3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-77534 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77534

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-59683 — OpenRGB: The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59683

The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or a full account takeover (if the daemon is running in user context). CVSSv3.1 9.8 (CRITICAL)

CWECWE 73VNDOpenrgbTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 10:16Z
CRIT

CVE-2026-59682 — Arbitrary: file overwrite via SAVE_PROFILE message in OpenRGB.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59682

Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3. CVSSv3.1 9.1 (CRITICAL)

CWECWE 73VNDArbitraryTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 10:16Z
HIGH

CVE-2026-19042 — TeamViewer: A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19042

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDTeamviewerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 10:16Z
HIGH

CVE-2026-18794 — OpenRGB: The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18794

The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by passing inconsistent data. CVSSv3.1 8.2 (HIGH)

CWECWE 1288VNDOpenrgbTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 10:00Z
CRIT

Exploits and vulnerabilities in Q2 2026

Kaspersky's Q2 2026 vulnerability report documents a dramatic surge in CVE registrations driven by AI-assisted vulnerability discovery, with unprecedented numbers of critical Linux kernel privilege escalation vulnerabilities (Dirty Frag family) and Windows Defender/system vulnerabilities published with working exploits before CVE assignment. The report highlights a dangerous trend of researchers publishing full exploits for unpatched Windows vulnerabilities (BlueHammer, RedSun, YellowKey, GreenPlasma, RougePlanet, UnDefend) and widespread exploitation of AI/LLM platform vulnerabilities in APT campaigns, particularly Langflow.

SRFApplicationSRFOsTACTA0004TACTA0001TACTA0002SRFAiOSLinuxOSWindows
82
Edit Score
3w ago
2026-08-26 09:16Z
HIGH

CVE-2026-80237 — EFence: developed by Thinking Software Technology has an Arbitrary File Upload vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80237

EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDEfenceTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-26 09:16Z
HIGH

CVE-2026-80236 — Efence: developed by Thinking Software Technology has a SQL Injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80236

Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDEfenceTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 09:16Z
CRIT

CVE-2026-80235 — EFence: developed by Thinking Software Technology has an Arbitrary File Upload vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80235

EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDEfenceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 09:16Z
CRIT

CVE-2026-77533 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77533

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-26 09:16Z
CRIT

CVE-2026-18664 — Nlnetlabs Nsd: When ranges are used for access control (i.e.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18664

When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant to be denied access could be allowed. An IPv4 address is compared with IPv4 ranges as unsigned 32 bit numbers directly with the endianness of the host, but the values to compare are in network byte order (big-endian). With IPv6 addresses the c CVSSv3.1 9.1 (CRITICAL) · EPSS 24th percentile

CWECWE 284CWECWE 697VNDNlnetlabsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-26 08:16Z
HIGH

CVE-2026-78236 — PIN: An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78236

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process. CVSSv3.1 8.8 (HIGH)

CWECWE 287CWECWE 284CWECWE 285CWECWE 327VNDPinTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 08:16Z
HIGH

CVE-2026-75977 — Mang: The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75977

The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a WordPress user is logged in, combined with insufficient validation in mbw_validate_auth_cookie(). This makes it possible for authenticated attackers, with subscribe CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDMangTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 07:16Z
CRIT

CVE-2026-18431 — Avada: The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18431

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDAvadaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 06:16Z
HIGH

CVE-2026-77693 — Order: The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77693

The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over. CVSSv3.1 8.7 (HIGH)

CWECWE 73VNDOrderTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 06:16Z
CRIT

CVE-2026-58096 — LcpDecodeConfig: Undersized options would trigger an out-of-bounds write.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58096

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787CWECWE 130VNDLcpdecodeconfigTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 06:16Z
CRIT

CVE-2026-58095 — mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58095

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 06:16Z
HIGH

CVE-2026-19718 — BlogVault: The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19718

The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing attackers to recover it and gain administrative access to the site. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDBlogvaultTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 05:18Z
HIGH

CVE-2026-80202 — Kimai: before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80202

Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet) can read, modify, and permanently delete timesheets belonging to any user system-wide via the API, regardless of team membership. Timesheet IDs are sequential integers and trivially enumerable. ROLE CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDKimaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 05:18Z
HIGH

CVE-2026-80193 — Kimai: before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80193

Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere. CVSSv3.1 8.8 (HIGH) · EPSS 28th percentile

CWECWE 862VNDKimaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 05:18Z
HIGH

CVE-2026-80192 — When domain verification is enabled, a race condition between the verify-domain and update-provider endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80192

@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization owner/administrator to register an SSO provider for an arbitrary domain and have users with matching email domains added to the attacker's organization with default member permis CVSSv3.1 8.1 (HIGH)

CWECWE 287TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 05:18Z
HIGH

CVE-2026-58092 — FreeBSD: Since membership in group 0 is often used to enable controlled privilege escalation, the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58092

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel and not user-visible. One function, group_is_primary(), was not properly updated as a part of this transition. This function is used by mac_do to determine th CVSSv3.1 8.1 (HIGH) · EPSS 3th percentile

CWECWE 288TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 05:18Z
CRIT

CVE-2026-19632 — TranslatePress: The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19632

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account ta CVSSv3.1 9.8 (CRITICAL)

CWECWE 640VNDTranslatepressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 23:17Z
CRIT

CVE-2026-80138 — ClipBucket: V5's web installer fails to properly validate or escape the php_cli_filepath parameter before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80138

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDClipbucketTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 23:17Z
HIGH

CVE-2026-79912 — TOTOLINK: Performing a manipulation of the argument ntp_server results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79912

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. CVSSv3.1 8.3 (HIGH)

CWECWE 74CWECWE 77VNDTotolinkTYPVulnerability
8.3
CVSS v3.1
92
Edit Score