Vulnfeed

Archives
Log in
Subscribe
August 21, 2026

[vulnfeed] 19 critical CVEs — 2026-08-21 16:00 UTC

vulnfeed Critical alert — 2026-08-21 16:58 UTC
19 new critical CVEs in the last 5 hours — 19 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-69502CRITICAL
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-48749CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrar
CVSS 9.9
CVE-2026-48750CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-out
CVSS 9.9
CVE-2026-48751CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution
CVSS 9.9
CVE-2026-48752CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly
CVSS 9.9
CVE-2026-48753CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoi
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. Thi
CVSS 9.9
CVE-2026-48755CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-p
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed comman
CVSS 9.9
CVE-2026-48769CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exist
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` h
CVSS 9.9
CVE-2026-62867CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-p
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection
CVSS 9.9
CVE-2026-62940CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critica
CVSS 9.9
CVE-2026-62941CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance acro
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the sourc
CVSS 9.9
CVE-2026-63125CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-conf
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_in
CVSS 9.9
CVE-2026-63343CRITICAL
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus
CVSS 9.9
CVE-2026-77806CRITICAL
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request heade
CVSS 9.8
CVE-2026-77087CRITICAL
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to exe
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that,
CVSS 9.4

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 7 critical CVEs — 2026-08-21 20:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-08-21 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.