Vulnfeed

Archives
Log in
Subscribe
August 10, 2026

[vulnfeed] 13 critical CVEs — 2026-08-10 12:00 UTC

vulnfeed Critical alert — 2026-08-10 13:51 UTC
13 new critical CVEs in the last 5 hours — 13 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-66915CRITICAL
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.7 - An unauthenticated attacker could
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.7 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
CVSS 10.0
CVE-2026-72565CRITICAL
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypa
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having op
CVSS 9.8
CVE-2026-72567CRITICAL
An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthent
An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The ap
CVSS 9.8
CVE-2026-72577CRITICAL
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to conne
CVSS 9.8
CVE-2026-72580CRITICAL
An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to
An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on Xiaomi smart speakers running the patch. The /mute a
CVSS 9.8
CVE-2026-72589CRITICAL
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remot
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a crafted crontab database fi
CVSS 9.8
CVE-2026-72590CRITICAL
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remot
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /cront
CVSS 9.8
CVE-2026-72592CRITICAL
An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote att
An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty upl
CVSS 9.8
CVE-2026-72593CRITICAL
A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attack
A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and
CVSS 9.8
CVE-2026-13206CRITICAL
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zy
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 200
CVSS 9.8
CVE-2026-72564CRITICAL
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attac
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued
CVSS 9.6
CVE-2026-72569CRITICAL
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote att
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application
CVSS 9.1
CVE-2026-72575CRITICAL
An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to
An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, create, update, and delete usergroup records. The permission check functions (CanRea
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 6 critical CVEs — 2026-08-10 16:00 UTC Older → [vulnfeed] 11 critical CVEs — 2026-08-09 00:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.