Vulnfeed

Archives
Log in
Subscribe
August 17, 2026

[vulnfeed] 20 critical CVEs — 2026-08-17 12:00 UTC

vulnfeed Critical alert — 2026-08-17 13:13 UTC
20 new critical CVEs in the last 5 hours — 20 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-74800CRITICAL
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrar
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can u
CVSS 9.4
CVE-2026-74798CRITICAL
SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool p
SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAt
CVSS 9.3
CVE-2026-74872CRITICAL
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verific
CVSS 9.3
CVE-2026-74875CRITICAL
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema
CVSS 9.3
CVE-2026-74876CRITICAL
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() f
CVSS 9.3
CVE-2026-74878CRITICAL
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is no
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentica
CVSS 9.3
CVE-2026-74880CRITICAL
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history
CVSS 9.3
CVE-2026-74885CRITICAL
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module count
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additi
CVSS 9.3
CVE-2026-74886CRITICAL
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuar
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attacke
CVSS 9.3
CVE-2026-74887CRITICAL
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at lin
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the co
CVSS 9.3
CVE-2026-74889CRITICAL
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization fun
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key
CVSS 9.3
CVE-2026-74890CRITICAL
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that di
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment varia
CVSS 9.3
CVE-2026-74894CRITICAL
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload ar
CVSS 9.3
CVE-2026-74895CRITICAL
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to
CVSS 9.3
CVE-2026-74896CRITICAL
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AS
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use _
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
Older → [vulnfeed] 1 critical CVE — 2026-08-17 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.