Vulnfeed

Archives
Log in
Subscribe
August 20, 2026

[vulnfeed] 15 critical CVEs — 2026-08-20 20:00 UTC

vulnfeed Critical alert — 2026-08-20 20:53 UTC
15 new critical CVEs in the last 5 hours — 15 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-66785CRITICAL
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traf
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted networ
CVSS 9.9
CVE-2026-66788CRITICAL
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerabilit
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-contr
CVSS 9.9
CVE-2026-18265CRITICAL
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remot
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Aut
CVSS 9.8
CVE-2026-55642CRITICAL
dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-
dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is
CVSS 9.8
CVE-2026-2334CRITICAL
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypas
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-si
CVSS 9.4
CVE-2026-71428CRITICAL
The unstructured library provides open-source components for ingesting and pre-processing images and text docu
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argu
CVSS 9.3
CVE-2026-73251CRITICAL
Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TL
Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_bu
CVSS 9.3
CVE-2026-19586CRITICAL
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to op
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during O
CVSS 9.3
CVE-2026-63382CRITICAL
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-En
CVSS 9.2
CVE-2026-63385CRITICAL
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weak
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into litera
CVSS 9.2
CVE-2026-53424CRITICAL
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as t
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_
CVSS 9.1
CVE-2026-73253CRITICAL
Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker wit
Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client
CVSS 9.1
CVE-2026-73256CRITICAL
Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can e
Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: c
CVSS 9.1
CVE-2026-73257CRITICAL
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attack
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked.
CVSS 9.1
CVE-2026-54061CRITICAL
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
## Summary Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 34 critical CVEs — 2026-08-21 00:00 UTC Older → [vulnfeed] 21 critical CVEs — 2026-08-20 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.