[vulnfeed] 6 critical CVEs — 2026-08-26 00:00 UTC
vulnfeed
Critical alert — 2026-08-26 02:06 UTC
6 new critical CVEs
in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-65083CRITICAL
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could c
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability m
CVSS 9.9
CVE-2026-65093CRITICAL
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successf
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, d
CVSS 9.9
CVE-2026-80104CRITICAL
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it t
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/ag
CVSS 9.3
CVE-2026-79911CRITICAL
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is t
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler.
CVSS 9.3
CVE-2026-80138CRITICAL
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passi
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to t
CVSS 9.2
CVE-2026-62862CRITICAL
Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default pas
Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that l
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: