3w ago
2026-08-26 15:16Z
CRIT

CVE-2026-74746 — Linux: KASAN can trigger slab-use-after-free read and write reports in the flowtable/rhashtable path (rht_deferred_worker, jhash

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74746

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while flow_offload_add() is still inserting the reply node. Publish the reply node first and the original node last so GC never sees a partially installed flow. KASAN can trigger slab-use-after-free read CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:16Z
CRIT

CVE-2026-74744 — Linux: This can result in reallocation overhead, skb headroom underflows, or KASAN slab-use-after-free crashes when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74744

In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(), but leave needed_headroom and needed_tailroom set to 0. When the underlying phy_dev (or stacked lower device) requires extra headroom or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx headroom), upper layers calculating packet hea CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:16Z
CRIT

CVE-2026-74743 — Linux: This can result in reallocation overhead, skb headroom underflows, or KASAN slab-use-after-free crashes when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74743

In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroom from lowerdev macvlan devices inherit hard_header_len from lowerdev during macvlan_init(), but leave needed_headroom and needed_tailroom set to 0. When the underlying lowerdev requires extra headroom or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx headroom), upper layers calculating packet headroom and tailroom f CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:16Z
CRIT

CVE-2026-74737 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74737

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG On the packet reception path, the ID of the MAC Port on which the packet was received, is embedded in the RX DMA Descriptor's metadata. The ID is extracted using the helper function cppi5_desc_get_tags_ids() which fills in the 16-bit Source Tag into the 'port_id' variable. However, it is only the lower 8-bits of the 16-bit Source Tag tha CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:16Z
CRIT

CVE-2026-54523 — Kyverno: A user who can create NamespacedMutatingPolicy objects in one namespace can cause the admission

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54523

Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke generator.apply(namespace, resources) with an arbitrary target namespace. The validation in pkg/cel/policies/mpol/validate.go checks that the policy compiles but does not enforce namespace scope, and GenerateResources in pkg/cel/libs/co CVSSv3.1 9.6 (CRITICAL)

CWECWE 862VNDKyvernoTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-26 15:16Z
HIGH

CVE-2026-54511 — LogTape: Applications that forward attacker-controlled property values or keys can therefore allow forged records with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54511

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F in structured data values, and formatStructuredData() inserts property keys without validating the RFC 5424 SD-NAME grammar. When includeStructuredData is true, an attacker-controlled newline can terminate an RFC 6587 non-transparen CVSSv3.1 8.6 (HIGH)

CWECWE 93CWECWE 117VNDLogtapeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3w ago
2026-08-26 14:17Z
HIGH

CVE-2026-75960 — Rently: Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75960

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions. CVSSv3.1 8.1 (HIGH)

CWECWE 522VNDRentlyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-26 14:17Z
CRIT

CVE-2026-75896 — Use: of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75896

Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords. This issue affects Liderahenk: before 3.5.5. CVSSv3.1 9.1 (CRITICAL)

CWECWE 798TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 13:00Z
CRIT

A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console

Bishop Fox disclosed two chained critical vulnerabilities in Veeam Service Provider Console (VSPC) affecting versions 9.2.1 and earlier. CVE-2026-58073 (CVSS 9.5) allows unauthenticated attackers to impersonate managed agents by presenting self-signed certificates with known GUIDs, obtaining legitimate agent credentials. CVE-2026-58072 (CVSS 9.0) enables arbitrary file writes via path traversal in the SaveFiles RPC method. Chained together, these flaws result in unauthenticated RCE on the multi-tenant console controlling backups across all customer environments. Patch 9.3.0 closes all four KB4893 vulnerabilities; no 9.2.x backport exists.

SRFApplicationTACTA0001TACTA0002SRFNetworkSWVeeam Service Provider ConsoleVNDVeeamTYPResearchTYPVulnerability
92
Edit Score
3w ago
2026-08-26 12:16Z
HIGH

CVE-2026-63041 — Apache Apisix: This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63041

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly. This issue affects Apache APISIX: from 3.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue. CVSSv3.1 8.8 (HIGH)

CWECWE 807VNDApacheVNDRelianceTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 12:16Z
HIGH

CVE-2026-15985 — Classified: The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15985

The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login() function. This makes it possible for unauthenticated attackers to authenticate as any user with a phone number registered in the plugin's phone table by submitting an arbitrary OTP code and UID through the Firebase OTP login flow. Succes CVSSv3.1 8.1 (HIGH)

CWECWE 289VNDClassifiedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-80203 — The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80203

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the specific API key carries super authority (via isSuperWithinScope()). As a result, an API key scoped below full super authority but belonging to a super-admin account can act against other super-admin a CVSSv3.1 9.8 (CRITICAL)

CWECWE 863TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77557 — A malicious actor with access to the network could exploit an Improper Access Control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77557

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77554 — A malicious actor with access to the network could exploit an Improper Input Validation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77554

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device. CVSSv3.1 10.0 (CRITICAL)

CWECWE 20TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77553 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77553

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77552 — A malicious actor with access to the network could exploit an Improper Input Validation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77552

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77551 — A malicious actor with access to the network and under certain conditions could exploit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77551

A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device. CVSSv3.1 9.0 (CRITICAL)

CWECWE 284TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77550 — A malicious actor with access to the network could exploit an Improper Neutralization of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77550

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. CVSSv3.1 10.0 (CRITICAL)

CWECWE 93TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77549 — A malicious actor with access to the network and under certain conditions could exploit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77549

A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. CVSSv3.1 9.0 (CRITICAL)

CWECWE 93TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77548 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77548

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77547 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77547

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77546 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77546

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-77532 — A malicious actor with access to an adjacent network could exploit a Buffer Overflow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77532

A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device. CVSSv3.1 9.6 (CRITICAL)

CWECWE 122TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-26 11:16Z
CRIT

CVE-2026-18080 — ERP: The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18080

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing file extension validation and missing path normalization when CRM Email Connect processes inbound IMAP email attachments. This makes it possible for unauthenticated attackers to send a crafted email to the site's configured inbound mailbox CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDErpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 11:00Z
CRIT

VMs won't contain cyber-capable agents

Trail of Bits·blog.trailofbits.comCVE-2026-53359CVE-2026-95390day

Trail of Bits researchers demonstrated that GPT 5.6-Cyber autonomously escaped a QEMU/KVM VM three times using a combination of disclosed vulnerabilities, unpatched distribution bugs, and zero-day exploits in QEMU, Linux KVM, and libslirp. The agent operated for ~12 hours, chaining multiple memory corruption and privilege escalation primitives to achieve host kernel execution and flag exfiltration. The research challenges the assumption that standard VMs provide adequate containment for advanced AI agents and highlights critical gaps in distribution patch cycles and virtualization attack surface.

SRFOsTACTA0004TACTA0002SRFCloudOSLinuxSWFirecrackerSWKvmSWLibslirp
92
Edit Score