[vulnfeed] 7 critical CVEs — 2026-08-11 12:00 UTC
vulnfeed
Critical alert — 2026-08-11 13:50 UTC
7 new critical CVEs
in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-58231CRITICAL
SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit spec
SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially crafted
input to certain functions lacking sufficient validation. Successful
exploit
CVSS 10.0
CVE-2026-72603CRITICAL
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to exe
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives
CVSS 9.9
CVE-2026-10579CRITICAL
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as an
CVSS 9.8
CVE-2026-72550CRITICAL
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attac
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter
CVSS 9.8
CVE-2026-72599CRITICAL
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a
CVSS 9.8
CVE-2026-13737CRITICAL
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software cus
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, includ
CVSS 9.2
CVE-2026-13738CRITICAL
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operati
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault in
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: