[vulnfeed] 15 critical CVEs — 2026-08-05 12:00 UTC
vulnfeed
Critical alert — 2026-08-05 14:43 UTC
15 new critical CVEs
in the last 5 hours — 15 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-71268CRITICAL
OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directiv
OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) program files and writes the referenced content to
CVSS 9.9
CVE-2026-71231CRITICAL
IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM users WHER
IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cook
CVSS 9.8
CVE-2026-71237CRITICAL
Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from $_POST['
Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from $_POST['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query("select
CVSS 9.8
CVE-2026-71248CRITICAL
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenatio
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: $sql = "select * from user where email = '$email' and password =
CVSS 9.8
CVE-2026-71254CRITICAL
nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record()
nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the tot
CVSS 9.8
CVE-2026-71256CRITICAL
nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_d
nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic() / recv_read_device_identification_res() in nanomodbus.c. A fi
CVSS 9.8
CVE-2026-71262CRITICAL
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the app
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global
CVSS 9.8
CVE-2026-71267CRITICAL
microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-suppl
microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcp
CVSS 9.8
CVE-2026-71278CRITICAL
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_route
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` field. This route does not take the AuthToken reque
CVSS 9.8
CVE-2026-71289CRITICAL
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (
CVSS 9.8
CVE-2026-66747CRITICAL
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published bui
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenW
CVSS 9.3
CVE-2026-44945CRITICAL
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersona
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user
global role can gain full adm
CVSS 9.1
CVE-2026-71238CRITICAL
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token
CVSS 9.1
CVE-2026-71263CRITICAL
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/po
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-tha
CVSS 9.1
CVE-2026-71277CRITICAL
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authoriza
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token stor
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: