Vulnfeed

Archives
Log in
Subscribe
August 25, 2026

[vulnfeed] 9 critical CVEs — 2026-08-25 00:00 UTC

vulnfeed Critical alert — 2026-08-25 01:57 UTC
9 new critical CVEs in the last 5 hours — 9 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-32559CRITICAL
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
CVSS 9.9
CVE-2026-32563CRITICAL
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVSS 9.8
CVE-2026-78262CRITICAL
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVSS 9.8
CVE-2026-78265CRITICAL
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVSS 9.8
CVE-2026-78267CRITICAL
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVSS 9.8
CVE-2026-32554CRITICAL
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
CVSS 9.3
CVE-2026-32555CRITICAL
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
CVSS 9.3
CVE-2026-77635CRITICAL
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respect
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL
CVSS 9.2
CVE-2026-77337CRITICAL
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applicatio
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow a
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 6 critical CVEs — 2026-08-25 04:00 UTC Older → [vulnfeed] 10 critical CVEs — 2026-08-24 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.