[vulnfeed] 18 critical CVEs — 2026-08-04 16:00 UTC
vulnfeed
Critical alert — 2026-08-04 18:09 UTC
18 new critical CVEs
in the last 5 hours — 18 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-64633CRITICAL
A vulnerability allowing remote unauthenticated code execution on the agent host.
A vulnerability allowing remote unauthenticated code execution on the agent host.
CVSS 10.0
CVE-2026-63455CRITICAL
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauth
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functi
CVSS 9.8
CVE-2026-63456CRITICAL
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauth
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functi
CVSS 9.8
CVE-2026-25289CRITICAL
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frame
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVSS 9.6
CVE-2026-58073CRITICAL
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a manage
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
CVSS 9.5
CVE-2026-69254CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, execu
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default
CVSS 9.4
CVE-2026-69256CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the C
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; althou
CVSS 9.4
CVE-2026-69259CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the S
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/S
CVSS 9.4
CVE-2026-61514CRITICAL
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packe
CVSS 9.3
CVE-2026-61515CRITICAL
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a
CVSS 9.3
CVE-2026-18801CRITICAL
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-at
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values.
An attacker who can create or update a customer can store a malicious
CVSS 9.3
CVE-2026-69098CRITICAL
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint th
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying c
CVSS 9.3
CVE-2026-69110CRITICAL
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remot
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by direct
CVSS 9.3
CVE-2026-69255CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the C
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-contro
CVSS 9.2
CVE-2026-60007CRITICAL
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for inv
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attack
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: