Vulnfeed

Archives
Log in
Subscribe
August 20, 2026

[vulnfeed] 9 critical CVEs — 2026-08-20 00:00 UTC

vulnfeed Critical alert — 2026-08-20 01:56 UTC
9 new critical CVEs in the last 5 hours — 9 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-53545CRITICAL
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities.
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/disconnect/:tunnelName teardown path in src/backend
CVSS 9.8
CVE-2026-53546CRITICAL
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities.
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/bac
CVSS 9.6
CVE-2026-53548CRITICAL
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities.
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes
CVSS 9.6
CVE-2026-76310CRITICAL
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an emb
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover sess
CVSS 9.4
CVE-2026-76311CRITICAL
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an emb
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job a
CVSS 9.4
CVE-2026-76312CRITICAL
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read t
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use
CVSS 9.4
CVE-2026-76850CRITICAL
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdepl
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyo
CVSS 9.3
CVE-2026-75595CRITICAL
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final,
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading t
CVSS 9.1
CVE-2026-76404CRITICAL
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrar
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of mi
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 21 critical CVEs — 2026-08-20 12:00 UTC Older → [vulnfeed] 52 critical CVEs — 2026-08-19 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.