[vulnfeed] 32 critical CVEs — 2026-08-12 20:00 UTC
vulnfeed
Critical alert — 2026-08-12 21:10 UTC
32 new critical CVEs
in the last 5 hours — 32 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-73299CRITICAL
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScrip
CVSS 10.0
CVE-2026-73294CRITICAL
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_u
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemo
CVSS 9.9
CVE-2026-16860CRITICAL
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an u
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
CVSS 9.9
CVE-2026-19656CRITICAL
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary op
CVSS 9.9
CVE-2026-62420CRITICAL
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project securit
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-pro
CVSS 9.9
CVE-2026-63293CRITICAL
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations o
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whe
CVSS 9.9
CVE-2026-63294CRITICAL
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system.
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly
CVSS 9.9
CVE-2026-63296CRITICAL
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restric
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accep
CVSS 9.9
CVE-2026-63297CRITICAL
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authe
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copi
CVSS 9.9
CVE-2026-63298CRITICAL
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling a
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying
CVSS 9.9
CVE-2026-63299CRITICAL
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and vol
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations
CVSS 9.9
CVE-2026-63300CRITICAL
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allo
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project
CVSS 9.9
CVE-2026-72508CRITICAL
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RH
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy atta
CVSS 9.9
CVE-2026-73268CRITICAL
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with creat
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specificat
CVSS 9.9
CVE-2026-73269CRITICAL
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resou
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped Cluste
CVSS 9.9
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: