Vulnfeed

Archives
Log in
Subscribe
August 11, 2026

[vulnfeed] 7 critical CVEs — 2026-08-11 12:00 UTC

vulnfeed Critical alert — 2026-08-11 13:50 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-58231CRITICAL
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit spec
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploit
CVSS 10.0
CVE-2026-72603CRITICAL
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to exe
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives
CVSS 9.9
CVE-2026-10579CRITICAL
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as an
CVSS 9.8
CVE-2026-72550CRITICAL
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attac
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter
CVSS 9.8
CVE-2026-72599CRITICAL
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a
CVSS 9.8
CVE-2026-13737CRITICAL
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software cus
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, includ
CVSS 9.2
CVE-2026-13738CRITICAL
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operati
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault in
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 12 critical CVEs — 2026-08-11 16:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-08-11 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.