[vulnfeed] 6 critical CVEs — 2026-08-21 04:00 UTC
vulnfeed
Critical alert — 2026-08-21 05:01 UTC
6 new critical CVEs
in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-77649CRITICAL
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control se
CVSS 9.8
CVE-2026-77650CRITICAL
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-contr
CVSS 9.8
CVE-2026-77651CRITICAL
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control ser
CVSS 9.8
CVE-2026-76156CRITICAL
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.
CVSS 9.4
CVE-2026-76155CRITICAL
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attack
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default adm
CVSS 9.3
CVE-2026-76158CRITICAL
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: