Vulnfeed

Archives
Log in
Subscribe
August 14, 2026

[vulnfeed] 15 critical CVEs — 2026-08-14 20:00 UTC

vulnfeed Critical alert — 2026-08-14 20:52 UTC
15 new critical CVEs in the last 5 hours — 15 CVSS ≥ 9.0
New vulnerabilities
CVE-2025-7639CRITICAL
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privi
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deser
CVSS 10.0
CVE-2026-19188CRITICAL
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway produc
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint
CVSS 10.0
CVE-2026-73678CRITICAL
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerabil
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting c
CVSS 10.0
CVE-2026-17186CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to i
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
CVSS 9.9
CVE-2026-48528CRITICAL
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat version
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v
CVSS 9.8
CVE-2026-73849CRITICAL
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall w
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard
CVSS 9.8
CVE-2026-50027CRITICAL
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /ap
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even
CVSS 9.8
CVE-2026-17182CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or al
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
CVSS 9.8
CVE-2026-17184CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
CVSS 9.8
CVE-2026-19626CRITICAL
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially cra
CVSS 9.4
CVE-2026-19681CRITICAL
An authenticated command injection vulnerability exists in Security Center related to file upload processing.
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially re
CVSS 9.4
CVE-2026-19682CRITICAL
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exp
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the
CVSS 9.4
CVE-2026-17181CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
CVSS 9.3
CVE-2026-67365CRITICAL
Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated S
Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session,
CVSS 9.2
CVE-2026-49457CRITICAL
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked,
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
Older → [vulnfeed] 1 critical CVE — 2026-08-14 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.