Live feed All digests
← 2026-06-21 2026-09-03

Security Digest — 2026-09-03

10506
Total vulnerabilities
582
Critical
3539
High
12
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-81735startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was gCRITICAL10.0NVD2026-08-27
CVE-2026-18885ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulneraCRITICAL10.0NVD2026-08-27
CVE-2026-18886ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. ThCRITICAL10.0NVD2026-08-27
CVE-2026-6876ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This securiCRITICAL10.0NVD2026-08-27
CVE-2026-74820ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulneCRITICAL10.0NVD2026-08-27
CVE-2026-82222Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue afCRITICAL10.0NVD2026-08-28
CVE-2026-54745Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, theCRITICAL10.0NVD2026-08-28
CVE-2026-82456argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller cCRITICAL10.0NVD2026-08-29
CVE-2026-82970Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivaCRITICAL10.0NVD2026-08-31
CVE-2026-81779Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software ICRITICAL10.0NVD2026-08-31
CVE-2026-81780Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.CRITICAL10.0NVD2026-08-31
CVE-2026-84147This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation CRITICAL10.0NVD2026-09-01
CVE-2026-76657Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthCRITICAL10.0NVD2026-09-01
CVE-2026-76658A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticaCRITICAL10.0NVD2026-09-01
CVE-2026-83548A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternCRITICAL10.0NVD2026-09-01
CVE-2026-4357The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as welCRITICAL10.0NVD2026-09-02
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-57106Data Quality Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58275Azure DNS Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-66803Azure Cosmos DB Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-45480Azure Active Directory Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-06-09
CVE-2026-48567Azure HorizonDB Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-06-09
CVE-2026-32186Microsoft Bing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-32213Azure AI Foundry Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33105Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33107Azure Databricks Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33819Microsoft Bing Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-35431Microsoft Entra ID Entitlement Management Spoofing VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2017-20230Storable versions before 3.05 for Perl has a stack overflowCRITICAL10.0Microsoft2026-04-14
CVE-2026-39821Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaCRITICAL10.0Microsoft2026-05-12
CVE-2026-42960Possible cache poisoning via promiscuous records for the authority sectionCRITICAL10.0Microsoft2026-05-12
CVE-2026-46595Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshCRITICAL10.0Microsoft2026-05-12
CVE-2026-40412Azure Orbital Spatio Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-23652Microsoft Power Pages Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-47280Azure Resource Manager Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-42822Azure Local Disconnected Operations (ALDO) Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-05-12
CVE-2026-42826Azure DevOps Information Disclosure VulnerabilityCRITICAL10.0Microsoft2026-05-12