Vulnfeed

Archives
Log in
Subscribe
August 26, 2026

[vulnfeed] 7 critical CVEs — 2026-08-26 16:00 UTC

vulnfeed Critical alert — 2026-08-26 18:10 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-54569CRITICAL
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-
CVSS 9.8
CVE-2026-54523CRITICAL
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, a
CVSS 9.6
CVE-2026-12717CRITICAL
An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Tran
An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated
CVSS 9.4
CVE-2026-80428CRITICAL
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitial
CVSS 9.3
CVE-2026-81032CRITICAL
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all inte
CVSS 9.3
CVE-2026-75062CRITICAL
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated a
CVSS 9.2
CVE-2026-75896CRITICAL
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderah
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords. This issue affects Liderahenk:
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 4 critical CVEs — 2026-08-26 20:00 UTC Older → [vulnfeed] 6 critical CVEs — 2026-08-26 00:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.