Vulnfeed

Archives
Log in
Subscribe
August 11, 2026

[vulnfeed] 12 critical CVEs — 2026-08-11 16:00 UTC

vulnfeed Critical alert — 2026-08-11 17:24 UTC
12 new critical CVEs in the last 5 hours — 12 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-58115CRITICAL
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentica
CVSS 10.0
CVE-2026-48056CRITICAL
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allo
CVSS 10.0
CVE-2026-17061CRITICAL
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
CVSS 10.0
CVE-2026-46670CRITICAL
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Baza
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a defau
CVSS 9.8
CVE-2026-72920CRITICAL
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagem
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, all
CVSS 9.8
CVE-2026-18972CRITICAL
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom heade
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low
CVSS 9.6
CVE-2026-72785CRITICAL
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user hol
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can
CVSS 9.3
CVE-2026-48046CRITICAL
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised render
CVSS 9.3
CVE-2025-31114CRITICAL
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remo
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker
CVSS 9.3
CVE-2026-73080CRITICAL
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volu
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3
CVSS 9.3
CVE-2026-47702CRITICAL
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate agai
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gain
CVSS 9.1
CVE-2026-73069CRITICAL
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a wo
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for t
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 29 critical CVEs — 2026-08-11 20:00 UTC Older → [vulnfeed] 7 critical CVEs — 2026-08-11 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.