[vulnfeed] 21 critical CVEs — 2026-08-18 20:00 UTC
vulnfeed
Critical alert — 2026-08-18 20:45 UTC
21 new critical CVEs
in the last 5 hours — 21 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-55107CRITICAL
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
### Summary
A guest mruby script running inside the Kobako sandbox can execute arbitrary
Ruby in the host process, fully escaping the sandbox.
### Details
A host embeds bound "Service" objects that g
CVSS 10.0
CVE-2026-66780CRITICAL
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assi
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluste
CVSS 9.9
CVE-2026-55166CRITICAL
Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority
Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.
CVSS 9.9
CVE-2026-45117CRITICAL
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resu
CVSS 9.8
CVE-2026-67271CRITICAL
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attac
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of
CVSS 9.8
CVE-2026-47627CRITICAL
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.
CVSS 9.8
CVE-2026-55211CRITICAL
surfio has an out-of-bounds read
### Impact
Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused file
CVSS 9.8
CVE-2026-55209CRITICAL
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-b
### Impact
Prior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a
CVSS 9.8
CVE-2026-12564CRITICAL
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service accoun
CVSS 9.6
CVE-2026-57580CRITICAL
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configur
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML c
CVSS 9.4
CVE-2026-45118CRITICAL
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code inj
CVSS 9.3
CVE-2026-75926CRITICAL
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directo
CVSS 9.3
CVE-2026-50161CRITICAL
libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4
libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow
CVSS 9.3
CVE-2026-52735CRITICAL
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects b
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabl
CVSS 9.3
CVE-2026-75856CRITICAL
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: