Vulnfeed

Archives
Log in
Subscribe
August 31, 2026

[vulnfeed] 7 critical CVEs — 2026-08-31 16:00 UTC

vulnfeed Critical alert — 2026-08-31 16:14 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-82970CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCP
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice fo
CVSS 10.0
CVE-2026-82876CRITICAL
Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmw
Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitra
CVSS 9.3
CVE-2026-82693CRITICAL
A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelne
A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to
CVSS 9.3
CVE-2026-82694CRITICAL
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHand
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing aut
CVSS 9.3
CVE-2026-82695CRITICAL
A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /go
A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentic
CVSS 9.3
CVE-2026-59111CRITICAL
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Di
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to 
CVSS 9.3
CVE-2026-66047CRITICAL
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plu
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-09-01 04:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-08-31 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.