| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-77998 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML | CRITICAL | 10.0 | NVD | 2026-08-25 |
| CVE-2026-76193 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbi | CRITICAL | 10.0 | NVD | 2026-08-25 |
| CVE-2026-76195 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co | CRITICAL | 10.0 | NVD | 2026-08-25 |
| CVE-2026-76197 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co | CRITICAL | 10.0 | NVD | 2026-08-25 |
| CVE-2026-77537 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Pro | CRITICAL | 10.0 | NVD | 2026-08-26 |
| CVE-2026-77550 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability fo | CRITICAL | 10.0 | NVD | 2026-08-26 |
| CVE-2026-77554 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Tal | CRITICAL | 10.0 | NVD | 2026-08-26 |
| CVE-2026-65956 | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API | CRITICAL | 10.0 | NVD | 2026-08-26 |
| CVE-2026-81735 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was g | CRITICAL | 10.0 | NVD | 2026-08-27 |
| CVE-2026-18885 | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnera | CRITICAL | 10.0 | NVD | 2026-08-27 |
| CVE-2026-18886 | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. Th | CRITICAL | 10.0 | NVD | 2026-08-27 |
| CVE-2026-74820 | ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulne | CRITICAL | 10.0 | NVD | 2026-08-27 |
| CVE-2026-82222 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue af | CRITICAL | 10.0 | NVD | 2026-08-28 |
| CVE-2026-54745 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the | CRITICAL | 10.0 | NVD | 2026-08-28 |
| CVE-2026-82456 | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller c | CRITICAL | 10.0 | NVD | 2026-08-29 |
| CVE-2026-82970 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePriva | CRITICAL | 10.0 | NVD | 2026-08-31 |
| CVE-2026-81779 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software I | CRITICAL | 10.0 | NVD | 2026-08-31 |
| CVE-2026-81780 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | CRITICAL | 10.0 | NVD | 2026-08-31 |
| CVE-2026-32186 | Microsoft Bing Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-32213 | Azure AI Foundry Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33107 | Azure Databricks Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33819 | Microsoft Bing Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-35431 | Microsoft Entra ID Entitlement Management Spoofing Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2017-20230 | Storable versions before 3.05 for Perl has a stack overflow | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65770 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65801 | Microsoft Exchange Online Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65816 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-69502 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-69555 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-69836 | Microsoft Entra ID Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |