Vulnfeed

Archives
Log in
Subscribe
August 26, 2026

[vulnfeed] 6 critical CVEs — 2026-08-26 00:00 UTC

vulnfeed Critical alert — 2026-08-26 02:06 UTC
6 new critical CVEs in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-65083CRITICAL
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could c
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability m
CVSS 9.9
CVE-2026-65093CRITICAL
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successf
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, d
CVSS 9.9
CVE-2026-80104CRITICAL
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it t
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/ag
CVSS 9.3
CVE-2026-79911CRITICAL
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is t
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler.
CVSS 9.3
CVE-2026-80138CRITICAL
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passi
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to t
CVSS 9.2
CVE-2026-62862CRITICAL
Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default pas
Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that l
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 7 critical CVEs — 2026-08-26 16:00 UTC Older → [vulnfeed] 16 critical CVEs — 2026-08-25 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.