2026-08-20
2026-08-20 21:17Z
HIGH

CVE-2026-76017 — Use: after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76017

Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 21:17Z
HIGH

CVE-2026-73040 — Dockge: In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73040

Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksDir, this.name) and Stack.getStack builds path.join(server.stacksDir, stackName) with no check. The socket handlers in backend/agent-socket-handlers/docker-socket-handler.ts confirm the caller is logged in and that the name is a strin CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDDockgeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 21:17Z
CRIT

CVE-2026-71485 — Centrifugo: Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71485

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The requestHeaders path in internal/proxy/http.go, the requestMetadata path in internal/proxy/grpc.go, and the Consume path in internal/unigrpc/grpc.go can forward an allowlisted value as a trusted backend hea CVSSv3.1 9.1 (CRITICAL)

CWECWE 290VNDCentrifugoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-20
2026-08-20 21:17Z
CRIT

CVE-2026-67567 — This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67567

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise. CVSSv3.1 9.9 (CRITICAL)

CWECWE 441TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 21:17Z
CRIT

CVE-2026-43798 — SSH: A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43798

A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 121VNDSshTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 21:17Z
HIGH

CVE-2026-18420 — Time: Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18420

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later. CVSSv3.1 8.8 (HIGH)

CWECWE 1321TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 19:17Z
CRIT

CVE-2026-77148 — Comfast: The manipulation results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77148

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119VNDComfastTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-20
2026-08-20 19:16Z
CRIT

CVE-2026-66788 — Lighthouse: A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66788

A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDLighthouseTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 19:16Z
HIGH

CVE-2026-66787 — This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66787

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Ma CVSSv3.1 8.7 (HIGH)

CWECWE 345TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 19:16Z
CRIT

CVE-2026-66785 — Submariner: This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66785

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious cluster, enabling it to declare arbitrary network ranges. Consequently, all network traffic intended for these arbitrary ranges from peer clusters will be rerouted through the attacker CVSSv3.1 9.9 (CRITICAL)

CWECWE 20VNDSubmarinerTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 19:16Z
CRIT

CVE-2026-19586 — Tp-link Er7212pc_firmware: A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19586

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attack CVSSv3.1 9.8 (CRITICAL) · EPSS 92th percentile

CWECWE 78VNDTp LinkTYPVulnerability
9.8
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 18:16Z
CRIT

CVE-2026-73257 — Mongoose: Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73257

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use a different request boundary. This CL.TE desynchronization can inject requests t CVSSv3.1 9.1 (CRITICAL)

CWECWE 444VNDMongooseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-20
2026-08-20 18:16Z
CRIT

CVE-2026-73256 — Mongoose: consequently processes chunked encoding that an HTTP/1.0 proxy can ignore, enabling request smuggling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73256

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impossible greater-than-eight condition even though mg_http_parse() requires an eight-byte protocol string, so is_http_1_0 is never set. Mongoose consequently processes chunked encodin CVSSv3.1 9.1 (CRITICAL)

CWECWE 444VNDMongooseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-20
2026-08-20 18:16Z
HIGH

CVE-2026-63388 — Libevent: Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63388

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect CVSSv3.1 8.4 (HIGH)

CWECWE 787CWECWE 617VNDLibeventTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-20
2026-08-20 17:19Z
HIGH

CVE-2026-77176 — Kata: In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77176

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input. CVSSv3.1 8.1 (HIGH)

CWECWE 73VNDKataTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 17:19Z
CRIT

CVE-2026-77022 — The manipulation of the argument ssid results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77022

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 17:19Z
CRIT

CVE-2026-71428 — The response body is returned as Element text, allowing internal response disclosure, and side-effecting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71428

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host validation in unstructured/partition/auto.py, unstructured/partition/html/partition.py, and unstructured/partition/md.py. An attacker who controls that URL can make a server-side ingestion service request CVSSv3.1 9.3 (CRITICAL)

CWECWE 918CWECWE 601TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 17:19Z
HIGH

CVE-2026-65842 — Plate: The converter can make requests to internal network resources and include the fetched image

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65842

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can make requests to internal network resources and include the fetched image bytes in the generated DOCX, allowing server-side request forgery with response disclosure. Applications can also incur resource consumption from attacker-selected remo CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDPlateTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 17:18Z
CRIT

CVE-2026-55642 — An unauthenticated network attacker can call the /api/connection/connect and /api/query/execute routes to use configured

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55642

dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that state when DBX_PASSWORD is unset and no stored password exists, while crates/dbx-web/src/main.rs binds the service to 0.0.0.0 on port 4224 by default. An unauthenticated network attacker can call the /api/connection/connect and /api/query/exe CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 17:18Z
HIGH

CVE-2026-54449 — LangBot: An attacker who can sign up or obtain an account can use the Extensions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54449

LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or change an STDIO MCP server configuration without an adequate authorization boundary. In src/langbot/pkg/provider/tools/loaders/mcp.py, StdioServerParameters accepts the configured command and arguments and starts a server-side subprocess on the LangBot server. An attacker who can sign up or obtain an account can use the Extensions MCP configuration to execut CVSSv3.1 8.8 (HIGH)

CWECWE 77VNDLangbotTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 17:17Z
HIGH

CVE-2026-18282 — Sony: XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18282

Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the handling of AVRCP packets. The issue results from the lack of p CVSSv3.1 8.0 (HIGH)

CWECWE 122VNDSonyTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-20
2026-08-20 17:17Z
HIGH

CVE-2026-18281 — Sony: XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18281

Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the handling of Bluetooth L2CAP packets. The issue results from the lack o CVSSv3.1 8.0 (HIGH)

CWECWE 122VNDSonyTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-20
2026-08-20 17:17Z
HIGH

CVE-2026-18279 — Sony: XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18279

Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SETUP RTSP packets. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length buffer. A CVSSv3.1 8.8 (HIGH)

CWECWE 120VNDSonyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 17:17Z
CRIT

CVE-2026-18265 — OSNEXUS: QuantaStor Missing Authentication Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18265

OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of Kapacitor. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDOsnexusTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 17:17Z
HIGH

CVE-2026-18264 — NoMachine: getstat Command Injection Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18264

NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4000 by default. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage t CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDNomachineTYPVulnerability
8.8
CVSS v3.1
94
Edit Score