Vulnfeed

Archives
Log in
Subscribe
August 20, 2026

[vulnfeed] 21 critical CVEs — 2026-08-20 12:00 UTC

vulnfeed Critical alert — 2026-08-20 13:25 UTC
21 new critical CVEs in the last 5 hours — 21 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-73992CRITICAL
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVSS 9.9
CVE-2026-74014CRITICAL
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
CVSS 9.9
CVE-2026-74016CRITICAL
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
CVSS 9.9
CVE-2026-74018CRITICAL
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
CVSS 9.9
CVE-2025-15689CRITICAL
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVSS 9.8
CVE-2026-66583CRITICAL
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVSS 9.8
CVE-2026-66672CRITICAL
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
CVSS 9.8
CVE-2026-66682CRITICAL
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVSS 9.8
CVE-2026-73993CRITICAL
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVSS 9.8
CVE-2026-74001CRITICAL
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVSS 9.8
CVE-2026-11861CRITICAL
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Act
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal,
CVSS 9.6
CVE-2025-15688CRITICAL
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
CVSS 9.3
CVE-2026-66592CRITICAL
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVSS 9.3
CVE-2026-66593CRITICAL
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVSS 9.3
CVE-2026-66609CRITICAL
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 21 critical CVEs — 2026-08-20 16:00 UTC Older → [vulnfeed] 9 critical CVEs — 2026-08-20 00:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.