<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
    <title>CVE Brief - Daily Security Intelligence</title>
    <link>https://cvebrief.com</link>
    <description>Critical security vulnerabilities, curated daily for security professionals</description>
    <language>en-us</language>
    <pubDate>Sun, 09 Aug 2026 09:11:31 GMT</pubDate>
    <lastBuildDate>Sun, 09 Aug 2026 09:11:31 GMT</lastBuildDate>
    <managingEditor>editor@cvebrief.com (CVE Brief Team)</managingEditor>
    <webMaster>webmaster@cvebrief.com (CVE Brief Team)</webMaster>
    <atom:link href="https://cvebrief.com/rss.xml" rel="self" type="application/rss+xml" />
    <image>
        <url>https://cvebrief.com/android-chrome-192x192.png</url>
        <title>CVE Brief - Daily Security Intelligence</title>
        <link>https://cvebrief.com</link>
        <width>192</width>
        <height>192</height>
    </image>
    <item>
        <title>CVE Brief - August 9, 2026</title>
        <link>https://cvebrief.com/archive/2026/08/09/</link>
        <description>27 critical vulnerabilities and 55 high priority updates for August 9, 2026</description>
        <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/08/09/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - August 9, 2026</h2>
<ul>
<li><strong>27</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>55</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>38%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-71991</strong> (CVSS 9.8) - MSI Radix AXE6600: A command injection vulnerability in the TelnetSSH function of the MSI Radix AXE6600 router allows unauthenticated remote attackers to execute arbitrary system commands with root privileges.</li>
<li><strong>CVE-2026-71990</strong> (CVSS 9.8) - MSI Radix AXE6600: A command injection vulnerability in the TelnetSSH function of the MSI Radix AXE6600 router allows unauthenticated remote attackers to execute arbitrary system commands via the SSH configuration interface.</li>
<li><strong>CVE-2026-15210</strong> (CVSS 9.1) - WordPress OTP Login With Phone Number, OTP Verification: The OTP Login With Phone Number, OTP Verification plugin fails to limit verification attempts, allowing unauthenticated attackers to bypass authentication and hijack accounts.</li>
<li><strong>CVE-2026-71992</strong> (CVSS 9.8) - MSI Radix AXE6600: A command injection vulnerability in the macfilter function of the MSI Radix AXE6600 router allows unauthenticated remote attackers to execute arbitrary system commands with root privileges.</li>
<li><strong>CVE-2026-71993</strong> (CVSS 9.8) - MSI Radix AXE6600: The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the openvpn and macfilter functions, allowing unauthenticated remote attackers to execute arbitrary system commands.</li>
<li><strong>CVE-2026-71986</strong> (CVSS 9.8) - MSI Radix AXE6600: The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the dmz function, which allows unauthenticated remote attackers to execute arbitrary commands with root privileges.</li>
<li><strong>CVE-2026-71987</strong> (CVSS 9.8) - MSI Radix AXE6600: The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the alg function, allowing unauthenticated remote attackers to execute arbitrary commands on the device.</li>
<li><strong>CVE-2026-71988</strong> (CVSS 9.8) - MSI Radix AXE6600: MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability in the portFw function, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.</li>
<li><strong>CVE-2026-71989</strong> (CVSS 9.8) - MSI Radix AXE6600: MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability in the porTrigger function, allowing unauthenticated remote attackers to execute arbitrary commands as root.</li>
<li><strong>CVE-2026-71984</strong> (CVSS 9.8) - MSI Radix AXE6600: MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability in the urlfilter function, allowing unauthenticated remote attackers to execute arbitrary commands as root.</li>
<li><strong>CVE-2026-71985</strong> (CVSS 9.8) - MSI Radix AXE6600: A command injection vulnerability in the MSI Radix AXE6600 router firmware allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the accesscontrol function.</li>
<li><strong>CVE-2026-71983</strong> (CVSS 9.8) - MSI Radix AXE6600: MSI Radix AXE6600 router firmware contains a command injection vulnerability in the wps.cgi interface, allowing unauthenticated remote attackers to execute commands via the pin parameters.</li>
<li><strong>CVE-2026-71944</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 /boafrm/formLtefotaUpgradeQuectel interface allows unauthenticated remote attackers to execute arbitrary commands as root.</li>
<li><strong>CVE-2026-71945</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the fota_url parameter.</li>
<li><strong>CVE-2026-71946</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the host parameter in the ping interface.</li>
<li><strong>CVE-2026-71947</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the traceroute interface.</li>
<li><strong>CVE-2026-71948</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 /boafrm/formDebugDiagnosticRun interface allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.</li>
<li><strong>CVE-2026-71949</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 /boafrm/formUSSDSetup interface allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.</li>
<li><strong>CVE-2026-71950</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 /boafrm/formSmsManage interface allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.</li>
<li><strong>CVE-2026-71951</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 /boafrm/formIMEISetup interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.</li>
<li><strong>CVE-2026-71952</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 /boafrm/formPinManageSetup interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.</li>
<li><strong>CVE-2026-71953</strong> (CVSS 9.8) - D-Link DWR-M961: A command injection vulnerability in the D-Link DWR-M961 /boafrm/formNtp interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.</li>
<li><strong>CVE-2026-71954</strong> (CVSS 9.8) - D-Link DWR-M961: D-Link DWR-M961 routers contain a command injection vulnerability in the L2TPv3 configuration interface allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.</li>
<li><strong>CVE-2026-71957</strong> (CVSS 9.8) - D-Link DWR-M961: D-Link DWR-M961 routers are susceptible to a buffer overflow in the app.cgi interface, which allows unauthenticated remote attackers to execute arbitrary commands or crash the device.</li>
<li><strong>CVE-2026-71958</strong> (CVSS 9.8) - D-Link DWR-M961: D-Link DWR-M961 routers contain a buffer overflow vulnerability in the quicksetup.cgi interface, allowing unauthenticated attackers to execute arbitrary code via crafted input.</li>
<li><strong>CVE-2026-71956</strong> (CVSS 9.8) - D-Link DWR-M961: D-Link DWR-M961 routers contain a command injection vulnerability in the app.cgi interface, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.</li>
<li><strong>CVE-2026-71955</strong> (CVSS 9.8) - D-Link DWR-M961: D-Link DWR-M961 routers are vulnerable to command injection in the /boafrm/formWsc interface, enabling unauthenticated remote attackers to execute arbitrary commands as root.</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-14553</strong> (CVSS 8.1) - WordPress zportals: The zportals WordPress plugin lacks proper file validation, allowing authenticated users to upload arbitrary PHP files and achieve remote code execution.</li>
<li><strong>CVE-2026-56793</strong> (CVSS 7.7) - Dell OpenManage Server Administrator: Dell OpenManage Server Administrator contains an improper authentication vulnerability that may allow unauthorized access to the managed node.</li>
<li><strong>CVE-2026-62296</strong> (CVSS 7.5) - HAPI FHIR org.hl7.fhir.core: HAPI FHIR is vulnerable to uncontrolled resource consumption and recursion, which can lead to a denial of service condition.</li>
<li><strong>CVE-2026-62295</strong> (CVSS 7.5) - HAPI FHIR org.hl7.fhir.core: HAPI FHIR is vulnerable to improper input validation, which can lead to uncontrolled resource consumption and denial of service.</li>
<li><strong>CVE-2026-66061</strong> (CVSS 7.1) - Home Assistant core: Home Assistant core is affected by a missing authorization vulnerability that allows unauthorized parties to perform unauthorized actions.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/08/09/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
    <item>
        <title>CVE Brief - August 8, 2026</title>
        <link>https://cvebrief.com/archive/2026/08/08/</link>
        <description>11 critical vulnerabilities and 62 high priority updates for August 8, 2026</description>
        <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/08/08/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - August 8, 2026</h2>
<ul>
<li><strong>11</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>62</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>28%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-16258</strong> (CVSS 9.8) - WordPress Ajax Search Lite: The Ajax Search Lite WordPress plugin is vulnerable to PHP object injection due to improper deserialization of untrusted input, which can lead to remote code execution.</li>
<li><strong>CVE-2026-19264</strong> (CVSS 9.8) - gitroomhq postiz-app: A path traversal vulnerability in the Postiz social media scheduling tool allows unauthenticated remote attackers to read sensitive files and compromise system secrets.</li>
<li><strong>CVE-2026-17676</strong> (CVSS 9.6) - Google Chrome: An inappropriate implementation in the ANGLE graphics library allows a sandbox escape in Google Chrome on Android.</li>
<li><strong>CVE-2026-17681</strong> (CVSS 9.6) - Google Chrome: A sandbox escape vulnerability exists in Google Chrome on Android due to insufficient input validation in Web Authentication, potentially allowing a remote attacker to compromise the renderer process.</li>
<li><strong>CVE-2026-71558</strong> (CVSS 9.8) - Apache Software Foundation Apache Fory: A heap type confusion vulnerability in Apache Fory C++ allows remote attackers to trigger denial of service or arbitrary code execution via crafted payloads during polymorphic smart-pointer deserialization.</li>
<li><strong>CVE-2026-17666</strong> (CVSS 9.1) - Google Chrome: A cryptographic flaw in the enterprise component of Google Chrome allows unauthorized access control bypass via malicious network traffic.</li>
<li><strong>CVE-2026-14526</strong> (CVSS 9.8) - wupsales AI Copilot – Content Generator: An authorization bypass in the AI Copilot WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site takeover.</li>
<li><strong>CVE-2026-14205</strong> (CVSS 9.8) - WordPress WP Events Manager: The WP Events Manager WordPress plugin contains a vulnerability that allows authenticated users to bypass payment requirements when registering for paid events.</li>
<li><strong>CVE-2022-4995</strong> (CVSS 9.8) - Weaver Network Co. E-cology 9.0: Weaver E-cology 9.0 contains a file upload vulnerability allowing remote, unauthenticated attackers to execute arbitrary code via malicious JSP files.</li>
<li><strong>CVE-2026-61808</strong> (CVSS 9.8) - HKUDS LightRAG: LightRAG versions through 1.5.4 expose an unauthenticated API server, allowing remote attackers to manipulate knowledge graphs, access documents, and consume LLM resources.</li>
<li><strong>CVE-2026-64637</strong> (CVSS 9.9) - WebPros Plesk: Plesk before 18.0.80.1 contains an improper privilege management vulnerability in its XML-RPC API that allows resellers to escalate to administrative root access.</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-19144</strong> (CVSS 8.8) - Google Chrome: A use after free vulnerability in the HTML component of Google Chrome allows for potential arbitrary code execution.</li>
<li><strong>CVE-2026-19141</strong> (CVSS 8.3) - Google Chrome: A use after free vulnerability in the Resources component of Google Chrome on Android allows for potential arbitrary code execution.</li>
<li><strong>CVE-2026-19147</strong> (CVSS 8.3) - Google Chrome: A use after free vulnerability in the Aura component of Google Chrome on Linux allows for potential arbitrary code execution.</li>
<li><strong>CVE-2026-64638</strong> (CVSS 8.9) - WordPress WordPress: WordPress contains a reflected cross-site scripting vulnerability on the login screen that allows unauthenticated attackers to execute malicious scripts in the context of a user session.</li>
<li><strong>CVE-2026-48169</strong> (CVSS 8.8) - MervinPraison praisonai-platform: The PraisonAI platform is susceptible to authorization bypass and missing authorization checks, allowing authenticated users to perform unauthorized actions.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/08/08/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
    <item>
        <title>CVE Brief - August 7, 2026</title>
        <link>https://cvebrief.com/archive/2026/08/07/</link>
        <description>20 critical vulnerabilities and 32 high priority updates for August 7, 2026</description>
        <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/08/07/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - August 7, 2026</h2>
<ul>
<li><strong>20</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>32</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>26%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-70558</strong> (CVSS 9.8) - DataLinkDC Dinky: Dinky contains an unrestricted file upload vulnerability due to insufficient path validation and a hardcoded, default authentication token, allowing unauthenticated remote code execution.</li>
<li><strong>CVE-2026-14812</strong> (CVSS 10) - Unknown Premium SEO: The Premium SEO WordPress plugin contains a malicious backdoor that enables unauthenticated attackers to create admin accounts, execute code, and inject arbitrary content into the site.</li>
<li><strong>CVE-2026-17726</strong> (CVSS 9.6) - Google Chrome: An integer overflow vulnerability in WebGL within Google Chrome on Android enables remote attackers to perform a sandbox escape through a specially crafted HTML page.</li>
<li><strong>CVE-2026-17727</strong> (CVSS 9.6) - Google Chrome: An out of bounds write vulnerability in WebGL for Google Chrome on Android permits remote attackers to escape the browser sandbox via a crafted HTML page.</li>
<li><strong>CVE-2026-11976</strong> (CVSS 10) - MonsterInsights MonsterInsights Pro: The official MonsterInsights Pro update distribution bucket was compromised, resulting in the delivery of a malicious file that grants an attacker persistent write access and control.</li>
<li><strong>CVE-2026-67622</strong> (CVSS 9.9) - FlowiseAI Flowise: Flowise through 3.1.4 contains an insecure direct object reference vulnerability in its OpenAI Assistants integration that allows authenticated attackers to access data across different workspaces.</li>
<li><strong>CVE-2026-17032</strong> (CVSS 9.8) - Supsystic Google Maps Easy Pro, Supsystic Gallery Pro, Tables Generator Pro: Multiple Supsystic Pro plugins were distributed with malicious code via a compromised update server, allowing unauthenticated attackers to steal sensitive data and gain control of affected sites.</li>
<li><strong>CVE-2026-14364</strong> (CVSS 9.8) - themetechmount TrueBooker – Appointment Booking and Scheduler System: The TrueBooker WordPress plugin is vulnerable to account takeover due to improper password reset validation, allowing unauthenticated attackers to reset passwords for arbitrary user accounts.</li>
<li><strong>CVE-2026-14365</strong> (CVSS 9.8) - themetechmount TrueBooker – Appointment Booking and Scheduler System: The TrueBooker WordPress plugin is vulnerable to authorization bypass, allowing unauthenticated attackers to perform unauthorized actions such as changing user passwords.</li>
<li><strong>CVE-2026-48087</strong> (CVSS 9.8) - open-reception appointment-booking-software: An improper authentication vulnerability in the OpenReception registration handler allows unauthenticated attackers to hijack user passkeys and gain unauthorized account access.</li>
<li><strong>CVE-2026-48086</strong> (CVSS 9.9) - open-reception appointment-booking-software: An improper privilege management vulnerability exists where tenant administrators can escalate their own privileges to platform-wide global administrator status.</li>
<li><strong>CVE-2026-64399</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE

The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the
destination file's data via vfs_clone_file_range() with neither the
share-level KSMBD_TREE_CON</li>
<li><strong>CVE-2026-64410</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: IPIP tunnel hardware offload is not yet support

No driver supports for IPIP tunnels yet, give up early on setting up the
hardware offload for this scenario.

This patch adds a stub that can be enhanced to add</li>
<li><strong>CVE-2026-64439</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

crypto: krb5 - filter out async aead implementations at alloc

krb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and
rfc8009_encrypt(), rfc8009_decrypt() in rfc8009_aes2.c set a NULL
completion callback and treat any</li>
<li><strong>CVE-2026-64459</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

tcp: restore RCU grace period in tcp_ao_destroy_sock

Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU")
removed the call_rcu() callback from tcp_ao_destroy_sock(), arguing that
"the destruction of info/keys is </li>
<li><strong>CVE-2026-59139</strong> (CVSS 9.1) - EGOR Data::ReqRep::Shared: Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked.

The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not validate the array conten</li>
<li><strong>CVE-2026-59140</strong> (CVSS 9.1) - EGOR Data::SortedSet::Shared: Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths.

The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries</li>
<li><strong>CVE-2026-59142</strong> (CVSS 9.1) - EGOR Data::HashMap::Shared: Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy.

The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it th</li>
<li><strong>CVE-2026-64392</strong> (CVSS 9.1) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

ksmbd: use opener credentials for delete-on-close

Delete-on-close can be completed by deferred or durable handle teardown,
where no request work is available. Both the base-file unlink and the ADS
xattr removal consequently run wi</li>
<li><strong>CVE-2026-48085</strong> (CVSS 9.8) - open-reception appointment-booking-software: A missing authorization vulnerability in the OpenReception setup handler allows unauthenticated attackers to create new global administrator accounts on already configured instances.</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-19145</strong> (CVSS 8.8) - Google Chrome: A use after free vulnerability exists in the Translate component of Google Chrome, which could allow a remote attacker to execute arbitrary code.</li>
<li><strong>CVE-2026-19151</strong> (CVSS 8.8) - Google Chrome: A use after free vulnerability in the V8 JavaScript engine of Google Chrome may permit a remote attacker to execute arbitrary code.</li>
<li><strong>CVE-2026-19137</strong> (CVSS 8.3) - Google Chrome: A use after free vulnerability in the WebGL implementation of Google Chrome on Android allows a remote attacker to execute arbitrary code.</li>
<li><strong>CVE-2026-19138</strong> (CVSS 8.3) - Google Chrome: A heap buffer overflow vulnerability exists in the CrashReporting component of Google Chrome, potentially allowing remote code execution under specific conditions.</li>
<li><strong>CVE-2026-19140</strong> (CVSS 8.3) - Google Chrome: A use after free vulnerability in the GPU component of Google Chrome may allow a remote attacker to execute arbitrary code via a crafted webpage.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/08/07/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
    <item>
        <title>CVE Brief - August 6, 2026</title>
        <link>https://cvebrief.com/archive/2026/08/06/</link>
        <description>63 critical vulnerabilities and 83 high priority updates for August 6, 2026</description>
        <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/08/06/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - August 6, 2026</h2>
<ul>
<li><strong>63</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>83</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>24%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-66909</strong> (CVSS 9.8) - Apache Software Foundation Apache CXF: Apache CXF is vulnerable to remote code execution due to insecure native Java deserialization of inbound JMS ObjectMessages without type restrictions.</li>
<li><strong>CVE-2026-71268</strong> (CVSS 9.9) - thiagoralves OpenPLC_v3: OpenPLC Runtime v3 contains a path traversal vulnerability in its compile_program function, allowing remote authenticated users to write arbitrary files to the filesystem.</li>
<li><strong>CVE-2026-16940</strong> (CVSS 10) - Unknown Custom Fields (WordPress Plugin): The Custom Fields WordPress plugin before version 1.5.1 is vulnerable to path traversal, allowing unauthenticated attackers to delete arbitrary files on the server.</li>
<li><strong>CVE-2026-70615</strong> (CVSS 9.9) - boringproxy boringproxy: A CRLF injection vulnerability in boringproxy allows authenticated users to manipulate the SSH authorized_keys file, leading to persistent unauthorized access and credential theft.</li>
<li><strong>CVE-2026-57817</strong> (CVSS 9.8) - Apache Software Foundation Apache CXF: Apache CXF fails to validate the c_hash parameter in OpenID Connect Hybrid Flow, allowing for Authorization Code Substitution or Injection attacks when integrated with certain Identity Providers.</li>
<li><strong>CVE-2026-20272</strong> (CVSS 9.8) - Cisco IOS XE Software: Cisco IOS XE Software contains multiple injection vulnerabilities due to improper neutralization of special elements, addressed in recent software hardening releases.</li>
<li><strong>CVE-2026-65553</strong> (CVSS 10) - wbolt.com Spider Analyser: The Spider Analyser WordPress plugin contains an unauthenticated Remote Code Execution vulnerability, allowing attackers to execute arbitrary code on the underlying server.</li>
<li><strong>CVE-2026-8709</strong> (CVSS 9.9) - Progress Software MarkLogic Server: Progress MarkLogic Server contains an improper privilege management vulnerability in its REST API, allowing low-privileged users to perform unauthorized operations against the Security database.</li>
<li><strong>CVE-2026-71278</strong> (CVSS 9.8) - iot-ecology rust-iot-platform: The rust-iot-platform software lacks authentication on a calc rule creation endpoint, allowing unauthenticated attackers to execute arbitrary JavaScript code via unsanitized input.</li>
<li><strong>CVE-2026-10090</strong> (CVSS 9.9) - Red Hat Advanced Cluster Management for Kubernetes: A privilege escalation vulnerability in the Red Hat Advanced Cluster Management Application Subscription controller allows authenticated users to gain cluster-admin privileges.</li>
<li><strong>CVE-2026-71231</strong> (CVSS 9.8) - thebradleysanders IOTSmartHome: The IOTSmartHome platform is vulnerable to SQL injection via the lastLogin cookie, allowing unauthenticated attackers to bypass authentication and extract sensitive database information.</li>
<li><strong>CVE-2026-48168</strong> (CVSS 10) - MervinPraison PraisonAI: PraisonAI versions prior to 4.6.40 contain a command injection vulnerability in its GitHub Actions workflow, allowing unauthenticated attackers to execute arbitrary shell code.</li>
<li><strong>CVE-2026-9193</strong> (CVSS 9.9) - Progress Software MarkLogic Server: Progress Software MarkLogic Server contains an improper privilege management flaw in its Hadoop integration, enabling authenticated users to escalate privileges and compromise the Security database.</li>
<li><strong>CVE-2026-28139</strong> (CVSS 9.8) - wpdreams Ajax Search Lite: The Ajax Search Lite plugin for WordPress is susceptible to unauthenticated PHP object injection, which can lead to remote code execution or unauthorized data manipulation.</li>
<li><strong>CVE-2026-53975</strong> (CVSS 9.8) - Bohdan Triapitsyn OpenChamber: OpenChamber contains an unauthenticated remote code execution flaw in the /api/fs/exec endpoint, allowing attackers to execute arbitrary shell commands on the host system.</li>
<li><strong>CVE-2026-65552</strong> (CVSS 9.8) - qstudio Export User Data: The Export User Data WordPress plugin is vulnerable to PHP object injection, which allows unauthenticated attackers to execute arbitrary code or manipulate data via deserialization of untrusted input.</li>
<li><strong>CVE-2026-65556</strong> (CVSS 9.8) - MihChe WPBruiser {no- Captcha anti-Spam}: The WPBruiser {no- Captcha anti-Spam} WordPress plugin is vulnerable to unauthenticated PHP object injection, enabling attackers to execute arbitrary code via the deserialization of untrusted data.</li>
<li><strong>CVE-2026-65571</strong> (CVSS 9.8) - Axiomthemes 69 Clothing: The 69 Clothing WordPress theme is affected by an unauthenticated PHP object injection vulnerability, which enables attackers to execute arbitrary code through the deserialization of untrusted input.</li>
<li><strong>CVE-2026-65572</strong> (CVSS 9.8) - Axiomthemes A.Williams: The Axiomthemes A.Williams WordPress theme is vulnerable to unauthenticated PHP object injection, which may allow remote code execution.</li>
<li><strong>CVE-2026-65573</strong> (CVSS 9.8) - ThemeREX Abelle: The ThemeREX Abelle WordPress theme is susceptible to unauthenticated PHP object injection, potentially enabling remote code execution.</li>
<li><strong>CVE-2026-65574</strong> (CVSS 9.8) - AncoraThemes Abogado: The AncoraThemes Abogado WordPress theme contains an unauthenticated PHP object injection vulnerability, which could lead to remote code execution.</li>
<li><strong>CVE-2026-65575</strong> (CVSS 9.8) - AncoraThemes Accalia: The AncoraThemes Accalia WordPress theme is vulnerable to unauthenticated PHP Object Injection, allowing remote code execution via deserialization of untrusted user input.</li>
<li><strong>CVE-2026-65576</strong> (CVSS 9.8) - AncoraThemes Adrena: The AncoraThemes Adrena WordPress theme is susceptible to unauthenticated PHP Object Injection, enabling remote attackers to execute arbitrary code by manipulating serialized data.</li>
<li><strong>CVE-2026-65577</strong> (CVSS 9.8) - AncoraThemes Advice: The AncoraThemes Advice WordPress theme contains an unauthenticated PHP Object Injection flaw that could allow remote attackers to execute arbitrary code.</li>
<li><strong>CVE-2026-65578</strong> (CVSS 9.8) - AncoraThemes Agora: An unauthenticated PHP Object Injection vulnerability exists in AncoraThemes Agora versions 1.9 and earlier, allowing for potential remote code execution.</li>
<li><strong>CVE-2026-65579</strong> (CVSS 9.8) - axiomthemes Agricola: An unauthenticated PHP Object Injection vulnerability exists in the axiomthemes Agricola theme, specifically affecting versions 1.21.0 and earlier.</li>
<li><strong>CVE-2026-65581</strong> (CVSS 9.8) - Axiomthemes AI ANN: A critical PHP Object Injection vulnerability exists in the Axiomthemes AI ANN theme, allowing unauthenticated attackers to potentially execute arbitrary code.</li>
<li><strong>CVE-2026-5430</strong> (CVSS 10) - WSO2 WSO2 Universal Gateway: The WSO2 JWT authentication mechanism incorrectly validates tokens using unsupported algorithms, potentially allowing unauthenticated attackers to bypass security controls and gain unauthorized access.</li>
<li><strong>CVE-2025-63823</strong> (CVSS 9.8) - My Safetipin My Safetipin Android Application: The My Safetipin Android application version 5.2.1 contains hardcoded credentials and predictable OTP values, allowing for unauthorized account access.</li>
<li><strong>CVE-2026-67261</strong> (CVSS 9.8) - Dell Virtual Storage Integrator for VMware vSphere Client: An OS command injection vulnerability exists in the Dell Virtual Storage Integrator for VMware vSphere Client, allowing unauthenticated remote attackers to execute arbitrary code as root.</li>
<li><strong>CVE-2026-71289</strong> (CVSS 9.8) - NASA-AMMOS anms: The NASA-AMMOS ANMS reference implementation exposes its REST API directly to the network without authentication, allowing remote attackers to send unauthorized commands to DTNMA agents.</li>
<li><strong>CVE-2026-66747</strong> (CVSS 9.8) - Zbtlink CPE2801 Firmware: Multiple Zbtlink router models contain an embedded remote control implant that enables unauthenticated remote code execution with root privileges via a cleartext command channel.</li>
<li><strong>CVE-2026-43748</strong> (CVSS 9.8) - Apple macOS: An out-of-bounds write vulnerability in Apple macOS allows an application to cause unexpected system termination due to insufficient bounds checking.</li>
<li><strong>CVE-2026-43757</strong> (CVSS 9.8) - Apple macOS: An out-of-bounds read vulnerability in Apple macOS, addressed via improved bounds checking, allows an application to cause unexpected system termination.</li>
<li><strong>CVE-2026-43764</strong> (CVSS 9.8) - Apple macOS: An integer overflow vulnerability exists in Apple macOS that may allow a malicious application to cause unexpected system termination.</li>
<li><strong>CVE-2026-16410</strong> (CVSS 9.8) - Mozilla Firefox: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-20303</strong> (CVSS 9.9) - Cisco Catalyst SD-WAN Controller and Manager: Cisco Catalyst SD-WAN components are vulnerable to improper input validation, which could allow an authenticated attacker to compromise the system.</li>
<li><strong>CVE-2026-20304</strong> (CVSS 9.9) - Cisco Catalyst SD-WAN Controller and Manager: Cisco Catalyst SD-WAN components are vulnerable to improper access control, which could allow an authenticated attacker to gain unauthorized privileges.</li>
<li><strong>CVE-2026-68079</strong> (CVSS 9.8) - Apache Software Foundation Apache CXF: Apache CXF contains a flaw in the removeCodeGrant functionality, allowing an authorization code to be redeemed multiple times in violation of RFC specifications.</li>
<li><strong>CVE-2026-65548</strong> (CVSS 9.9) - Muffingroup Betheme: A critical remote code execution vulnerability exists in the Betheme WordPress theme, allowing authenticated contributors to execute arbitrary code on the underlying server.</li>
<li><strong>CVE-2026-9192</strong> (CVSS 9.8) - Progress Software MarkLogic Server: Progress MarkLogic Server contains an authentication bypass vulnerability in the ODBC App Server, allowing unauthenticated attackers to execute queries with administrative privileges.</li>
<li><strong>CVE-2026-71262</strong> (CVSS 9.8) - IoTSharp IoTSharp: IoTSharp fails to enforce authorization on its BlobStorageController, allowing unauthenticated remote attackers to perform arbitrary file operations via path traversal.</li>
<li><strong>CVE-2026-71254</strong> (CVSS 9.8) - debevv nanoMODBUS: An out-of-bounds write vulnerability in nanoMODBUS allows unauthenticated attackers to corrupt memory and potentially achieve remote code execution via a malformed Modbus request.</li>
<li><strong>CVE-2026-1728</strong> (CVSS 9.8) - WSO2 WSO2 API Manager: WSO2 API Manager suffers from improper privilege management where low-privileged tokens can access administrative REST APIs, potentially leading to full account takeover.</li>
<li><strong>CVE-2026-28005</strong> (CVSS 9.8) - Nexcess Kadence WooCommerce Email Designer: The Kadence WooCommerce Email Designer plugin for WordPress contains a missing authorization vulnerability that allows unauthenticated attackers to escalate privileges.</li>
<li><strong>CVE-2026-65507</strong> (CVSS 9.8) - Sergey AIWU: The AIWU plugin for WordPress is susceptible to an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment.</li>
<li><strong>CVE-2026-66662</strong> (CVSS 9.8) - Shabti Kaplan Frontend Admin by DynamiApps: The Frontend Admin by DynamiApps plugin for WordPress contains an unauthenticated privilege escalation vulnerability caused by incorrect privilege assignment.</li>
<li><strong>CVE-2026-5134</strong> (CVSS 9.8) - Loca Software Informatics Technology Ltd. CMS: An SQL injection vulnerability exists in Loca Software Informatics Technology Ltd. CMS, allowing unauthenticated attackers to execute arbitrary SQL commands.</li>
<li><strong>CVE-2026-71267</strong> (CVSS 9.8) - rxi microtar: A stack buffer overflow exists in rxi microtar due to improper boundary checks when copying filenames into the header structure.</li>
<li><strong>CVE-2026-66665</strong> (CVSS 10) - Brandexponents Type Hub: An unauthenticated arbitrary file upload vulnerability exists in the Brandexponents Type Hub plugin for WordPress, allowing remote code execution.</li>
<li><strong>CVE-2026-7329</strong> (CVSS 9.9) - Progress Software MarkLogic Server: Progress MarkLogic Server contains an improper privilege management vulnerability in its query interfaces allowing authenticated users with low-privileged roles to escalate to administrator.</li>
<li><strong>CVE-2026-71256</strong> (CVSS 9.8) - debevv nanoMODBUS: nanoMODBUS contains an out-of-bounds stack read and wild-pointer write vulnerability in its Modbus identification response handling, which can be triggered by a malicious server.</li>
<li><strong>CVE-2026-67873</strong> (CVSS 9.8) - mz-automation lib60870-C: A heap-based buffer overflow in lib60870-C 2.4.0 allows unauthenticated attackers to potentially achieve arbitrary code execution.</li>
<li><strong>CVE-2026-64232</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

block: recompute nr_integrity_segments in blk_insert_cloned_request

blk_insert_cloned_request() already recomputes nr_phys_segments
against the bottom queue, because "the queue settings related to
segment counting may differ from </li>
<li><strong>CVE-2026-64523</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

net/handshake: Take a long-lived file reference at submit

handshake_nl_accept_doit() needs the file pointer backing
req->hr_sk->sk_socket to survive the window between
handshake_req_next() and the subsequent FD_PREPARE() and get_f</li>
<li><strong>CVE-2026-64303</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

spi: fsl-lpspi: terminate the RX channel on TX prepare failure path

When dmaengine_prep_slave_sg() fails for the TX channel, the error path
terminates the TX DMA channel but leaves the RX channel running. Since
the RX channel was </li>
<li><strong>CVE-2026-64355</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject fragmented frames in devmap

Devmap broadcast redirects clone the packet for all but the last
destination.

For native XDP, that clone path copies only the linear xdp_frame data,
while fragmented frames keep skb_shared_</li>
<li><strong>CVE-2026-64384</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix change notify replay double-free

A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_notify_init() fails before the next send, cleanup
retains the previous buffer type an</li>
<li><strong>CVE-2026-64386</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix query_info() replay double-free

A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_query_info_init() fails before the next send,
cleanup retains the previous buffer type</li>
<li><strong>CVE-2026-64387</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix query directory replay double-free

A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_query_directory_init() fails before the next send,
cleanup retains the previous buf</li>
<li><strong>CVE-2026-64391</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

ksmbd: use opener credentials for ADS I/O

Alternate data streams are stored as xattrs. Unlike regular file I/O,
their read and write paths therefore call VFS xattr helpers which recheck
inode permissions and LSM policy using the c</li>
<li><strong>CVE-2026-64397</strong> (CVSS 9.8) - Linux Linux: In the Linux kernel, the following vulnerability has been resolved:

ksmbd: serialize QUERY_DIRECTORY requests per file

smb2_query_dir() stores a pointer to its stack-allocated private data in
the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the
same file handle can overwrite </li>
<li><strong>CVE-2026-52466</strong> (CVSS 9.8) - Open Library Foundation VuFind: Open Library Foundation VuFind v11.0.3 and v4.1 suffer from an incorrect access control vulnerability where requests continue processing despite failed authorization checks.</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-20263</strong> (CVSS 8.6) - Cisco IOS XE Software: A vulnerability in the BEEP feature of Cisco IOS XE Software allows an unauthenticated remote attacker to trigger a denial of service condition on affected devices.</li>
<li><strong>CVE-2026-20301</strong> (CVSS 8.6) - Cisco IOS and IOS XE Software: A vulnerability in the Extensible Messaging Client Protocol of Cisco IOS and IOS XE Software allows an unauthenticated remote attacker to cause a denial of service on an affected device.</li>
<li><strong>CVE-2026-20268</strong> (CVSS 8.6) - Cisco IOS XE Software: An internal security review identified a memory buffer vulnerability in Cisco IOS XE Software that could allow an unauthenticated remote attacker to cause a denial of service on an affected device.</li>
<li><strong>CVE-2026-20269</strong> (CVSS 8.6) - Cisco IOS XE Software: A resource management vulnerability in Cisco IOS XE Software identified during an internal review could allow an unauthenticated remote attacker to cause a denial of service on an affected device.</li>
<li><strong>CVE-2026-20270</strong> (CVSS 8.6) - Cisco IOS XE Software: A vulnerability in Cisco IOS XE Software involves an incorrect calculation flaw, potentially leading to a denial of service condition.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/08/06/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
    <item>
        <title>CVE Brief - August 5, 2026</title>
        <link>https://cvebrief.com/archive/2026/08/05/</link>
        <description>26 critical vulnerabilities and 74 high priority updates for August 5, 2026</description>
        <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/08/05/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - August 5, 2026</h2>
<ul>
<li><strong>26</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>74</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>28%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-70553</strong> (CVSS 9.8) - MaxSite MaxSite CMS: MaxSite CMS is vulnerable to remote code execution due to improper handling of database configuration inputs, allowing unauthenticated attackers to inject malicious PHP code.</li>
<li><strong>CVE-2026-16618</strong> (CVSS 9.8) - Unknown Improve SEO: The Improve SEO WordPress plugin fails to validate file extensions during uploads, allowing unauthenticated attackers to upload executable PHP files and gain remote code execution.</li>
<li><strong>CVE-2026-69703</strong> (CVSS 9.8) - maximeAmini Atals-Livre: Atals-Livre contains an improper access control vulnerability in admin controllers that allows unauthenticated attackers to bypass authentication and execute destructive actions.</li>
<li><strong>CVE-2026-70554</strong> (CVSS 9.8) - MaxSite MaxSite CMS: MaxSite CMS is susceptible to PHP object injection via the maxsite_comuser cookie, allowing unauthenticated remote code execution.</li>
<li><strong>CVE-2026-0163</strong> (CVSS 9.8) - Google Android: A use after free vulnerability in the Android kernel vpu_ioctl.c functions could allow an unauthenticated remote attacker to escalate privileges.</li>
<li><strong>CVE-2026-70376</strong> (CVSS 9.6) - pluck-cms Pluck CMS: Pluck CMS lacks robust CSRF protection, allowing attackers to force authenticated administrators to perform sensitive actions including remote code execution.</li>
<li><strong>CVE-2026-71207</strong> (CVSS 9.8) - mrswapnilsahu Stock-Inventory-Management-System: The Stock-Inventory-Management-System contains a SQL injection vulnerability and hardcoded credentials in the login module, allowing for total authentication bypass by unauthenticated remote attackers.</li>
<li><strong>CVE-2026-70552</strong> (CVSS 9.8) - MaxSite MaxSite CMS: MaxSite CMS contains an authentication bypass flaw in the AJAX dispatcher, allowing unauthenticated attackers to invoke privileged administrative functions via crafted requests.</li>
<li><strong>CVE-2026-43682</strong> (CVSS 9.8) - Apple macOS: A memory handling vulnerability in macOS Sequoia, Sonoma, and Tahoe allows remote attackers to trigger system termination or kernel memory corruption.</li>
<li><strong>CVE-2026-63455</strong> (CVSS 9.8) - Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Orchestrator: HPE EdgeConnect SD-WAN Orchestrator contains multiple REST API vulnerabilities that allow unauthenticated remote attackers to bypass authentication and gain access to sensitive system functions.</li>
<li><strong>CVE-2026-63456</strong> (CVSS 9.8) - Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Orchestrator: Multiple vulnerabilities in the HPE EdgeConnect SD-WAN Orchestrator REST API allow unauthenticated remote attackers to bypass authentication and modify sensitive system information.</li>
<li><strong>CVE-2026-69098</strong> (CVSS 9.8) - Cinnamon kotaemon: The kotaemon application contains an insecure deserialization vulnerability that allows unauthenticated attackers to achieve remote code execution by injecting arbitrary Python classes.</li>
<li><strong>CVE-2026-43694</strong> (CVSS 9.8) - Apple macOS: A memory handling vulnerability in macOS Sequoia, Sonoma, and Tahoe allows applications to trigger system termination or write to kernel memory.</li>
<li><strong>CVE-2026-43710</strong> (CVSS 9.8) - Apple macOS: A memory handling vulnerability in Apple macOS may allow an unauthenticated attacker to cause system termination or corrupt kernel memory.</li>
<li><strong>CVE-2026-43730</strong> (CVSS 9.8) - Apple iOS and iPadOS, macOS, tvOS, visionOS, watchOS: A permissions vulnerability in multiple Apple operating systems allows an application to fingerprint a user due to insufficient permission restrictions.</li>
<li><strong>CVE-2026-45538</strong> (CVSS 9.8) - OpenSIPS opensips: OpenSIPS contains a stack-based buffer overflow vulnerability in the sip_to_json() function, allowing unauthenticated remote attackers to cause a crash or achieve remote code execution.</li>
<li><strong>CVE-2017-20241</strong> (CVSS 9.8) - Keysight IxChariot: Keysight IxChariot Endpoint contains a heap-based buffer overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code or crash the system via crafted network packets.</li>
<li><strong>CVE-2017-20242</strong> (CVSS 9.8) - Keysight IxChariot: Keysight IxChariot Endpoint contains a stack-based buffer overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code or crash the system via crafted network packets.</li>
<li><strong>CVE-2026-49435</strong> (CVSS 9.8) - Keysight Hawkeye, IxChariot, IxTap, IxProbe, IxByPass: Multiple Keysight products contain a stack-based buffer overflow vulnerability, allowing an unauthenticated remote attacker to execute arbitrary code with administrative privileges.</li>
<li><strong>CVE-2026-61514</strong> (CVSS 9.8) - Puwell Technology IP Camera: Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability, allowing unauthenticated attackers to control device functions via TCP port 23456.</li>
<li><strong>CVE-2026-64633</strong> (CVSS 10) - Veeam ONE: A critical code injection vulnerability in Veeam ONE allows remote unauthenticated attackers to execute arbitrary code on the agent host.</li>
<li><strong>CVE-2026-61515</strong> (CVSS 9.8) - Puwell Technology IP Camera: Puwell IP Camera firmware versions 2.x through 4.x contain an unauthenticated command injection vulnerability in the DebugShell interface on TCP port 34567.</li>
<li><strong>CVE-2026-71214</strong> (CVSS 9.8) - NASA-AMMOS plandev (sequencing-server): The NASA-AMMOS plandev sequencing-server contains an authentication bypass flaw in the session role derivation middleware, allowing unauthenticated attackers to perform unauthorized administrative actions.</li>
<li><strong>CVE-2026-24254</strong> (CVSS 9.8) - NVIDIA Dynamo: NVIDIA Dynamo for Linux is vulnerable to an out-of-bounds write in the multimodal serving topology, potentially leading to remote code execution or system compromise.</li>
<li><strong>CVE-2026-25289</strong> (CVSS 9.6) - Qualcomm Snapdragon: A stack-based buffer overflow in Qualcomm Snapdragon occurs when processing Device Capability Extended attributes in NAN Service Discovery Frames with invalid length values.</li>
<li><strong>CVE-2025-29296</strong> (CVSS 9.8) - H3C Network Devices (Magic BE18000, NX400, Magic NX30 Pro, Magic R3010, Magic NX15, Magic R1510, NE36 Pro): Multiple H3C network devices contain command injection vulnerabilities in the /api/esps request handler, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-18830</strong> (CVSS 8.1) - AWS Amazon Bedrock AgentCore: Amazon Bedrock AgentCore contains an input validation vulnerability that allows authenticated users to bypass security controls and execute tools via crafted conversation messages.</li>
<li><strong>CVE-2026-8761</strong> (CVSS 8.8) - Dokan AI Powered WooCommerce Multivendor Marketplace Solution: The Dokan plugin for WordPress is susceptible to a privilege escalation vulnerability due to missing authorization checks in its REST API controllers.</li>
<li><strong>CVE-2026-68494</strong> (CVSS 8.7) - FasterXML jackson-core: The FasterXML jackson-core library is vulnerable to resource exhaustion due to insufficient limits on resource allocation during processing.</li>
<li><strong>CVE-2026-64631</strong> (CVSS 8.6) - Veeam ONE: A SQL injection vulnerability in Veeam ONE allows low-privileged users to execute unauthorized database queries and extract sensitive information.</li>
<li><strong>CVE-2026-18322</strong> (CVSS 8.8) - Supsystic Smart Popup by Supsystic: The Smart Popup by Supsystic plugin for WordPress is vulnerable to improper privilege management, allowing authenticated users to escalate their permissions.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/08/05/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
    <item>
        <title>CVE Brief - August 4, 2026</title>
        <link>https://cvebrief.com/archive/2026/08/04/</link>
        <description>44 critical vulnerabilities and 75 high priority updates for August 4, 2026</description>
        <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/08/04/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - August 4, 2026</h2>
<ul>
<li><strong>44</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>75</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>29%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-39932</strong> (CVSS 9.1) - openemr openemr: OpenEMR contains a remote code execution vulnerability via eval injection in the CategoryTree component, allowing authenticated administrators to execute arbitrary OS commands.</li>
<li><strong>CVE-2026-69085</strong> (CVSS 10) - siyuan-note siyuan: SiYuan contains a SQL injection vulnerability in the searchDocs endpoint, allowing unauthenticated attackers to read and modify database content via stacked queries.</li>
<li><strong>CVE-2026-69084</strong> (CVSS 10) - siyuan-note siyuan: A critical SQL injection vulnerability in the SiYuan /api/search/searchEmbedBlock endpoint allows unauthenticated remote attackers to execute arbitrary SQL commands on the underlying database.</li>
<li><strong>CVE-2026-48063</strong> (CVSS 9.3) - WhiskeySockets Baileys: The Baileys WhatsApp API allows unauthenticated remote attackers to spoof messages and corrupt the application state by sending malicious payloads to the placeholderResendMessage function.</li>
<li><strong>CVE-2026-48330</strong> (CVSS 10) - Adobe Campaign Classic: Adobe Campaign Classic is vulnerable to SQL injection, which allows an unauthenticated remote attacker to execute arbitrary SQL commands and achieve arbitrary code execution.</li>
<li><strong>CVE-2026-48331</strong> (CVSS 10) - Adobe Campaign Classic: Adobe Campaign Classic is affected by a Server-Side Request Forgery (SSRF) vulnerability that enables unauthenticated attackers to escalate privileges.</li>
<li><strong>CVE-2026-69083</strong> (CVSS 10) - siyuan-note siyuan: A critical SQL injection vulnerability in the SiYuan fullTextSearchAssetContent endpoint allows unauthenticated attackers to read, modify, or delete data across multiple notebooks.</li>
<li><strong>CVE-2026-48326</strong> (CVSS 9.9) - Adobe Campaign Classic: Adobe Campaign Classic is vulnerable to SQL injection, which allows a low-privileged authenticated attacker to execute arbitrary code.</li>
<li><strong>CVE-2026-48333</strong> (CVSS 9.8) - Adobe Campaign Classic: Adobe Campaign Classic is vulnerable to an Incorrect Authorization flaw allowing unauthenticated attackers to perform privilege escalation.</li>
<li><strong>CVE-2026-69240</strong> (CVSS 9.8) - Sequelize Sequelize: Sequelize ORM versions prior to 6.37.4 contain an SQL injection vulnerability in the Oracle dialect when processing specific date strings, allowing unauthenticated attackers to execute arbitrary SQL.</li>
<li><strong>CVE-2026-64827</strong> (CVSS 9.8) - Telenia Software TVox: Telenia Software TVox contains an authentication bypass vulnerability via set_env.php, allowing unauthenticated attackers to access restricted PHP scripts by manipulating the requested path.</li>
<li><strong>CVE-2026-48323</strong> (CVSS 10) - Adobe Campaign Classic: Adobe Campaign Classic contains a template engine vulnerability that allows unauthenticated remote attackers to execute arbitrary code.</li>
<li><strong>CVE-2026-48317</strong> (CVSS 9.6) - Adobe Campaign Classic: Adobe Campaign Classic is vulnerable to Eval Injection, allowing a low-privileged attacker to execute arbitrary code.</li>
<li><strong>CVE-2026-18574</strong> (CVSS 9.3) - Check Point Security Management Server and Multi-Domain Security Management Server: An authentication bypass vulnerability in Check Point Security Management Server allows unauthenticated remote attackers to execute arbitrary commands.</li>
<li><strong>CVE-2026-48031</strong> (CVSS 9.1) - dhax go-base: The go-base boilerplate template contains a hardcoded JWT signing secret, allowing unauthenticated attackers to forge authentication tokens and bypass security controls.</li>
<li><strong>CVE-2026-16300</strong> (CVSS 9.8) - ChamaWP ChamaWP: The ChamaWP WordPress plugin contains a missing authorization flaw in the password reset process, allowing unauthenticated attackers to reset the passwords of any user.</li>
<li><strong>CVE-2026-15930</strong> (CVSS 9.4) - Simple Membership Simple Membership WordPress plugin: The Simple Membership WordPress plugin contains an authorization bypass vulnerability allowing unauthenticated attackers to overwrite administrator account data and perform account takeovers.</li>
<li><strong>CVE-2026-18753</strong> (CVSS 9.1) - GeoVision GV-AS1620 (AS-Manager): The GeoVision GV-AS1620 AS-Manager firmware contains a hard-coded RSA private key, allowing attackers to decrypt HTTPS traffic and spoof the server.</li>
<li><strong>CVE-2026-18754</strong> (CVSS 9.1) - GeoVision GV-AS1620 (GV-Cloud): The GeoVision GV-AS1620 GV-Cloud firmware contains a hard-coded RSA private key, which allows attackers to decrypt HTTPS traffic and spoof the server.</li>
<li><strong>CVE-2021-32086</strong> (CVSS 9.8) - Quest KACE Systems Deployment Appliance (SMA): Quest KACE Systems Deployment Appliance uses a hardcoded symmetric encryption key to protect secrets in MySQL databases, allowing unauthorized decryption by attackers with access to database backups.</li>
<li><strong>CVE-2026-18248</strong> (CVSS 9.1) - @fastify aws-lambda: The @fastify/aws-lambda package in version 6.4.0 allows unauthenticated attackers to forge API Gateway proxy events, leading to a complete authentication and authorization bypass.</li>
<li><strong>CVE-2026-33591</strong> (CVSS 10) - Tranquil IT Systems WAPT Server: A critical authentication bypass vulnerability in WAPT Server allows remote, unauthenticated attackers to forge session tokens via specially crafted packets.</li>
<li><strong>CVE-2026-14175</strong> (CVSS 9.8) - Bilin Software and Informatics Consultancy HUMANIST Digital Human Resources: An unrestricted file upload vulnerability in HUMANIST Digital Human Resources allows remote, unauthenticated attackers to upload and execute malicious web shells on the server.</li>
<li><strong>CVE-2026-18686</strong> (CVSS 9.8) - GL.iNet GL-MT3000: A command injection vulnerability in the nas-web component of GL.iNet GL-MT3000 allows remote, unauthenticated attackers to execute arbitrary system commands via the add_user function.</li>
<li><strong>CVE-2026-18685</strong> (CVSS 9.8) - GL.iNet GL-MT3000: A command injection vulnerability in the set_upgrade function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to execute arbitrary system commands.</li>
<li><strong>CVE-2026-18684</strong> (CVSS 9.8) - GL.iNet GL-MT3000: A command injection vulnerability in the remove_profile function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to execute arbitrary system commands.</li>
<li><strong>CVE-2026-18616</strong> (CVSS 9.8) - GL-iNet GL-MT3000: A command injection vulnerability in the server.set_peer function of the GL-iNet GL-MT3000 wg-server.so plugin allows remote, unauthenticated attackers to execute arbitrary commands.</li>
<li><strong>CVE-2026-18614</strong> (CVSS 9.8) - GL-iNet GL-MT3000: A command injection vulnerability in the s2s.so plugin of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands via the s2s.enable_echo_server function.</li>
<li><strong>CVE-2026-18615</strong> (CVSS 9.8) - GL-iNet GL-MT3000: An unauthenticated remote command injection vulnerability in the GL-iNet GL-MT3000 allows attackers to execute arbitrary commands via the wg-server.generate_publickey function.</li>
<li><strong>CVE-2026-18612</strong> (CVSS 9.8) - GL-iNet GL-MT3000: A command injection vulnerability in the plugins.so component of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands via the package management functions.</li>
<li><strong>CVE-2026-18613</strong> (CVSS 9.8) - GL-iNet GL-MT3000: A remote injection vulnerability exists in the plugins.set_config function of the GL-iNet GL-MT3000 router firmware, allowing unauthenticated attackers to execute arbitrary code.</li>
<li><strong>CVE-2026-18602</strong> (CVSS 9.8) - GL.iNet GL-MT3000: A command injection vulnerability in the ovpn-client.get_recommend_config function of GL.iNet GL-MT3000 routers allows unauthenticated remote attackers to execute arbitrary system commands.</li>
<li><strong>CVE-2026-41452</strong> (CVSS 9.8) - krayin laravel-crm: A missing authentication vulnerability in the Krayin CRM installer middleware allows unauthenticated remote attackers to overwrite the administrator account and gain full CRM access.</li>
<li><strong>CVE-2026-18601</strong> (CVSS 9.8) - GL.iNet GL-MT3000: A command injection vulnerability in the GL.iNet GL-MT3000 ovpn-client.so plugin allows unauthenticated remote attackers to execute arbitrary code via the filename argument in /cgi-bin/glc.</li>
<li><strong>CVE-2026-18667</strong> (CVSS 9.6) - Tenable Sensor Proxy: Tenable Sensor Proxy is vulnerable to remote code execution, allowing an unauthenticated attacker to gain elevated privileges if an operator connects the sensor to a malicious host.</li>
<li><strong>CVE-2026-15721</strong> (CVSS 9.8) - Bilin Software and Informatics Consultancy HUMANIST Digital Human Resources: HUMANIST Digital Human Resources contains a cleartext storage vulnerability that facilitates SQL injection, allowing unauthenticated attackers to compromise sensitive application data.</li>
<li><strong>CVE-2026-18108</strong> (CVSS 9.8) - TIMLEGGE Net::SAML2: Net::SAML2 fails to verify cryptographic signatures on encrypted SAML assertions, allowing unauthenticated attackers to bypass authentication and impersonate arbitrary users.</li>
<li><strong>CVE-2026-2346</strong> (CVSS 9.8) - Menulux Software Mobile App: An authorization bypass vulnerability in Menulux Software Mobile App allows attackers to access unauthorized data by manipulating record identifiers.</li>
<li><strong>CVE-2026-38447</strong> (CVSS 9.8) - osTicket osTicket: osTicket 1.18.3 uses insecure MD5 hashing with predictable inputs to generate API keys, allowing attackers to brute-force authentication credentials.</li>
<li><strong>CVE-2026-46713</strong> (CVSS 9.2) - misskey-dev misskey: Misskey fails to properly validate JSON-LD signatures, enabling attackers to spoof activities on the federated social media platform.</li>
<li><strong>CVE-2026-14804</strong> (CVSS 9.1) - Bilin Software and Informatics Consultancy HUMANIST Digital Human Resources: Bilin Software and Informatics Consultancy HUMANIST Digital Human Resources versions 26.0 before 26.1 contain a hard-coded cryptographic key, allowing for unauthorized access to sensitive constants.</li>
<li><strong>CVE-2026-9390</strong> (CVSS 9.1) - TIMLEGGE XML::Sig: The XML::Sig library for Perl, in versions before 0.71, is vulnerable to XPath injection due to improper neutralization of URI data during the document verification process.</li>
<li><strong>CVE-2026-9487</strong> (CVSS 9.1) - TIMLEGGE XML::Sig: XML::Sig versions before 0.71 for Perl are vulnerable to signature wrapping attacks because the library fails to detect duplicate ID attributes during the XML verification process.</li>
<li><strong>CVE-2021-32084</strong> (CVSS 9.8) - Quest KACE Systems Deployment Appliance (SMA): Quest KACE SMA 11.0.273 fails to enforce IP-based access restrictions on API endpoints, allowing bypass of console security.</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-68945</strong> (CVSS 8.8) - Angular Angular: Angular is vulnerable to insufficient verification of data authenticity, which may allow attackers to bypass security checks.</li>
<li><strong>CVE-2026-69149</strong> (CVSS 8.6) - Angular Angular: Angular is susceptible to a Cross-site Scripting (XSS) vulnerability during web page generation, which can be triggered by malicious user interaction.</li>
<li><strong>CVE-2026-62870</strong> (CVSS 8.8) - Microsoft Microsoft 365 Apps for Enterprise: A use after free vulnerability in Microsoft Office Excel allows an unauthenticated attacker to achieve remote code execution through malicious file interaction.</li>
<li><strong>CVE-2026-69151</strong> (CVSS 7.6) - Angular Angular: A Cross-site Scripting (XSS) vulnerability exists in the Angular compiler and core, allowing for script injection during the web generation process.</li>
<li><strong>CVE-2026-66315</strong> (CVSS 7.5) - Microsoft Microsoft Edge (Chromium-based): A use after free vulnerability in Microsoft Edge allows an unauthenticated attacker to execute code over a network via a specially crafted web page.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/08/04/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
    <item>
        <title>CVE Brief - August 3, 2026</title>
        <link>https://cvebrief.com/archive/2026/08/03/</link>
        <description>16 critical vulnerabilities and 55 high priority updates for August 3, 2026</description>
        <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/08/03/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - August 3, 2026</h2>
<ul>
<li><strong>16</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>55</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>20%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-58062</strong> (CVSS 9.3) - Legion of the Bouncy Castle BC-JAVA: Bouncy Castle for Java fails to properly bind stapled OCSP responses to the checked certificate, allowing for potential validation bypasses.</li>
<li><strong>CVE-2026-59638</strong> (CVSS 9.3) - Legion of the Bouncy Castle BC-JAVA: Bouncy Castle for Java has an insecure default configuration for the JSSE hostname verifier, which incorrectly enables CN-fallback.</li>
<li><strong>CVE-2026-68579</strong> (CVSS 9.6) - FreeRDP FreeRDP: FreeRDP contains a heap-based buffer overflow in the Windows clipboard client, which can be triggered by a malicious RDP server sending an oversized response.</li>
<li><strong>CVE-2026-59650</strong> (CVSS 9.3) - Legion of the Bouncy Castle BC-JAVA: Bouncy Castle for Java and Java LTS versions contain an improper input validation vulnerability where peer values are exponentiated without validation during Diffie-Hellman key agreement.</li>
<li><strong>CVE-2026-8763</strong> (CVSS 9.3) - Legion of the Bouncy Castle BC-JAVA: Bouncy Castle for Java, Java LTS, and FIPS versions are vulnerable to a Name Constraints bypass via trailing dots in rfc822Name and URI fields during certificate validation.</li>
<li><strong>CVE-2026-16364</strong> (CVSS 9.1) - Mozilla Firefox: Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16370</strong> (CVSS 9.1) - Mozilla Firefox: Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16380</strong> (CVSS 9.1) - Mozilla Firefox: Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16390</strong> (CVSS 9.1) - Mozilla Firefox: Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-12877</strong> (CVSS 9.1) - Unknown Project Management, Bug and Issue Tracking Plugin: The Project Management, Bug and Issue Tracking Plugin  WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Trac</li>
<li><strong>CVE-2026-18588</strong> (CVSS 9.8) - Wavlink WL-NU516U1: The Wavlink WL-NU516U1 router contains a stack-based buffer overflow vulnerability in the nas.cgi file, which can be triggered by manipulating the CONTENT_LENGTH argument.</li>
<li><strong>CVE-2026-18589</strong> (CVSS 9.8) - Wavlink WL-NU516U1: A stack-based buffer overflow in the nas.cgi component of Wavlink WL-NU516U1 allows remote unauthenticated attackers to execute arbitrary code via the User1Passwd argument.</li>
<li><strong>CVE-2026-65321</strong> (CVSS 9.8) - laughingman7743 PyAthena: An SQL injection vulnerability in PyAthena versions prior to 3.35.4 allows unauthenticated attackers to execute arbitrary SQL commands due to improper quote-escaping in the DefaultParameterFormatter.</li>
<li><strong>CVE-2026-64873</strong> (CVSS 9.8) - regularlabs.com Cache Cleaner Pro extension for Joomla: Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.</li>
<li><strong>CVE-2026-52439</strong> (CVSS 9.8) - Unknown Multiple Products: An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism</li>
<li><strong>CVE-2026-59145</strong> (CVSS 9.1) - EGOR Data::Intern::Shared: Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find.

The attach-time validator si_validate_header is thorough about the header and layout (magic, version, section offsets, total_size, count and arena_used) but</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-12802</strong> (CVSS 8.7) - Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA: A vulnerability in Bouncy Castle Java libraries allows for the improper validation of integrity check values, potentially leading to unauthorized operations.</li>
<li><strong>CVE-2026-12803</strong> (CVSS 8.7) - Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA: Bouncy Castle for Java contains an improper validation of integrity check values, which could lead to integrity compromise.</li>
<li><strong>CVE-2026-12816</strong> (CVSS 8.7) - Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA: Bouncy Castle for Java is susceptible to an improper validation of integrity check values, which may permit unauthorized modification of protected data.</li>
<li><strong>CVE-2026-12817</strong> (CVSS 8.7) - Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA: Multiple Bouncy Castle for Java components are affected by an improper validation of integrity check values, potentially impacting data security.</li>
<li><strong>CVE-2026-12852</strong> (CVSS 8.7) - Legion of the Bouncy Castle Inc. BC-JAVA: A memory allocation vulnerability exists in the Bouncy Castle BC-JAVA library, allowing unauthenticated attackers to cause a denial of service via excessive memory consumption.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/08/03/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
    <item>
        <title>CVE Brief - August 2, 2026</title>
        <link>https://cvebrief.com/archive/2026/08/02/</link>
        <description>23 critical vulnerabilities and 43 high priority updates for August 2, 2026</description>
        <pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/08/02/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - August 2, 2026</h2>
<ul>
<li><strong>23</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>43</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>24%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-66402</strong> (CVSS 9.8) - FreeRDP FreeRDP: FreeRDP contains multiple TLS certificate validation flaws allowing attackers to bypass server identity verification due to improper handling of Common Name and DNS SAN strings.</li>
<li><strong>CVE-2026-67305</strong> (CVSS 9.4) - FreeRDP FreeRDP: A heap-based buffer overflow in the FreeRDP Windows client's clipboard virtual channel allows remote code execution when processing malicious clipboard responses from an RDP server.</li>
<li><strong>CVE-2026-8457</strong> (CVSS 9.8) - WPWeb WooCommerce - Social Login: The WooCommerce - Social Login plugin is vulnerable to authentication bypass via forged Apple ID tokens and exposed security nonces, allowing attackers to hijack any user account.</li>
<li><strong>CVE-2026-67340</strong> (CVSS 9.8) - ArcadeData arcadedb: ArcadeDB allows authenticated users to execute arbitrary OS commands via malicious JavaScript triggers due to improper package filtering within the script executor.</li>
<li><strong>CVE-2026-67341</strong> (CVSS 9.8) - ArcadeData arcadedb: ArcadeDB fails to enforce authorization checks on SQL DEFINE FUNCTION statements, allowing users with database access to execute arbitrary JavaScript code.</li>
<li><strong>CVE-2026-67342</strong> (CVSS 9.8) - ArcadeData arcadedb: ArcadeDB suffers from an authorization bypass in multiple HTTP handlers, allowing unauthorized users to access or modify databases by manipulating endpoint parameters.</li>
<li><strong>CVE-2026-16379</strong> (CVSS 9.8) - Mozilla Firefox: Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-15964</strong> (CVSS 9.8) - britcoder Single Sign On For TNG: The Single Sign On For TNG WordPress plugin suffers from an unauthenticated password reset vulnerability due to insufficient validation of AJAX requests.</li>
<li><strong>CVE-2026-65431</strong> (CVSS 9.8) - Regular Labs GeoIP extension for Joomla: A path traversal vulnerability in the Regular Labs GeoIP extension for Joomla allows for arbitrary file writes during the extraction of database update archives.</li>
<li><strong>CVE-2026-16377</strong> (CVSS 9.8) - Mozilla Firefox: Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16382</strong> (CVSS 9.8) - Mozilla Firefox: Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16383</strong> (CVSS 9.8) - Mozilla Firefox: Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16387</strong> (CVSS 9.8) - Mozilla Firefox: Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16388</strong> (CVSS 9.8) - Mozilla Firefox: Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16389</strong> (CVSS 9.8) - Mozilla Firefox: Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16402</strong> (CVSS 9.8) - Mozilla Firefox: Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16407</strong> (CVSS 9.8) - Mozilla Firefox: Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-67324</strong> (CVSS 9.8) - gitpython-developers GitPython: GitPython fails to properly filter joined short-option arguments, allowing attackers to bypass security gates and execute arbitrary commands during repository cloning.</li>
<li><strong>CVE-2026-67289</strong> (CVSS 9.8) - FreeRDP FreeRDP: FreeRDP is vulnerable to HTTP request header injection because it fails to sanitize control characters in RDP redirection addresses when using an HTTP proxy.</li>
<li><strong>CVE-2026-67308</strong> (CVSS 10) - Wazuh Wazuh: Wazuh workflows contain a shell injection vulnerability in GitHub Actions, allowing attackers to execute arbitrary commands via crafted VERSION.json files in pull requests.</li>
<li><strong>CVE-2026-58586</strong> (CVSS 9.8) - ZAPAD Image::WebP: The Perl module Image::WebP bundles a vulnerable version of libwebp, which allows remote attackers to trigger heap corruption and potential code execution via a specially crafted WebP image.</li>
<li><strong>CVE-2025-50329</strong> (CVSS 9.8) - Unknown Multiple Products: An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.</li>
<li><strong>CVE-2026-67330</strong> (CVSS 9.9) - better-auth scim: An authorization bypass in the @better-auth/scim plugin allows authenticated users to mint SCIM tokens that collide with existing provider namespaces, resulting in unauthorized account takeover.</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-67320</strong> (CVSS 8.3) - axios axios: The axios library in Node.js is vulnerable to prototype pollution when handling certain inputs via the Node.js HTTP adapter, potentially leading to unauthorized information exposure.</li>
<li><strong>CVE-2026-16635</strong> (CVSS 8.8) - WordPress Pronamic Pay: The Pronamic Pay plugin for WordPress contains an improper privilege management vulnerability, allowing authenticated users to perform unauthorized actions.</li>
<li><strong>CVE-2026-13339</strong> (CVSS 7.5) - WordPress CubeWP Framework: The CubeWP Framework plugin for WordPress is susceptible to directory traversal, which may allow unauthenticated attackers to access sensitive files on the server.</li>
<li><strong>CVE-2026-18352</strong> (CVSS 7.5) - WordPress User Access Manager: The User Access Manager plugin for WordPress is vulnerable to directory traversal, enabling unauthenticated attackers to access restricted files on the underlying server.</li>
<li><strong>CVE-2026-15052</strong> (CVSS 7.2) - WordPress MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder: The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/08/02/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
    <item>
        <title>CVE Brief - August 1, 2026</title>
        <link>https://cvebrief.com/archive/2026/08/01/</link>
        <description>24 critical vulnerabilities and 77 high priority updates for August 1, 2026</description>
        <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/08/01/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - August 1, 2026</h2>
<ul>
<li><strong>24</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>77</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>25%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-3141</strong> (CVSS 9.1) - wpwax FormGent: The FormGent WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via the REST API, potentially allowing attackers to delete critical files such as wp-config.php.</li>
<li><strong>CVE-2025-67649</strong> (CVSS 9.3) - PHP Jabbers Car Rental Script: A SQL injection vulnerability in the PHP Jabbers Car Rental Script allows unauthenticated attackers to execute malicious database queries through improperly sanitized sorting parameters.</li>
<li><strong>CVE-2026-17349</strong> (CVSS 9.6) - pgadmin.org pgAdmin 4: A vulnerability in the pgAdmin 4 Workspaces feature allows authenticated users to clone and inherit sensitive database credentials from other users, leading to unauthorized access.</li>
<li><strong>CVE-2026-58048</strong> (CVSS 9.4) - WebPros cPanel: A SQL injection vulnerability in cPanel allows authenticated users with low privileges to execute arbitrary SQL commands in the root context when renaming databases.</li>
<li><strong>CVE-2026-63221</strong> (CVSS 9.4) - codeigniter4 CodeIgniter4: A SQL injection vulnerability in the deleteBatch method of CodeIgniter4 allows attackers to bypass escape flags and execute arbitrary SQL commands via user-controlled input.</li>
<li><strong>CVE-2026-16365</strong> (CVSS 9.8) - Mozilla Firefox: Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16366</strong> (CVSS 9.8) - Mozilla Firefox: Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16371</strong> (CVSS 9.8) - Mozilla Firefox: Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16372</strong> (CVSS 9.8) - Mozilla Firefox: Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-17566</strong> (CVSS 9.9) - pgadmin.org pgAdmin 4: An OS command injection vulnerability in the Import/Export Data tool of pgAdmin 4 allows authenticated users to execute arbitrary commands on the underlying host.</li>
<li><strong>CVE-2026-68771</strong> (CVSS 9.8) - Comfy-Org ComfyUI: ComfyUI v0.23.0 contains an insecure deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code.</li>
<li><strong>CVE-2026-16357</strong> (CVSS 9.8) - Mozilla Firefox: Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16358</strong> (CVSS 9.8) - Mozilla Firefox: Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16360</strong> (CVSS 9.8) - Mozilla Firefox: Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR</li>
<li><strong>CVE-2026-16368</strong> (CVSS 9.8) - Mozilla Firefox: Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16369</strong> (CVSS 9.8) - Mozilla Firefox: Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16375</strong> (CVSS 9.8) - Mozilla Firefox: Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-17351</strong> (CVSS 9) - pgadmin.org pgAdmin 4: A flawed fix in pgAdmin 4 allows for SQL injection via AI Assistant tool calls, enabling attackers to execute arbitrary multi-statement SQL commands.</li>
<li><strong>CVE-2026-14919</strong> (CVSS 9.8) - ShopMonitor.io ShopMonitor.io WordPress Plugin: A critical authentication bypass in the ShopMonitor.io WordPress plugin allows unauthenticated attackers to hijack administrator accounts via email redirection.</li>
<li><strong>CVE-2026-68770</strong> (CVSS 9.8) - Hugging Face sentence-transformers: A logic flaw in the sentence-transformers library allows attackers to bypass security checks and achieve arbitrary code execution by loading malicious local models.</li>
<li><strong>CVE-2026-52855</strong> (CVSS 9.9) - Pterodactyl Wings: A vulnerability in Pterodactyl Wings allows authenticated users to read sensitive configuration tokens and registry credentials from daemon configuration files.</li>
<li><strong>CVE-2026-54725</strong> (CVSS 9.6) - Bank-Vaults Vault-secrets-webhook: A server-side request forgery vulnerability in the bank-vaults vault-secrets-webhook allows attackers to redirect ServiceAccount JWTs to arbitrary, attacker-controlled Vault addresses.</li>
<li><strong>CVE-2026-17561</strong> (CVSS 9.8) - Innotim Software Logsign SIEM: A code injection vulnerability in Logsign SIEM allows unauthenticated attackers to execute arbitrary code due to improper control of code generation.</li>
<li><strong>CVE-2026-67822</strong> (CVSS 9.8) - Tenda W6-S: A stack-based buffer overflow in the Tenda W6-S web interface allows remote, unauthenticated attackers to trigger a crash or execute arbitrary code via the wifiSSIDset endpoint.</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-53599</strong> (CVSS 7.5) - redaxo core: The REDAXO CMS core contains an unrestricted file upload vulnerability that allows authenticated users to execute arbitrary code on the server.</li>
<li><strong>CVE-2026-17543</strong> (CVSS 8.1) - PHP Group PHP: PHP contains a flaw involving improper escaping of backslashes in attacker-provided parameters, which enables trivial SQL injection attacks.</li>
<li><strong>CVE-2026-14537</strong> (CVSS 8.1) - Google mcp-toolbox: An incorrect authorization vulnerability in the Google mcp-toolbox HTTP API tool invocation endpoint allows unauthenticated users to perform unauthorized actions.</li>
<li><strong>CVE-2026-15414</strong> (CVSS 8.8) - wpswings Subscriptions for WooCommerce: The Subscriptions for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to 2.0.0, allowing authenticated users to gain unauthorized access.</li>
<li><strong>CVE-2025-67650</strong> (CVSS 8.6) - PHP Jabbers Appointment Scheduler (and others): Multiple PHP Jabbers scripts contain an authenticated SQL injection vulnerability, allowing privileged users to execute unauthorized database commands.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/08/01/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
    <item>
        <title>CVE Brief - July 31, 2026</title>
        <link>https://cvebrief.com/archive/2026/07/31/</link>
        <description>41 critical vulnerabilities and 74 high priority updates for July 31, 2026</description>
        <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
        <guid isPermaLink="true">https://cvebrief.com/archive/2026/07/31/</guid>
        <content:encoded><![CDATA[
<h2>Daily Security Snapshot - July 31, 2026</h2>
<ul>
<li><strong>41</strong> Critical CVEs (CVSS 9.0+)</li>
<li><strong>74</strong> High Priority CVEs (CVSS 7.0-8.9)</li>
<li><strong>30%</strong> Patches Available</li>
</ul>
<h3>Critical Vulnerabilities</h3>
<ul>
<li><strong>CVE-2026-67208</strong> (CVSS 9.8) - somta Juggle: An unauthenticated remote code execution vulnerability exists in somta Juggle through 1.6.0 due to exposed H2 database consoles with default credentials.</li>
<li><strong>CVE-2026-17656</strong> (CVSS 9.6) - Google Chrome: A use after free vulnerability in Ozone in Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.</li>
<li><strong>CVE-2026-17670</strong> (CVSS 9.6) - Google Chrome: A use after free vulnerability in the Views component of Google Chrome allows a remote attacker to perform a sandbox escape after compromising the renderer process.</li>
<li><strong>CVE-2026-63223</strong> (CVSS 9.8) - codeigniter4 CodeIgniter4: CodeIgniter4 versions prior to 4.7.4 fail to properly validate file extensions during upload, potentially allowing remote attackers to execute arbitrary code.</li>
<li><strong>CVE-2026-67594</strong> (CVSS 9.8) - yolanmees Spikster: Spikster contains a missing authentication vulnerability in its API routing, allowing unauthenticated remote attackers to access approximately 50 sensitive endpoints.</li>
<li><strong>CVE-2026-17651</strong> (CVSS 9.6) - Google Chrome: Insufficient validation of untrusted input in the Dawn component of Google Chrome on Android allows a remote attacker to perform a sandbox escape via a crafted HTML page.</li>
<li><strong>CVE-2026-17655</strong> (CVSS 9.6) - Google Chrome: Insufficient input validation in the ANGLE component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.</li>
<li><strong>CVE-2026-17669</strong> (CVSS 9.6) - Google Chrome for iOS: An inappropriate implementation in Google Chrome for iOS allows a remote attacker to perform a sandbox escape via a crafted HTML page.</li>
<li><strong>CVE-2026-17671</strong> (CVSS 9.6) - Google Chrome: Insufficient input validation in the ANGLE component of Google Chrome allows an attacker who has already compromised the renderer process to perform a sandbox escape.</li>
<li><strong>CVE-2026-17672</strong> (CVSS 9.6) - Google Chrome: Google Chrome contains an input validation flaw in Chromecast that allows a remote attacker to achieve a sandbox escape through a crafted HTML page after compromising the renderer process.</li>
<li><strong>CVE-2026-17673</strong> (CVSS 9.6) - Google Chrome: An integer overflow vulnerability in the QUIC implementation of Google Chrome allows a remote attacker to perform a sandbox escape if they have previously compromised the renderer process.</li>
<li><strong>CVE-2026-16353</strong> (CVSS 9.8) - Mozilla Firefox: Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-14483</strong> (CVSS 9.8) - realtyna Realtyna Organic IDX plugin + WPL Real Estate: The Realtyna Organic IDX plugin + WPL Real Estate for WordPress is vulnerable to unauthenticated arbitrary file uploads due to missing validation and static API credentials.</li>
<li><strong>CVE-2026-16367</strong> (CVSS 10) - Mozilla Firefox: Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153.</li>
<li><strong>CVE-2026-16352</strong> (CVSS 9.8) - Mozilla Firefox: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-68503</strong> (CVSS 9.8) - grisuno LazyOwn: The LazyOwn C2 framework contains default credentials in its source code, allowing unauthenticated remote attackers to gain operator level access to the dashboard.</li>
<li><strong>CVE-2026-16349</strong> (CVSS 9.8) - Mozilla Firefox: Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16350</strong> (CVSS 9.8) - Mozilla Firefox: Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-16351</strong> (CVSS 9.8) - Mozilla Firefox: Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.</li>
<li><strong>CVE-2026-59309</strong> (CVSS 9.8) - VMware Cloud Foundation, vCenter, vSphere Foundation, Telco Cloud Infrastructure, Telco Cloud Platform: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service, allowing unauthenticated attackers with network access to gain unauthorized system access.</li>
<li><strong>CVE-2025-66390</strong> (CVSS 9.8) - Unknown Multiple Products: In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI leve</li>
<li><strong>CVE-2026-59310</strong> (CVSS 9.8) - VMware Cloud Foundation, vCenter, vSphere Foundation, Telco Cloud Infrastructure, Telco Cloud Platform: VMware vCenter contains a directory traversal vulnerability in the Syslog server, which may allow an unauthenticated attacker with network access to execute arbitrary code on the system.</li>
<li><strong>CVE-2026-13435</strong> (CVSS 9.9) - IBM Langflow OSS: IBM Langflow OSS contains an improper input validation vulnerability in its PythonREPL sandbox implementation, allowing authenticated attackers to perform code injection.</li>
<li><strong>CVE-2026-68502</strong> (CVSS 9.8) - grisuno LazyOwn: A missing authentication flaw in the LazyOwn Socket.IO event handler allows unauthenticated remote attackers to execute arbitrary commands within the C2 process.</li>
<li><strong>CVE-2026-12118</strong> (CVSS 9.8) - IBM webMethods Integration (on prem): IBM webMethods Integration is vulnerable to unauthenticated remote code execution via deserialization of untrusted data in the WmServiceMock package.</li>
<li><strong>CVE-2026-12940</strong> (CVSS 9.8) - IBM Langflow OSS: IBM Langflow OSS is susceptible to unauthenticated remote code execution due to an incomplete blocklist of dangerous environment variables in the MCP stdio launcher.</li>
<li><strong>CVE-2026-18452</strong> (CVSS 10) - Rich Source DMS+ (Non-Mobile): DMS+ (Non-Mobile) contains hardcoded credentials that allow unauthenticated remote attackers to gain full administrative control over the device.</li>
<li><strong>CVE-2026-12946</strong> (CVSS 9.9) - IBM Langflow OSS: IBM Langflow OSS is vulnerable to code injection, allowing an authenticated remote attacker to execute arbitrary code due to improper control of user-supplied input.</li>
<li><strong>CVE-2026-15435</strong> (CVSS 9.8) - IBM App Connect Enterprise: IBM App Connect Enterprise is vulnerable to path traversal, allowing unauthenticated remote attackers to write arbitrary files to the system via specially crafted URL requests.</li>
<li><strong>CVE-2026-28323</strong> (CVSS 9.8) - SolarWinds Web Help Desk: SolarWinds Web Help Desk contains a SAML authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access if SAML 2.0 is enabled.</li>
<li><strong>CVE-2026-4978</strong> (CVSS 9.8) - UMAI Vision Traffic Analysis System: A critical SQL injection vulnerability in UMAI Vision Traffic Analysis System allows unauthenticated attackers to execute arbitrary SQL commands via the application.</li>
<li><strong>CVE-2026-12943</strong> (CVSS 9.8) - IBM HMC (Hardware Management Console): IBM HMC management systems are vulnerable to OS command injection, allowing unauthenticated remote attackers to execute arbitrary commands with elevated privileges.</li>
<li><strong>CVE-2026-59144</strong> (CVSS 9.8) - EGOR Data::RingBuffer::Shared: Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq.

The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size against the destination s</li>
<li><strong>CVE-2026-52469</strong> (CVSS 9.8) - Crocus Crocus: An SQL injection vulnerability in the Crocus DeviceInfoMapper.xml file allows remote, unauthenticated attackers to execute arbitrary SQL commands and escalate privileges.</li>
<li><strong>CVE-2026-52470</strong> (CVSS 9.8) - Crocus Crocus: An SQL injection vulnerability in the Crocus RecordStateMapper.xml file allows remote, unauthenticated attackers to execute arbitrary SQL commands and escalate privileges.</li>
<li><strong>CVE-2026-52472</strong> (CVSS 9.8) - Wgcloud Wgcloud: A SQL injection vulnerability in Wgcloud 3.6.4 allows unauthenticated remote attackers to escalate privileges via the PortInfoMapper.xml file.</li>
<li><strong>CVE-2026-51272</strong> (CVSS 9.8) - schreibfaul1 ESP32-audioI2S: A heap-based buffer overflow in the schreibfaul1 ESP32-audioI2S library allows for potential code execution or denial of service via malformed input during character encoding conversion.</li>
<li><strong>CVE-2026-51291</strong> (CVSS 9.8) - SQLite SQLite: A use-after-free vulnerability in the jsonCacheInsert function of SQLite 3.41 may lead to application crashes or arbitrary code execution.</li>
<li><strong>CVE-2026-59147</strong> (CVSS 9.8) - EGOR Data::DisjointSet::Shared: Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find.

The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then</li>
<li><strong>CVE-2026-50755</strong> (CVSS 9.8) - Unknown Multiple Products: An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value</li>
<li><strong>CVE-2026-30631</strong> (CVSS 9.8) - bytebot-ai bytebot-ai: A vulnerability in bytebot-ai allows an unauthenticated attacker to execute arbitrary code via a crafted path provided to the computer_write_file function.</li>
</ul>
<h3>High Priority Updates</h3>
<ul>
<li><strong>CVE-2026-16418</strong> (CVSS 8.8) - Google Chrome: A stack buffer overflow in the Google Chrome V8 engine allows remote attackers to execute arbitrary code within the sandbox via a crafted HTML page.</li>
<li><strong>CVE-2026-17658</strong> (CVSS 8.8) - Google Chrome: A use after free vulnerability in the V8 engine of Google Chrome allows remote attackers to perform unauthorized operations via a crafted HTML page.</li>
<li><strong>CVE-2026-17661</strong> (CVSS 8.8) - Google Chrome: A use after free vulnerability in the Loader component of Google Chrome allows remote attackers to perform unauthorized operations via a crafted web page.</li>
<li><strong>CVE-2026-17665</strong> (CVSS 8.8) - Google Chrome: A use after free vulnerability exists in the V8 engine of Google Chrome, potentially allowing an unauthenticated remote attacker to execute arbitrary code.</li>
<li><strong>CVE-2026-17685</strong> (CVSS 8.8) - Google Chrome: A use after free vulnerability exists in the Autofill component of Google Chrome, which may allow an unauthenticated remote attacker to execute arbitrary code.</li>
</ul>
<p><a href="https://cvebrief.com/archive/2026/07/31/">Read full brief on CVE Brief</a></p>]]></content:encoded>
    </item>
</channel>
</rss>