Vulnfeed

Archives
Log in
Subscribe
August 17, 2026

[vulnfeed] 7 critical CVEs — 2026-08-17 16:00 UTC

vulnfeed Critical alert — 2026-08-17 16:51 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-74843CRITICAL
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the f
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the compone
CVSS 9.3
CVE-2026-71566CRITICAL
FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because i
FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG f
CVSS 9.3
CVE-2026-55674CRITICAL
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unaut
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_sc
CVSS 9.3
CVE-2026-64859CRITICAL
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return
CVSS 9.1
CVE-2026-71479CRITICAL
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_comp
CVSS 9.1
CVE-2026-75045CRITICAL
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could dow
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVSS 9.1
CVE-2026-14564CRITICAL
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsig
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 14 critical CVEs — 2026-08-17 20:00 UTC Older → [vulnfeed] 20 critical CVEs — 2026-08-17 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.