Vulnfeed

Archives
Log in
Subscribe
August 8, 2026

[vulnfeed] 3 critical CVEs — 2026-08-08 00:00 UTC

vulnfeed Critical alert — 2026-08-08 02:26 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-46409CRITICAL
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top.
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<rando
CVSS 9.6
CVE-2026-47243CRITICAL
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machine
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs
CVSS 9.2
CVE-2026-48170CRITICAL
`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applyi
`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`.
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-08-08 08:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-08-07 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.