2026-08-11
2026-08-11 22:18Z
HIGH

CVE-2026-66875 — Mira: In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66875

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates. CVSSv3.1 8.8 (HIGH)

CWECWE 306VNDMiraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 22:17Z
CRIT

CVE-2026-5917 — libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5917

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters be CVSSv3.1 9.6 (CRITICAL)

CWECWE 78TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-11
2026-08-11 22:17Z
HIGH

CVE-2026-19560 — Use: after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19560

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 22:17Z
HIGH

CVE-2026-19559 — Use: after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19559

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 22:17Z
HIGH

CVE-2026-19557 — Use: after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19557

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 22:17Z
HIGH

CVE-2026-19556 — Use: after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19556

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 21:17Z
CRIT

CVE-2026-71290 — TLS: Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71290

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are CVSSv3.1 9.1 (CRITICAL)

CWECWE 295VNDTlsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-11
2026-08-11 21:17Z
HIGH

CVE-2026-66154 — An insufficient certificate validation in a privileged communication workflow, was identified in a GMS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66154

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes. CVSSv3.1 8.3 (HIGH)

CWECWE 295TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 21:17Z
CRIT

CVE-2026-66147 — An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66147

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests. CVSSv3.1 9.4 (CRITICAL)

CWECWE 94TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-11
2026-08-11 21:17Z
HIGH

CVE-2026-55676 — Malcolm: The allow-list that should restrict accepted file types is an empty array by default

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55676

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the `.php` extension intact. Committed file CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDMalcolmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 21:17Z
CRIT

CVE-2026-48765 — TypeBot: Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48765

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an attacker-controlled writable `workspaceId`. The update path validates only the attacker-supplied workspace and then updates the credential record by global `id` alone, while also rewriting the credential's `wo CVSSv3.1 9.9 (CRITICAL)

CWECWE 639VNDTypebotTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 21:17Z
HIGH

CVE-2026-48763 — TypeBot: Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48763

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact key. Because the endpoint only checks that the referenced typebot is public and that the referenced block is a file input block, an unauthenticated attacker who knows a valid public `typebotId` and `block CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDTypebotTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 21:17Z
HIGH

CVE-2026-19550 — FreeIPA: The trust-fetch-domains command is gated by a read-only permission on the trust object rather

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19550

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory. CVSSv3.1 8.2 (HIGH) · EPSS 9th percentile

CWECWE 863VNDFreeipaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 21:17Z
HIGH

CVE-2026-18634 — A local attacker with the ability to interact with the service could exploit this

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18634

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component. CVSSv3.1 8.4 (HIGH)

CWECWE 502TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 21:17Z
HIGH

CVE-2026-15606 — Frontend: The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15606

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to reset the password of any user on the site, including administrators, leading to full account takeover and complete site compromise. Exploitation CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDFrontendTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 21:17Z
HIGH

CVE-2026-14863 — FileRun: up to and including version 2026.2.0 contains an OS command injection vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14863

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quotes directly to exec() without escapeshellarg() sanitization, allowing filenames such as $(PAYLOAD).mp4 to survive the filename sanitizer and be eva CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDFilerunTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 21:10Z
CRIT

Patch Tuesday - August 2026

Microsoft released 421 vulnerabilities in August 2026 Patch Tuesday, including 236 Windows CVEs. Notable findings include a critical unauthenticated SharePoint RCE chain (CVE-2026-63520/CVE-2026-55040), an exploited-in-the-wild AFD elevation-of-privilege (CVE-2026-68820), and a Defender patch-bypass (ShieldBreak) from pseudonymous researcher Nightmare Eclipse. Multiple critical RCEs in Exchange Server, LSA, and Windows Deployment Services TFTP were also patched.

SRFApplicationSRFOsSWEdgeSWSharepointSWPowershellVNDMicrosoftTYPVulnerabilityTYPAdvisory
72
Edit Score
2026-08-11
2026-08-11 20:18Z
CRIT

CVE-2026-73034 — GPT: DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73034

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipart upload request with a traversal-poisoned user_id header to escape the intended upload directory and write attacker-controlled content to locations such as Python startup hooks, c CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDGptTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 20:18Z
CRIT

CVE-2026-73032 — PapersGPT: for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73032

PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt injection in PDFs, MITM interception of API requests, or a malicious custom LLM endpoint to execute arbitrary code in Zotero's chrome-privileged context, enabling file read/write, process execution, and a CVSSv3.1 9.6 (CRITICAL)

CWECWE 94VNDPapersgptTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-11
2026-08-11 20:18Z
HIGH

CVE-2026-73031 — telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73031

telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. The highlightKeyword function in MessageList.vue passes raw message content directly to v-html without HTML escaping or sanitization, enabling stored, cross-user, zero-click execution of injected payloads such as image onerror handlers when vict CVSSv3.1 8.7 (HIGH)

CWECWE 79TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 20:18Z
HIGH

CVE-2026-66145 — An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66145

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip. CVSSv3.1 8.3 (HIGH)

CWECWE 94TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 20:17Z
CRIT

CVE-2026-45618 — LiquidJS: Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDLiquidjsTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 20:17Z
HIGH

CVE-2026-19091 — GeoDirectory: The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19091

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDGeodirectoryTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 20:17Z
HIGH

CVE-2026-18844 — Pulsetto: The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18844

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on. CVSSv3.1 8.1 (HIGH)

CWECWE 912VNDPulsettoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 20:17Z
CRIT

CVE-2026-16230 — Formidable: The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16230

The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accept CVSSv3.1 9.8 (CRITICAL)

CWECWE 23VNDFormidableTYPVulnerability
9.8
CVSS v3.1
99
Edit Score