Vulnfeed

Archives
Log in
Subscribe
August 12, 2026

[vulnfeed] 7 critical CVEs — 2026-08-12 16:00 UTC

vulnfeed Critical alert — 2026-08-12 17:25 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-73263CRITICAL
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeco
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-arg
CVSS 9.9
CVE-2026-73294CRITICAL
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_u
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemo
CVSS 9.9
CVE-2026-26035CRITICAL
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, For
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, F
CVSS 9.8
CVE-2026-50561CRITICAL
Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior t
Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versi
CVSS 9.4
CVE-2026-57858CRITICAL
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the Bookin
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaS
CVSS 9.3
CVE-2026-64639CRITICAL
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privilege
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server adm
CVSS 9.3
CVE-2026-67285CRITICAL
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are acc
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 32 critical CVEs — 2026-08-12 20:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-08-12 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.