[vulnfeed] 9 critical CVEs — 2026-08-03 12:00 UTC
vulnfeed
Critical alert — 2026-08-03 15:22 UTC
9 new critical CVEs
in the last 5 hours — 9 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-69083CRITICAL
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute a
CVSS 9.9
CVE-2026-69084CRITICAL
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read
CVSS 9.9
CVE-2026-69085CRITICAL
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where th
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no e
CVSS 9.9
CVE-2026-2346CRITICAL
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Soft
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack.
This issue affects Mobile App: through 12.05.2026.
CVSS 9.8
CVE-2026-18574CRITICAL
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Man
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to
CVSS 9.3
CVE-2026-64827CRITICAL
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authenti
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAcces
CVSS 9.3
CVE-2026-68584CRITICAL
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-ret
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform
CVSS 9.2
CVE-2026-68586CRITICAL
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the correspondi
CVSS 9.2
CVE-2026-68587CRITICAL
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransacti
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rend
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: