Vulnfeed

Archives
Log in
Subscribe
August 27, 2026

[vulnfeed] 8 critical CVEs — 2026-08-27 20:00 UTC

vulnfeed Critical alert — 2026-08-27 22:27 UTC
8 new critical CVEs in the last 5 hours — 8 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-18885CRITICAL
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. Th
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execut
CVSS 10.0
CVE-2026-18886CRITICAL
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI pl
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances,
CVSS 10.0
CVE-2026-74820CRITICAL
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform.
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to exec
CVSS 10.0
CVE-2026-19092CRITICAL
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argumen
CVSS 9.8
CVE-2026-48996CRITICAL
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the d
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter does not sanitize note titles, and the GeoMap note view int
CVSS 9.3
CVE-2026-53578CRITICAL
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the d
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap
CVSS 9.3
CVE-2026-53579CRITICAL
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the d
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the book no
CVSS 9.3
CVE-2026-81934CRITICAL
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated atta
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-08-28 08:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-08-27 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.