Vulnfeed

Archives
Log in
Subscribe
August 25, 2026

[vulnfeed] 6 critical CVEs — 2026-08-25 04:00 UTC

vulnfeed Critical alert — 2026-08-25 05:01 UTC
6 new critical CVEs in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-78683CRITICAL
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_
CVSS 9.4
CVE-2026-56705CRITICAL
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthe
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFil
CVSS 9.3
CVE-2026-56710CRITICAL
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUse
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login
CVSS 9.3
CVE-2026-72699CRITICAL
The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The
The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE)
CVSS 9.3
CVE-2026-72702CRITICAL
Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute()
Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_st
CVSS 9.3
CVE-2026-78676CRITICAL
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, cor
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-08-25 08:00 UTC Older → [vulnfeed] 9 critical CVEs — 2026-08-25 00:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.