2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17069 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17069

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens. CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17045 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17045

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management. CVSSv3.1 8.1 (HIGH)

CWECWE 294VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-17029 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17029

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16987 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16987

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable. CVSSv3.1 8.8 (HIGH)

CWECWE 73VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16975 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16975

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16967 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16967

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links. CVSSv3.1 8.5 (HIGH)

CWECWE 367VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16908 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16908

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability. CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16868 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16868

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing. CVSSv3.1 8.1 (HIGH)

CWECWE 908VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16867 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16867

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16815 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16815

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow. CVSSv3.1 8.6 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16722 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16722

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
HIGH

CVE-2026-16674 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16674

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path. CVSSv3.1 8.8 (HIGH)

CWECWE 426VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 20:17Z
CRIT

CVE-2026-14525 — IBM: WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDIbmTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 19:17Z
CRIT

CVE-2026-73653 — Vitest: Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73653

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or d CVSSv3.1 9.4 (CRITICAL)

CWECWE 862CWECWE 552CWECWE 22VNDVitestTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-73650 — SVGO: Applications that process untrusted SVG input with this plugin enabled and serve the result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73650

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as <svg:script> and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted CVSSv3.1 8.2 (HIGH)

CWECWE 79CWECWE 184VNDSvgoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-73482 — RC5: phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73482

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central verifyCsrfGetToken check uses enforce=false and is bypassed when the token parameter is absent). A remote attacker can trick a logged-in super-administrator into loading a crafted URL (e.g., embedded as an image CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDRc5TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-72777 — Next: Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72777

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses including cloud metadata. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-17220 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17220

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow. CVSSv3.1 8.2 (HIGH)

CWECWE 120VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 19:17Z
HIGH

CVE-2026-17197 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 18:18Z
CRIT

CVE-2026-73649 — Velocity: Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73649

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained unfiltered. The getReferences() flow called getAttributes(), whose property access allowed an attacker-controlled template to traverse constructor.constructor to the Java CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDVelocityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 18:18Z
CRIT

CVE-2026-73644 — OpenDJ: Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73644

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy ACI scope when an authzid resolved to a different user. Both dn: and u: or bare authzid forms could therefore let an authenticated account holding PROXIED_AUTH assume any resolvable non-root identity CVSSv3.1 9.6 (CRITICAL)

CWECWE 639CWECWE 285VNDOpendjTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-13
2026-08-13 18:18Z
CRIT

CVE-2026-73567 — JavaScript: sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73567

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by jsbn@1.1.0, which seeds an ARC4 stream from Math.random() and new Date().getTime() because window.crypto.getRandomValues is unavailable even though globalThis.crypto exists. An attacker who can observe the process's Ma CVSSv3.1 9.1 (CRITICAL)

CWECWE 338TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 18:18Z
HIGH

CVE-2026-72741 — Rainbond: through 6.9.7 contains a broken access control vulnerability in the CheckToken function that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72741

Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDRainbondTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 18:18Z
CRIT

CVE-2026-67614 — CyberPanel: before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67614

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDCyberpanelTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 18:17Z
HIGH

CVE-2026-18428 — SQL: A SQL query validation bypass in the Flint extension query handler in the OpenSearch

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18428

A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint. CVSSv3.1 8.8 (HIGH)

CWECWE 693TYPVulnerability
8.8
CVSS v3.1
94
Edit Score