Vulnfeed

Archives
Log in
Subscribe
August 17, 2026

[vulnfeed] 14 critical CVEs — 2026-08-17 20:00 UTC

vulnfeed Critical alert — 2026-08-17 20:50 UTC
14 new critical CVEs in the last 5 hours — 14 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-74253CRITICAL
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks found in Joomla’
CVSS 10.0
GHSA-m5w8-4gq2-6f8xCRITICAL
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack
# NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f) **CWE**: CWE-200 (Exposure of Sensitive Info
CVSS 10.0
CVE-2026-66792CRITICAL
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a man
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafte
CVSS 9.9
CVE-2026-47686CRITICAL
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
**Affected:** vm2 <= 3.11.3 **CVSS 3.1:** 9.9 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) **CWE:** CWE-693 (Protection Mechanism Failure) **Prerequisite:** Embedder exposes a host function tha
CVSS 9.9
CVE-2026-50768CRITICAL
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote atta
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document
CVSS 9.8
CVE-2026-47698CRITICAL
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
### Summary VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. ### Detail
CVSS 9.8
CVE-2026-19478CRITICAL
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allo
CVSS 9.4
CVE-2026-55674CRITICAL
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unaut
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_sc
CVSS 9.3
CVE-2026-74254CRITICAL
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed
CVSS 9.3
CVE-2026-64859CRITICAL
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return
CVSS 9.1
CVE-2026-71479CRITICAL
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_comp
CVSS 9.1
CVE-2026-75045CRITICAL
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could dow
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVSS 9.1
CVE-2026-51346CRITICAL
SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to e
SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.
CVSS 9.1
CVE-2026-71472CRITICAL
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub ad
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 8 critical CVEs — 2026-08-18 00:00 UTC Older → [vulnfeed] 7 critical CVEs — 2026-08-17 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.