026-20315As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering tCRITICAL10.0NVD2026-08-19
CVE-2026-20317As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering tCRITICAL10.0NVD2026-08-19
CVE-2026-20357As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team haCRITICAL10.0NVD2026-08-19
CVE-2026-20358As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team haCRITICAL10.0NVD2026-08-19
CVE-2026-22306Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transCRITICAL10.0NVD2026-08-19
CVE-2026-65770Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache CRITICAL10.0NVD2026-08-20
CVE-2026-65801Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ovCRITICAL10.0NVD2026-08-20
CVE-2026-65816Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a CRITICAL10.0NVD2026-08-20
CVE-2026-69555Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.CRITICAL10.0NVD2026-08-20
CVE-2026-69836Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.CRITICAL10.0NVD2026-08-20
CVE-2026-69502Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a neCRITICAL10.0NVD2026-08-21
CVE-2026-61539Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference CRITICAL10.0NVD2026-08-21
CVE-2026-61539Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsingCRITICAL10.0GitHub2026-08-21
GHSA-m5w8-4gq2-6f8xvm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (CRITICAL10.0GitHub2026-08-17
CVE-2026-55107kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)CRITICAL10.0GitHub2026-08-18
CVE-2026-32186Microsoft Bing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-32213Azure AI Foundry Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33105Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33107Azure Databricks Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33819Microsoft Bing Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-04-14