2026-08-17
2026-08-17 18:16Z
HIGH

CVE-2026-33437 — Stirling: Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted PDF Title and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33437

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted PDF Title and Author metadata into the summary-text element with innerHTML, allowing a malicious PDF to execute stored cross-site scripting when a user clicks Get Info and to access browser-session data or modify page content. This issue is fixed in vers CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDStirlingTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 17:16Z
HIGH

CVE-2026-9771 — By supplying a pointer to a forged struct device whose api table contains attacker-chosen

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9771

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the fix it validated only the output buffer (K_SYSCALL_MEMORY_WRITE) and passed the two struct device * arguments, src_dev and dst_dev, directly into the implementation without any object validation — unlike every sibling flash syscall, which guards its device poi CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 822TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-17
2026-08-17 16:17Z
HIGH

CVE-2026-75060 — JetBrains: In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75060

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools CVSSv3.1 8.4 (HIGH)

CWECWE 306VNDJetbrainsTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-17
2026-08-17 16:17Z
HIGH

CVE-2026-75051 — JetBrains: In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75051

In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDJetbrainsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 16:17Z
HIGH

CVE-2026-75048 — JetBrains: In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75048

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDJetbrainsTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 16:17Z
CRIT

CVE-2026-75045 — JetBrains: In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75045

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature CVSSv3.1 9.1 (CRITICAL)

CWECWE 288VNDJetbrainsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-17
2026-08-17 16:17Z
HIGH

CVE-2026-75044 — JetBrains: In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75044

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDJetbrainsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-17
2026-08-17 16:17Z
CRIT

CVE-2026-71479 — New: Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71479

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into accoun CVSSv3.1 9.1 (CRITICAL)

CWECWE 190CWECWE 682VNDNewTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-17
2026-08-17 16:17Z
CRIT

CVE-2026-64859 — New: Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64859

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omit("password"), allowing an authenticated administrator to obtain the root user's bearer token and access root-only system configuration APIs. This issue is fixed in version 1.0.0-rc.7 CVSSv3.1 9.1 (CRITICAL)

CWECWE 200VNDNewTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-17
2026-08-17 16:16Z
CRIT

CVE-2026-55674 — Discourse: Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55674

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Discourse page. Because the cookie value was rendered into a color scheme tag without escaping, the attacker could break out of the attribute and inject a tag that bypassed Discourse's nonce-based Content Security Policy, resulting CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDDiscourseTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-17
2026-08-17 15:16Z
CRIT

CVE-2026-71566 — FakeFish: This allows any user of the cluster to control VMs of the user that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71566

FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. This allows any user of the cluster to control VMs of the user that created fakefish, power them on and off, and mount arbitrary CD images to them. CVSSv3.1 9.3 (CRITICAL)

CWECWE 306VNDFakefishTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-17
2026-08-17 14:20Z
HIGH

CVE-2026-19693 — extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19693

extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory. CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 59TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-17
2026-08-17 14:20Z
HIGH

CVE-2026-16138 — Progress: In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16138

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host. CVSSv3.1 8.0 (HIGH)

CWECWE 502VNDProgressTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-17
2026-08-17 13:16Z
HIGH

CVE-2026-74997 — Roundcube: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74997

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDRoundcubeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-17
2026-08-17 13:16Z
CRIT

CVE-2026-14564 — Insufficiently: Logsign SIEM allows Retrieve Embedded Sensitive Data.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14564

Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114. CVSSv3.1 9.0 (CRITICAL)

CWECWE 522VNDInsufficientlyTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-17
2026-08-17 12:18Z
CRIT

CVE-2026-74843 — Wavlink: Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74843

A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure. CVSSv3.1 10.0 (CRITICAL)

CWECWE 121CWECWE 119VNDWavlinkTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-17
2026-08-17 11:29Z
CRIT

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 Research·rapid7.comin the wild

Rapid7 Labs discovered an exposed server hosting the complete infrastructure for Operation ASTERIX, an active cryptocurrency fraud pipeline combining account enumeration, multi-channel social engineering (phishing + vishing), and counterfeit wallet applications to steal seed phrases. The operation leveraged AI coding assistants (Claude, GitHub Copilot) throughout development, including attempts to bypass LLM safety controls via jailbreak prompts, and coordinated attacks across 54 countries using Asterisk telephony automation, enriched lead databases, and Telegram exfiltration.

SRFApplicationSRFMobileTACTA0001TACTA0002TACTA0006SRFWebTACTA0009SWClaude
92
Edit Score
2026-08-17
2026-08-17 11:16Z
CRIT

CVE-2026-74901 — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74901

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection. CVSSv3.1 9.8 (CRITICAL)

CWECWE 347TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 11:16Z
CRIT

CVE-2026-74900 — openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74900

openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the private key can compute the shared secret and decrypt all ciphertext, as the fallback triggers on any KEM failure without raising an error. CVSSv3.1 9.8 (CRITICAL)

CWECWE 391TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 11:16Z
CRIT

CVE-2026-74899 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74899

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands. CVSSv3.1 9.8 (CRITICAL)

CWECWE 95TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 11:16Z
CRIT

CVE-2026-74896 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74896

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 693TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 11:16Z
CRIT

CVE-2026-74895 — openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74895

openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules. CVSSv3.1 9.8 (CRITICAL)

CWECWE 693TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 11:16Z
CRIT

CVE-2026-74894 — openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74894

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-17
2026-08-17 11:16Z
HIGH

CVE-2026-74893 — openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74893

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs. CVSSv3.1 8.8 (HIGH)

CWECWE 798TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-17
2026-08-17 11:16Z
CRIT

CVE-2026-74891 — openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74891

openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798TYPVulnerability
9.8
CVSS v3.1
99
Edit Score