Vulnfeed

Archives
Log in
Subscribe
August 10, 2026

[vulnfeed] 6 critical CVEs — 2026-08-10 16:00 UTC

vulnfeed Critical alert — 2026-08-10 17:21 UTC
6 new critical CVEs in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-13206CRITICAL
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zy
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 200
CVSS 9.8
CVE-2026-19429CRITICAL
Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026
Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets, bypassing CVE-2026-33001. Any user with Item/Build access triggers tar extraction via POST /job/{name}/build
CVSS 9.4
CVE-2026-63106CRITICAL
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MyS
CVSS 9.3
CVE-2026-47754CRITICAL
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x th
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiv
CVSS 9.3
CVE-2026-48158CRITICAL
use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19
use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25d
CVSS 9.3
CVE-2026-66738CRITICAL
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 32 critical CVEs — 2026-08-10 20:00 UTC Older → [vulnfeed] 13 critical CVEs — 2026-08-10 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.