2026-08-13
2026-08-13 22:17Z
HIGH

CVE-2026-56865 — GOPROXY: A malicious GOPROXY was previously capable of forging up to two sumdb tiles that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56865

A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected: rm -r go.sum go.wor CVSSv3.1 8.4 (HIGH) · EPSS 1th percentile

CWECWE 347VNDGoproxyTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-13
2026-08-13 21:18Z
CRIT

CVE-2026-8715 — Vault: Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8715

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0. CVSSv3.1 9.6 (CRITICAL)

CWECWE 552VNDVaultTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-13
2026-08-13 21:17Z
CRIT

CVE-2026-19297 — IBM: Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19297

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. CVSSv3.1 9.1 (CRITICAL)

CWECWE 307VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 21:17Z
HIGH

CVE-2026-18509 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18509

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system. CVSSv3.1 8.2 (HIGH)

CWECWE 285VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 21:17Z
HIGH

CVE-2026-18249 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18249

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses. CVSSv3.1 8.4 (HIGH)

CWECWE 269VNDIbmTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-13
2026-08-13 21:17Z
HIGH

CVE-2026-18193 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18193

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses. CVSSv3.1 8.9 (HIGH)

CWECWE 269VNDIbmTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-08-13
2026-08-13 21:17Z
HIGH

CVE-2026-18101 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18101

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-13
2026-08-13 21:17Z
HIGH

CVE-2026-17502 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17502

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. CVSSv3.1 8.6 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 21:17Z
CRIT

CVE-2026-17482 — IBM: Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17482

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths. CVSSv3.1 9.8 (CRITICAL)

CWECWE 73VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 21:17Z
HIGH

CVE-2026-17481 — IBM: Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17481

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs. CVSSv3.1 8.8 (HIGH)

CWECWE 117VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 21:17Z
HIGH

CVE-2026-17272 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17272

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow. CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 21:17Z
HIGH

CVE-2026-17101 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17101

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication. CVSSv3.1 8.3 (HIGH)

CWECWE 287VNDIbmTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-13
2026-08-13 20:17Z
CRIT

CVE-2026-73656 — Trigger: Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeployme

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73656

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWorkerV4.server.ts, where workerDeployment.findFirst() selects a deployment by friendlyId without an environmentId predicate. A caller with a valid API key for one project can submit another project's d CVSSv3.1 9.9 (CRITICAL)

CWECWE 862CWECWE 639VNDTriggerTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-73654 — Trigger: A caller with a normal environment API key can pollute Object.prototype in the shared

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73654

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set(newMetadata, value) in packages/core/src/v3/runMetadata/operations.ts without rejecting dangerous constructor and prototype path segments. A caller with a normal environment API key can pollute Object.prototype in the shared webapp CVSSv3.1 8.5 (HIGH)

CWECWE 1321VNDTriggerTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-72665 — Authorization: Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72665

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally gov CVSSv3.1 8.1 (HIGH)

CWECWE 862TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-72642 — Elasticsearch: The result is heap corruption that crashes the inference process, and, with sufficient control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72642

The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required to upload and deploy a trained model can craft a model that reads and writes memory outside the intended allocation. The result is heap corruption that crashes t CVSSv3.1 8.8 (HIGH)

CWECWE 823VNDElasticsearchTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
CRIT

CVE-2026-19747 — This manipulation causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19747

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-18164 — An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18164

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state. CVSSv3.1 8.1 (HIGH)

CWECWE 798TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17223 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17223

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17206 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17206

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow. CVSSv3.1 8.1 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17069 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17069

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens. CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17045 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17045

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management. CVSSv3.1 8.1 (HIGH)

CWECWE 294VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17029 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17029

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16987 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16987

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable. CVSSv3.1 8.8 (HIGH)

CWECWE 73VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16975 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16975

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score