[vulnfeed] 29 critical CVEs — 2026-08-11 20:00 UTC
vulnfeed
Critical alert — 2026-08-11 21:11 UTC
29 new critical CVEs
in the last 5 hours — 2 actively exploited (CISA KEV) · 27 CVSS ≥ 9.0
New vulnerabilities
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (AS
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthe
CVSS 8.6
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVSS 7.0
CVE-2026-48362CRITICAL
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command In
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of th
CVSS 10.0
CVE-2026-27302CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbi
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vu
CVSS 10.0
CVE-2026-71398CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbi
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vu
CVSS 10.0
CVE-2026-45618CRITICAL
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to exe
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
CVSS 10.0
CVE-2026-12571CRITICAL
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
CVSS 9.8
CVE-2026-59124CRITICAL
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized at
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-62815CRITICAL
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-62878CRITICAL
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-62893CRITICAL
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-65791CRITICAL
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code ove
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-73211CRITICAL
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore()
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowin
CVSS 9.8
CVE-2026-16230CRITICAL
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6.
CVSS 9.8
CVE-2026-71384CRITICAL
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An att
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized
CVSS 9.6
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: