Vulnfeed

Archives
Log in
Subscribe
August 24, 2026

[vulnfeed] 16 critical CVEs — 2026-08-24 16:00 UTC

vulnfeed Critical alert — 2026-08-24 17:02 UTC
16 new critical CVEs in the last 5 hours — 16 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-77995CRITICAL
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipu
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
CVSS 10.0
CVE-2026-28165CRITICAL
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
CVSS 9.8
CVE-2026-32558CRITICAL
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
CVSS 9.8
CVE-2026-66587CRITICAL
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVSS 9.8
CVE-2026-66648CRITICAL
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
CVSS 9.8
CVE-2026-66650CRITICAL
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
CVSS 9.8
CVE-2026-78387CRITICAL
RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin
RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform an e
CVSS 9.4
CVE-2026-32551CRITICAL
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
CVSS 9.3
CVE-2026-78365CRITICAL
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record,
CVSS 9.3
CVE-2026-67602CRITICAL
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticat
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechani
CVSS 9.3
CVE-2026-76070CRITICAL
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unaut
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base
CVSS 9.3
CVE-2026-76071CRITICAL
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unaut
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destH
CVSS 9.3
CVE-2026-78370CRITICAL
RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthent
RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The /export/<data
CVSS 9.2
CVE-2026-78372CRITICAL
RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom not
RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked as private. An unauthenticated or otherwise unauthorized remote attacker can ac
CVSS 9.2
CVE-2026-59564CRITICAL
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connec
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 10 critical CVEs — 2026-08-24 20:00 UTC Older → [vulnfeed] 7 critical CVEs — 2026-08-24 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.