Vulnfeed

Archives
Log in
Subscribe
August 7, 2026

[vulnfeed] 4 critical CVEs — 2026-08-07 20:00 UTC

vulnfeed Critical alert — 2026-08-07 21:06 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-64637CRITICAL
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
CVSS 9.9
CVE-2026-61808CRITICAL
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API serv
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an un
CVSS 9.8
CVE-2026-48039CRITICAL
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` uncondition
CVSS 9.1
CVE-2026-71851CRITICAL
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomnes
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry p
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-08-08 00:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-08-07 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.