Vulnfeed

Archives
Log in
Subscribe
August 25, 2026

[vulnfeed] 16 critical CVEs — 2026-08-25 16:00 UTC

vulnfeed Critical alert — 2026-08-25 17:03 UTC
16 new critical CVEs in the last 5 hours — 16 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-77998CRITICAL
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOr
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Si
CVSS 10.0
CVE-2026-16286CRITICAL
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Softwar
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload
CVSS 9.8
CVE-2026-55546CRITICAL
QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed
QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strin
CVSS 9.8
CVE-2026-57909CRITICAL
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent ne
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.
CVSS 9.4
CVE-2026-57910CRITICAL
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to caus
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.
CVSS 9.3
CVE-2026-79657CRITICAL
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that t
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft mali
CVSS 9.3
CVE-2022-51000CRITICAL
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application t
CVSS 9.3
CVE-2024-58377CRITICAL
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllin
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the ma
CVSS 9.3
CVE-2024-58378CRITICAL
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which un
CVSS 9.3
CVE-2025-71407CRITICAL
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation aga
CVSS 9.3
CVE-2026-79675CRITICAL
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() f
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious
CVSS 9.3
CVE-2026-79774CRITICAL
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permis
CVSS 9.3
CVE-2026-79782CRITICAL
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HT
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AW
CVSS 9.3
CVE-2026-79664CRITICAL
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation
CVSS 9.1
CVE-2026-55536CRITICAL
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension:/
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 16 critical CVEs — 2026-08-25 20:00 UTC Older → [vulnfeed] 9 critical CVEs — 2026-08-25 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.