Vulnfeed

Archives
Log in
Subscribe
August 14, 2026

[vulnfeed] 13 critical CVEs — 2026-08-14 00:00 UTC

vulnfeed Critical alert — 2026-08-14 03:04 UTC
13 new critical CVEs in the last 5 hours — 13 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-73843CRITICAL
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cl
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable a
CVSS 9.6
CVE-2026-72841CRITICAL
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenti
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended direc
CVSS 9.4
CVE-2026-72842CRITICAL
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users t
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attacker
CVSS 9.4
CVE-2026-72850CRITICAL
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload fi
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenam
CVSS 9.4
CVE-2026-72776CRITICAL
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any n
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to th
CVSS 9.3
CVE-2026-72839CRITICAL
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inheri
CVSS 9.3
CVE-2026-73663CRITICAL
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places t
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in a
CVSS 9.3
CVE-2026-73665CRITICAL
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(chec
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the
CVSS 9.3
CVE-2026-73420CRITICAL
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-be
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an ad
CVSS 9.1
CVE-2026-73421CRITICAL
NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications
NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the au
CVSS 9.1
CVE-2026-72851CRITICAL
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automation
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook tri
CVSS 9.0
CVE-2026-73302CRITICAL
Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/mid
Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verifi
CVSS 9.0
CVE-2026-73842CRITICAL
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ o
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-08-14 08:00 UTC Older → [vulnfeed] 9 critical CVEs — 2026-08-13 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.