[vulnfeed] 12 critical CVEs — 2026-08-18 12:00 UTC
vulnfeed
Critical alert — 2026-08-18 13:17 UTC
12 new critical CVEs
in the last 5 hours — 12 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-75843CRITICAL
ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in be
ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scri
CVSS 9.4
CVE-2026-75851CRITICAL
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authentic
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted w
CVSS 9.4
CVE-2026-75626CRITICAL
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server bann
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into co
CVSS 9.3
CVE-2026-75627CRITICAL
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segm
CVSS 9.3
CVE-2026-74902CRITICAL
SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fai
SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers c
CVSS 9.3
CVE-2026-75827CRITICAL
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers wit
CVSS 9.3
CVE-2026-75828CRITICAL
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpa
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated edi
CVSS 9.3
CVE-2026-75832CRITICAL
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) c
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope()
CVSS 9.3
CVE-2026-75835CRITICAL
Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in user
Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling r
CVSS 9.3
CVE-2026-75837CRITICAL
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: ad
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin
CVSS 9.3
CVE-2026-75852CRITICAL
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-proto
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create c
CVSS 9.3
CVE-2026-75854CRITICAL
ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plug
ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can co
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: