Vulnfeed

Archives
Log in
Subscribe
August 29, 2026

[vulnfeed] 2 critical CVEs — 2026-08-29 12:00 UTC

vulnfeed Critical alert — 2026-08-29 13:53 UTC
2 new critical CVEs in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-14494CRITICAL
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamical
CVSS 9.8
CVE-2026-82448CRITICAL
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unaut
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child n
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-08-29 16:00 UTC Older → [vulnfeed] 17 critical CVEs — 2026-08-28 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.