2026-08-11
2026-08-11 13:19Z
CRIT

CVE-2026-58115 — This could allow an unauthenticated remote attacker to create malicious flows through the HTTP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58115

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arb CVSSv3.1 10.0 (CRITICAL)

CWECWE 306TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 13:17Z
CRIT

CVE-2026-18972 — This can lead to an account takeover attack from a user with low privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18972

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator. CVSSv3.1 9.6 (CRITICAL)

CWECWE 290TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-11
2026-08-11 13:00Z
CRIT

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Rapid7 Research·rapid7.comCVE-2026-63520CVE-2026-55040

Rapid7 disclosed CVE-2026-63520, a .NET unsafe type instantiation RCE in Microsoft SharePoint (CVSS 8.1), which chains with the previously disclosed authentication bypass CVE-2026-55040 to achieve unauthenticated RCE. The vulnerability was discovered through AI-assisted vulnerability research using LLM agents guided by subject matter experts, and affects SharePoint Server Subscription Edition, 2019, 2016, Project Server 2013, and Office Web Apps 2013. Microsoft has patched both vulnerabilities across July and August 2026 updates.

SRFApplicationTACTA0001TACTA0002SRFWebSWSharepointSWOffice Web AppsSWProject ServerVNDMicrosoft
92
Edit Score
2026-08-11
2026-08-11 13:00Z
CRIT

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

Rapid7 Research·rapid7.comCVE-2026-55040

Rapid7 published a detailed technical analysis of CVE-2026-55040, a critical JWT authentication bypass in Microsoft SharePoint Server Subscription Edition. The vulnerability chains four distinct weaknesses in the JWT token validation pipeline—disabled signature verification (RequireSignedTokens=false), unverified x5t certificate resolution, improper issuer validation, and non-cryptographic signature checks—allowing unauthenticated attackers to forge valid JWTs and impersonate any SharePoint user or administrator. A proof-of-concept script demonstrates exploitation via the unauthenticated /_layouts/15/metadata/json/1 endpoint to retrieve the STS signing certificate.

SRFApplicationTACTA0001TACTA0006SRFWebSWSharepointVNDMicrosoftTYPVulnerabilitySTGInitial Access
92
Edit Score
2026-08-11
2026-08-11 12:17Z
CRIT

CVE-2026-72603 — An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72603

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves CVSSv3.1 9.9 (CRITICAL)

CWECWE 78TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 12:17Z
CRIT

CVE-2026-72599 — SQL: An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72599

An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can read, modify, or delete all database contents including administrator credentials. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72596 — A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72596

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72595 — A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72595

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the TicketsController@update endpoint. The endpoint calls no authorize() method and performs no team-scoped ownership check. An attacker with any agent account can modify, escalate, or corrupt tickets assigned to other teams. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72563 — A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72563

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to other teams via the LeadsController@update endpoint. The endpoint performs no authorization check, and the Lead model has guarded set to an empty array making all columns mass-assignable. An attacker with any agent account can corrupt lead data across team boundaries. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72562 — SQL: An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72562

An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can exfiltrate or modify all database contents. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72561 — A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72561

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role check before applying new OIDC issuer settings. An attacker can redirect all SSO logins to an attacker-controlled identity provider, enabling credential harvesting for all platform users. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72558 — SQL: An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72558

An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72557 — An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72557

An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and uploaded files are stored in a web-accessible directory. An attacker with any authenticated account can upload a PHP webshell and execute arbitrary OS commands on the server. CVSSv3.1 8.8 (HIGH)

CWECWE 434TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72556 — A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72556

A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent methods on the ZM\User class, causing PHP __call() to return a truthy value that bypasses the permission check for all users. Any authenticated user can trigger filter-based OS command execution regardless of their assigned role. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72555 — All authenticated users bypass ownership and administrative access controls.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72555

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and administrative access controls. An attacker with any user account can read, modify, or delete tickets, clients, and users belonging to any other account. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72551 — A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72551

A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exploiting a PHP-Sandbox allow-list bypass. The sandbox allow-list permits functions that transitively invoke system(), enabling a developer to escape the sandbox and gain OS command execution on the server. An attacker with a Developer-role account can achieve full server compromise. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
CRIT

CVE-2026-72550 — SQL: An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72550

An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter is concatenated unescaped into a SHOW COLUMNS query via a bare PDO::query() call, enabling stacked statement injection. An unauthenticated attacker can read, modify, or delete the entire database. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72538 — PrefectHQ: An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72538

An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The branch parameter is passed directly to git pull without sanitization, enabling injection of arbitrary git arguments. This represents a distinct code path from the incomplete fix applied for CVE-2026-5366 and allows command execution on the Prefect server. CVSSv3.1 8.8 (HIGH)

CWECWE 88VNDPrefecthqTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72537 — Authentik: A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72537

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts by username without validating scope boundaries. An attacker can rewrite or delete any account, including the superuser, using only a lim CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDAuthentikTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72536 — Chaskiq: A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72536

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe payment intent creation to unauthenticated callers. An attacker can create payment intents and alter billing for any tenant without credentials. CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDChaskiqTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72535 — Chaskiq: A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72535

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. The mutation performs no authentication or authorization checks before creating a customer portal session linked to any tenant Stripe account. An attacker can access and manage subscription data for any tenant without credentials. CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDChaskiqTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72534 — Authentik: A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72534

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group by name and replaces its membership without validating the source scope against the target group. An attacker can grant their provisioning token full IdP superus CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDAuthentikTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72533 — Portainer: An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72533

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls, allowing crafted requests to be interpreted differently by the proxy and the authorization layer. Successful exploitation grants the attacker root-level access to CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDPortainerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
CRIT

CVE-2026-13739 — Commvault Commvault: A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13739

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center. CVSSv3.1 9.8 (CRITICAL) · EPSS 27th percentile

CWECWE 918VNDCommvaultVNDCommandTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 12:17Z
CRIT

CVE-2026-13738 — Commvault Commvault: CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13738

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. CVSSv3.1 9.8 (CRITICAL) · EPSS 44th percentile

CWECWE 863VNDCommvaultVNDCommserveTYPVulnerability
9.8
CVSS v3.1
99
Edit Score