[vulnfeed] 52 critical CVEs — 2026-08-19 20:00 UTC
vulnfeed
Critical alert — 2026-08-19 20:50 UTC
52 new critical CVEs
in the last 5 hours — 52 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-20030CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineeri
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a
CVSS 10.0
CVE-2026-20315CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload eng
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted
CVSS 10.0
CVE-2026-20317CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload eng
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted
CVSS 10.0
CVE-2026-20357CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineeri
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a
CVSS 10.0
CVE-2026-20358CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineeri
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a
CVSS 10.0
CVE-2026-22306CRITICAL
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleart
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows
CVSS 10.0
CVE-2026-20231CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload eng
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted
CVSS 9.9
CVE-2026-20359CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineeri
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a
CVSS 9.9
CVE-2026-70496CRITICAL
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster adm
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RB
CVSS 9.9
CVE-2026-55089CRITICAL
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.t
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredCl
CVSS 9.9
CVE-2026-18315CRITICAL
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and
CVSS 9.8
CVE-2026-16834CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due t
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer underflow.
CVSS 9.8
CVE-2026-16840CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
CVSS 9.8
CVE-2026-16845CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
CVSS 9.8
CVE-2026-16862CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
CVSS 9.8
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: