Vulnfeed

Archives
Log in
Subscribe
August 21, 2026

[vulnfeed] 34 critical CVEs — 2026-08-21 00:00 UTC

vulnfeed Critical alert — 2026-08-21 02:04 UTC
34 new critical CVEs in the last 5 hours — 34 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-65770CRITICAL
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance f
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
CVSS 10.0
CVE-2026-65801CRITICAL
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate pri
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-65816CRITICAL
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileg
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-69555CRITICAL
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-69836CRITICAL
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
CVSS 10.0
CVE-2026-67567CRITICAL
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who h
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security c
CVSS 9.9
CVE-2026-18835CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVSS 9.9
CVE-2026-63509CRITICAL
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
CVE-2026-68782CRITICAL
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database all
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
CVE-2026-68789CRITICAL
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database all
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
CVE-2026-69851CRITICAL
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
CVE-2026-17040CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
CVSS 9.8
CVE-2026-17118CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
CVSS 9.8
CVE-2026-17122CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
CVSS 9.8
CVE-2026-17136CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
CVSS 9.8

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 6 critical CVEs — 2026-08-21 04:00 UTC Older → [vulnfeed] 15 critical CVEs — 2026-08-20 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.