4w ago
2026-08-21 12:16Z
CRIT

CVE-2026-77776 — LLM: Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77776

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory. The fix introduces a single resolve_memory_identity seam in headroom/proxy/identity.py that honors the header CVSSv3.1 9.1 (CRITICAL)

CWECWE 639VNDLlmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
4w ago
2026-08-21 12:16Z
HIGH

CVE-2026-77775 — LLM: Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77775

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use as the upstream base; _select_passthrough_base_url in headroom/providers/proxy_routes.py reads the same header for the passthrough routes. No check rejects loopback, link-local, o CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDLlmTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
4w ago
2026-08-21 11:17Z
CRIT

CVE-2026-77683 — The manipulation of the argument timestr results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77683

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
4w ago
2026-08-21 11:17Z
CRIT

CVE-2026-77086 — SiYuan: before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77086

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location via install operations or recursively delete directories via uninstall operations by supplying crafted packageName values. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDSiyuanTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
4w ago
2026-08-21 09:16Z
HIGH

CVE-2026-68745 — Certificate: validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68745

Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures. Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue. CVSSv3.1 8.1 (HIGH) · EPSS 0th percentile

CWECWE 347TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
4w ago
2026-08-21 09:16Z
HIGH

CVE-2026-63046 — Neutralization: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63046

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1]/[2] to solve it. [1]  https://github.com/apache/inlong/pull/12151 . [2]  https://github.com CVSSv3.1 8.8 (HIGH)

CWECWE 88TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 09:16Z
CRIT

CVE-2026-62440 — Access: Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62440

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue. CVSSv3.1 9.1 (CRITICAL) · EPSS 3th percentile

CWECWE 284VNDAccessTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
4w ago
2026-08-21 09:16Z
HIGH

CVE-2026-61400 — Neutralization: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61400

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers. An authenticated user holding the permissions required to invoke either `getDiagnosticsData` or `runDiagnostics` can achieve arbitrary command execution on the system VM and/or Virtual Router instances, with commands running as root (or as the diagnostics-process user, at minimum CVSSv3.1 8.8 (HIGH)

CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 09:16Z
CRIT

CVE-2026-61398 — Encoding: Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61398

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue. CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

CWECWE 116TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
4w ago
2026-08-21 09:16Z
HIGH

CVE-2026-59799 — Privilege: Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59799

Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue. CVSSv3.1 8.8 (HIGH) · EPSS 8th percentile

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 09:16Z
CRIT

CVE-2026-59085 — Server: Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59085

Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue. CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

CWECWE 918TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
4w ago
2026-08-21 09:16Z
HIGH

CVE-2026-50112 — SSRF: via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50112

SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can later be downloaded through normal APIs. RCE on KVM hypervisor via NFS, Metalink files with/without Direct Downloads: An authenticated CloudStack tenant holding the default User role can execute arbitrary shell comman CVSSv3.1 8.8 (HIGH)

CWECWE 918CWECWE 78VNDSsrfTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 09:16Z
HIGH

CVE-2026-47359 — Neutralization: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47359

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introduced in 4.22.0.0) accept unsanitized command options for the backup repository. A malicious operator account can exploit this to inject arbitrary commands that execute on the KVM hypervisor host when any account subsequently perfor CVSSv3.1 8.8 (HIGH) · EPSS 41th percentile

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-08-21 08:16Z
CRIT

CVE-2026-77264 — Automation: The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77264

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the CVSSv3.1 9.8 (CRITICAL)

CWECWE 640VNDAutomationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4w ago
2026-08-21 08:00Z
HIGH

The invisible passenger in your car

Kaspersky Securelist·securelist.comin the wild

Kaspersky discovered the first documented Android malware targeting automotive head units, a multi-stage dropper chain distributed via compromised firmware updaters (TWCore) on DoFun head units. The infection chain delivers ad-fraud and reverse-proxy botnet capabilities (zhima module), attributed with high confidence to MoYu Group, linked to the BADBOX botnet platform. The attack exploits a design flaw in the head unit's update mechanism that allows installation of unsigned APKs without user interaction.

SRFMobileTACTA0001TACTA0003TACTA0011OSAndroidTYPResearchTYPThreat IntelSTGExecution
82
Edit Score
4w ago
2026-08-21 07:16Z
HIGH

CVE-2026-18781 — Drag: The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18781

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server. CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDDragTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
4w ago
2026-08-21 01:17Z
CRIT

CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77651

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 506TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4w ago
2026-08-21 01:17Z
CRIT

CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77650

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 506TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4w ago
2026-08-21 01:17Z
CRIT

CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77649

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 506TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 23:16Z
CRIT

CVE-2026-77647 — SPIP: before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77647

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDSpipTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:18Z
HIGH

CVE-2026-72860 — POST: The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72860

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate after a redirect, and its IPv4-mapped IPv6 branch is unreachable. The branch matches ^::ffff:(\d+\.\d+\.\d+\.\d+)$, but the WHATWG URL parser canonicalizes such literals to hextets bef CVSSv3.1 8.5 (HIGH)

CWECWE 918CWECWE 184VNDPostTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-20
2026-08-20 22:18Z
HIGH

CVE-2026-72848 — SitemapLoader: SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72848

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.scrape_all([loc.text], "xml"), which reaches WebBaseLoader.scrape_all and an aiohttp GET, with no domain comparison and no check for private, loopback or link-local destinations. An CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDSitemaploaderTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-20
2026-08-20 22:18Z
CRIT

CVE-2026-72843 — EverShop: The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72843

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the customer by the uuid taken from the URL path and writes the supplied fields back to CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDEvershopTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:18Z
CRIT

CVE-2026-69851 — Server: Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69851

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 918TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 22:18Z
CRIT

CVE-2026-69836 — Deserialization: of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69836

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 502TYPVulnerability
10.0
CVSS v3.1
100
Edit Score