Vulnfeed

Archives
Log in
Subscribe
August 21, 2026

[vulnfeed] 7 critical CVEs — 2026-08-21 20:00 UTC

vulnfeed Critical alert — 2026-08-21 20:45 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-69502CRITICAL
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-76904CRITICAL
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
### Summary An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation: * `jsonArrayContains` function Requires PostGIS 12 or greater with a
CVSS 9.8
CVE-2026-77810CRITICAL
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to pr
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, u
CVSS 9.4
CVE-2026-77234CRITICAL
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled por
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upg
CVSS 9.3
CVE-2026-75932CRITICAL
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit t
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once
CVSS 9.2
CVE-2026-39909CRITICAL
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler tha
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by st
CVSS 9.2
CVE-2026-62674CRITICAL
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 8 critical CVEs — 2026-08-22 00:00 UTC Older → [vulnfeed] 19 critical CVEs — 2026-08-21 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.