[vulnfeed] 7 critical CVEs — 2026-08-17 16:00 UTC
vulnfeed
Critical alert — 2026-08-17 16:51 UTC
7 new critical CVEs
in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-74843CRITICAL
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the f
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the compone
CVSS 9.3
CVE-2026-71566CRITICAL
FakeFish handles incoming credentials by passing them down
to scripts. This works for real hardware because i
FakeFish handles incoming credentials by passing them down
to scripts. This works for real hardware because in the end it's up to
the BMC to validate them. However, KubeVirt relies on a KUBECONFIG f
CVSS 9.3
CVE-2026-55674CRITICAL
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unaut
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_sc
CVSS 9.3
CVE-2026-64859CRITICAL
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return
CVSS 9.1
CVE-2026-71479CRITICAL
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_comp
CVSS 9.1
CVE-2026-75045CRITICAL
In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could dow
In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVSS 9.1
CVE-2026-14564CRITICAL
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data.
This issue affects Logsig
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: