2026-08-05
2026-08-05 20:17Z
HIGH

CVE-2026-66297 — Livebook Livebook: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66297

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.docker_instructions/2 and LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.fly_instructions/4 in lib/livebook_web/live/hub/teams/deployment_group_agent_component.ex interpolate deployment group environment variable values into th CVSSv3.1 8.0 (HIGH) · EPSS 68th percentile

CWECWE 78VNDLivebookTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-05
2026-08-05 20:17Z
HIGH

CVE-2026-18953 — Improper limitation of a pathname to a restricted directory in the get_resource tool in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18953

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should upgrade to version 0.1.5 or later. CVSSv3.1 8.6 (HIGH)

CWECWE 22TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 20:17Z
CRIT

CVE-2026-17556 — Github Enterprise_server: A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17556

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The X-GitHub-Request-Id request header was used without sanitization as a filesystem path segment for the upload buffer directory, so a traversal value pointed the buffer at an arbitrary path CVSSv3.1 9.1 (CRITICAL) · EPSS 38th percentile

CWECWE 22VNDGithubTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-05
2026-08-05 19:17Z
HIGH

CVE-2026-9201 — IBM: Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9201

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component code using a truncated SHA‑256 hash. Because the hash comparison relies on only a portion of the digest, an attacker can craft malicious component code that collid CVSSv3.1 8.8 (HIGH)

CWECWE 326VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 19:17Z
HIGH

CVE-2026-9196 — IBM: Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9196

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects such as outbound network access, file system interaction, or data exfiltration with the privileges of the Langflow backend pr CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 19:17Z
HIGH

CVE-2026-8478 — IBM: Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8478

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 19:17Z
HIGH

CVE-2026-8182 — IBM: Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8182

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-05
2026-08-05 19:17Z
CRIT

CVE-2026-48168 — PraisonAI: In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48168

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardless of whether the commenter is a trusted collaborator. An outside contributor can open a pull request from a fork whose branch name CVSSv3.1 10.0 (CRITICAL)

CWECWE 862VNDPraisonaiTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-05
2026-08-05 19:17Z
HIGH

CVE-2026-17633 — IBM: Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17633

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. CVSSv3.1 8.5 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 19:17Z
HIGH

CVE-2026-17632 — IBM: Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17632

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 19:17Z
HIGH

CVE-2026-17624 — IBM: Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17624

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports. CVSSv3.1 8.5 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 18:54Z
CRIT

CVE-2026-18556 and CVE-2026-18577 | N-able N-central Authentication Bypass Vulnerabilities

Horizon3.ai·horizon3.aiCVE-2026-18556CVE-2026-18577in the wild

N-able N-central RMM platform contains two chained authentication bypass vulnerabilities (CVSS 7.4 and 8.1) allowing unauthenticated attackers to gain administrative access. CVE-2026-18577 is a residual bypass resulting from incomplete remediation of CVE-2026-18556; both are actively exploited in the wild and listed in CISA's KEV catalog. Patch to N-central 2026.3 Hotfix 1 (build 2026.3.1.7) or later.

SRFApplicationTACTA0001SRFNetworkSWN CentralVNDN AbleTYPVulnerabilityTYPAdvisorySTGInitial Access
92
Edit Score
2026-08-05
2026-08-05 18:17Z
HIGH

CVE-2026-70432 — CSRF: A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70432

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM. CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDCsrfTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 18:17Z
HIGH

CVE-2026-70431 — Jenkins: Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70431

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 18:17Z
HIGH

CVE-2026-70429 — Jenkins: 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70429

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances. CVSSv3.1 8.1 (HIGH)

CWECWE 178VNDJenkinsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 18:17Z
CRIT

CVE-2026-70426 — Remoting: In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70426

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath. CVSSv3.1 9.0 (CRITICAL)

CWECWE 502VNDRemotingTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-9077 — IBM: Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9077

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. CVSSv3.1 8.5 (HIGH)

CWECWE 807VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-20312 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20312

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312. CVSSv3.1 8.8 (HIGH)

CWECWE 312TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 17:16Z
CRIT

CVE-2026-20310 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20310

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59. CVSSv3.1 9.1 (CRITICAL)

CWECWE 59TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-05
2026-08-05 17:16Z
CRIT

CVE-2026-20304 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20304

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-05
2026-08-05 17:16Z
CRIT

CVE-2026-20303 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20303

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-20301 — Extensible: A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20301

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful explo CVSSv3.1 8.6 (HIGH)

CWECWE 606VNDExtensibleTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-20273 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20273

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20. CVSSv3.1 8.6 (HIGH)

CWECWE 20TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 17:16Z
CRIT

CVE-2026-20272 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20272

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CVSSv3.1 9.8 (CRITICAL)

CWECWE 74TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-20271 — The vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20271

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-691. & CVSSv3.1 8.6 (HIGH)

CWECWE 691TYPVulnerability
8.6
CVSS v3.1
93
Edit Score