Live feed All digests
← 2026-06-21 2026-08-27

Security Digest — 2026-08-27

11519
Total vulnerabilities
698
Critical
3974
High
11
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-65770Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache CRITICAL10.0NVD2026-08-20
CVE-2026-65801Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ovCRITICAL10.0NVD2026-08-20
CVE-2026-65816Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a CRITICAL10.0NVD2026-08-20
CVE-2026-69555Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.CRITICAL10.0NVD2026-08-20
CVE-2026-69836Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.CRITICAL10.0NVD2026-08-20
CVE-2026-69502Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a neCRITICAL10.0NVD2026-08-21
CVE-2026-61539Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference CRITICAL10.0NVD2026-08-21
CVE-2026-76604Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHPCRITICAL10.0NVD2026-08-22
CVE-2026-76605Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.CRITICAL10.0NVD2026-08-22
CVE-2026-76606Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.CRITICAL10.0NVD2026-08-22
CVE-2026-76607Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.CRITICAL10.0NVD2026-08-22
CVE-2026-74612In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adjuCRITICAL10.0NVD2026-08-22
CVE-2026-74705In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentCRITICAL10.0NVD2026-08-22
CVE-2026-77995Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of CRITICAL10.0NVD2026-08-24
CVE-2025-36939Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread netCRITICAL10.0NVD2026-08-24
CVE-2026-77998Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML CRITICAL10.0NVD2026-08-25
CVE-2026-76193Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbiCRITICAL10.0NVD2026-08-25
CVE-2026-76195Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS CoCRITICAL10.0NVD2026-08-25
CVE-2026-76197Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS CoCRITICAL10.0NVD2026-08-25
CVE-2026-77537A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi ProCRITICAL10.0NVD2026-08-26
CVE-2026-77550A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability foCRITICAL10.0NVD2026-08-26
CVE-2026-77554A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi TalCRITICAL10.0NVD2026-08-26
CVE-2026-65956KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration APICRITICAL10.0NVD2026-08-26
CVE-2026-61539Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsingCRITICAL10.0GitHub2026-08-21
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65770Azure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65801Microsoft Exchange Online Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65816Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69502Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69555Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-69836Microsoft Entra ID Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-57106Data Quality Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58275Azure DNS Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-66803Azure Cosmos DB Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-07-14