Vulnfeed

Archives
Log in
Subscribe
August 25, 2026

[vulnfeed] 9 critical CVEs — 2026-08-25 12:00 UTC

vulnfeed Critical alert — 2026-08-25 13:26 UTC
9 new critical CVEs in the last 5 hours — 9 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-78568CRITICAL
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including,
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient p
CVSS 9.8
CVE-2026-78570CRITICAL
The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl
The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privil
CVSS 9.8
CVE-2026-77136CRITICAL
The extension passes the raw value of a form field configured as "This field contains the name of the sender"
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. A
CVSS 9.5
CVE-2026-57909CRITICAL
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent ne
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.
CVSS 9.4
CVE-2026-63586CRITICAL
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authen
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is i
CVSS 9.3
CVE-2026-77138CRITICAL
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP'
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payloa
CVSS 9.3
CVE-2026-57910CRITICAL
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to caus
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.
CVSS 9.3
CVE-2026-79657CRITICAL
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that t
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft mali
CVSS 9.3
CVE-2026-79664CRITICAL
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 16 critical CVEs — 2026-08-25 16:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-08-25 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.