[vulnfeed] 7 critical CVEs — 2026-08-24 12:00 UTC
vulnfeed
Critical alert — 2026-08-24 13:28 UTC
7 new critical CVEs
in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-66897CRITICAL
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit pe
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host
CVSS 9.9
CVE-2026-28165CRITICAL
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
CVSS 9.8
CVE-2026-32558CRITICAL
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
CVSS 9.8
CVE-2026-66587CRITICAL
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVSS 9.8
CVE-2026-66648CRITICAL
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
CVSS 9.8
CVE-2026-66650CRITICAL
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
CVSS 9.8
CVE-2026-32551CRITICAL
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: