[vulnfeed] 10 critical CVEs — 2026-08-05 08:00 UTC
vulnfeed
Critical alert — 2026-08-05 10:57 UTC
10 new critical CVEs
in the last 5 hours — 10 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-10090CRITICAL
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat A
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privi
CVSS 9.9
CVE-2026-71207CRITICAL
The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $
The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session value
CVSS 9.8
CVE-2026-71214CRITICAL
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the call
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object
CVSS 9.8
CVE-2026-70376CRITICAL
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in data/inc/f
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-reques
CVSS 9.6
CVE-2026-9273CRITICAL
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and inclu
CVSS 9.3
CVE-2026-4431CRITICAL
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a miss
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including,
CVSS 9.1
CVE-2026-5581CRITICAL
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deleti
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks i
CVSS 9.1
CVE-2026-71213CRITICAL
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attem
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configurati
CVSS 9.1
CVE-2026-10059CRITICAL
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator w
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced Cl
CVSS 9.1
CVE-2026-44945CRITICAL
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersona
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user
global role can gain full adm
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: