[vulnfeed] 21 critical CVEs — 2026-08-05 16:00 UTC
vulnfeed
Critical alert — 2026-08-05 18:00 UTC
21 new critical CVEs
in the last 5 hours — 21 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-71268CRITICAL
OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directiv
OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) program files and writes the referenced content to
CVSS 9.9
CVE-2026-7329CRITICAL
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privile
CVSS 9.9
CVE-2026-8709CRITICAL
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST ro
CVSS 9.9
CVE-2026-9193CRITICAL
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 1
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalat
CVSS 9.9
CVE-2026-20303CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN eng
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted
CVSS 9.9
CVE-2026-20304CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN eng
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted
CVSS 9.9
CVE-2026-71262CRITICAL
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the app
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global
CVSS 9.8
CVE-2026-71267CRITICAL
microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-suppl
microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcp
CVSS 9.8
CVE-2026-71278CRITICAL
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_route
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` field. This route does not take the AuthToken reque
CVSS 9.8
CVE-2026-71289CRITICAL
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (
CVSS 9.8
CVE-2026-9192CRITICAL
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 1
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execut
CVSS 9.8
CVE-2026-20272CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software eng
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted
CVSS 9.8
CVE-2026-15587CRITICAL
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platf
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative
CVSS 9.4
CVE-2026-9195CRITICAL
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to ex
CVSS 9.3
CVE-2026-39923CRITICAL
Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated a
Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset p
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: