Vulnfeed

Archives
Log in
Subscribe
August 4, 2026

[vulnfeed] 21 critical CVEs — 2026-08-04 20:00 UTC

vulnfeed Critical alert — 2026-08-04 21:45 UTC
21 new critical CVEs in the last 5 hours — 21 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-64633CRITICAL
A vulnerability allowing remote unauthenticated code execution on the agent host.
A vulnerability allowing remote unauthenticated code execution on the agent host.
CVSS 10.0
CVE-2025-29296CRITICAL
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Ma
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, and H3C NE36 Pro V100R002 contain multiple co
CVSS 9.8
CVE-2026-63455CRITICAL
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauth
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functi
CVSS 9.8
CVE-2026-63456CRITICAL
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauth
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functi
CVSS 9.8
CVE-2026-24254CRITICAL
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could c
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code
CVSS 9.8
CVE-2026-0163CRITICAL
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could l
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User
CVSS 9.8
CVE-2026-58073CRITICAL
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a manage
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
CVSS 9.5
CVE-2026-70470CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowi
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be
CVSS 9.5
CVE-2026-70477CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a pro
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with
CVSS 9.5
CVE-2026-69256CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the C
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; althou
CVSS 9.4
CVE-2026-69259CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the S
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/S
CVSS 9.4
CVE-2026-69264CRITICAL
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is lo
CVSS 9.4
CVE-2017-20241CRITICAL
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote at
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute ar
CVSS 9.3
CVE-2017-20242CRITICAL
Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote a
Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute a
CVSS 9.3
CVE-2026-49435CRITICAL
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with admini
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-08-05 00:00 UTC Older → [vulnfeed] 18 critical CVEs — 2026-08-04 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.