[vulnfeed] 7 critical CVEs — 2026-08-21 20:00 UTC
vulnfeed
Critical alert — 2026-08-21 20:45 UTC
7 new critical CVEs
in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-69502CRITICAL
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-76904CRITICAL
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
### Summary
An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation:
* `jsonArrayContains` function
Requires PostGIS 12 or greater with a
CVSS 9.8
CVE-2026-77810CRITICAL
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to pr
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, u
CVSS 9.4
CVE-2026-77234CRITICAL
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled por
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upg
CVSS 9.3
CVE-2026-75932CRITICAL
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit t
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once
CVSS 9.2
CVE-2026-39909CRITICAL
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler tha
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by st
CVSS 9.2
CVE-2026-62674CRITICAL
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: