| unknown |
CVE-2026-45199 — Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmwa… |
vulnerability |
nvd |
CVE-2026-45199 |
|
2026-08-21 |
| high |
CVE-2026-18409 — The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Te… |
vulnerability |
nvd |
CVE-2026-18409 |
|
2026-08-21 |
| unknown |
New infosec products of the week: August 21, 2026 |
news |
general-news |
|
|
2026-08-21 |
| unknown |
CVE-2026-76158 — External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center f… |
vulnerability |
nvd |
CVE-2026-76158 |
|
2026-08-21 |
| low |
CVE-2026-76137 — Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running… |
vulnerability |
nvd |
CVE-2026-76137 |
|
2026-08-21 |
| medium |
CVE-2026-76131 — Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate… |
vulnerability |
nvd |
CVE-2026-76131 |
|
2026-08-21 |
| high |
CVE-2026-73267 — A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant wi… |
vulnerability |
nvd |
CVE-2026-73267 |
|
2026-08-21 |
| medium |
CVE-2026-77392 — A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and… |
vulnerability |
nvd |
CVE-2026-77392 |
|
2026-08-21 |
| medium |
CVE-2026-77391 — A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS,… |
vulnerability |
nvd |
CVE-2026-77391 |
|
2026-08-21 |
| unknown |
CVE-2026-76157 — Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management… |
vulnerability |
nvd |
CVE-2026-76157 |
|
2026-08-21 |
| unknown |
CVE-2026-76156 — OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.… |
vulnerability |
nvd |
CVE-2026-76156 |
|
2026-08-21 |
| unknown |
CVE-2026-76155 — Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a rem… |
vulnerability |
nvd |
CVE-2026-76155 |
|
2026-08-21 |
| medium |
SynkLoader: when you throw in everything but the kitchen sink |
threat-intel |
otx |
d150c70d2732df17…, 138546bfa996b223… |
modular loader, fake lock screen, reverse proxy, microsoft teams phishing, synkloader, credential phishing, multi-language evasion, python loader, ransomware, phishing |
2026-08-21 |
| critical |
CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project… |
vulnerability |
nvd |
CVE-2026-77651 |
botnet |
2026-08-21 |
| critical |
CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a pr… |
vulnerability |
nvd |
CVE-2026-77650 |
botnet |
2026-08-21 |
| critical |
CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project… |
vulnerability |
nvd |
CVE-2026-77649 |
botnet |
2026-08-21 |
| low |
CVE-2026-43679 — This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An… |
vulnerability |
nvd |
CVE-2026-43679 |
|
2026-08-21 |
| unknown |
CVE-2026-20679 — The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Son… |
vulnerability |
nvd |
CVE-2026-20679 |
|
2026-08-21 |
| unknown |
CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability i… |
vulnerability |
nvd |
CVE-2026-16520 |
|
2026-08-21 |
| high |
SSB-104599 V1.3 (Last Update: 2026-08-21): Increasing Cyber Threats to Industrial Control Systems |
advisory |
vendor-blogs |
|
ics |
2026-08-21 |
| low |
CVE-2026-77648 — In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_f… |
vulnerability |
nvd |
CVE-2026-77648 |
|
2026-08-20 |
| critical |
CVE-2026-77647 — SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited i… |
vulnerability |
nvd |
CVE-2026-77647 |
|
2026-08-20 |
| unknown |
CVE-2026-77113 — Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allow… |
vulnerability |
nvd |
CVE-2026-77113 |
|
2026-08-20 |
| unknown |
CVE-2026-77646 — A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PT… |
vulnerability |
nvd |
CVE-2026-77646 |
|
2026-08-20 |
| critical |
CVE-2026-77645 — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC Flex… |
vulnerability |
nvd |
CVE-2026-77645 |
rce |
2026-08-20 |
| unknown |
CVE-2026-77644 — A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliabili… |
vulnerability |
nvd |
CVE-2026-77644 |
|
2026-08-20 |
| medium |
CVE-2026-77643 — A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core… |
vulnerability |
nvd |
CVE-2026-77643 |
|
2026-08-20 |
| high |
CVE-2026-77642 — tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signatur… |
vulnerability |
nvd |
CVE-2026-77642 |
|
2026-08-20 |
| high |
CVE-2026-72860 — The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues se… |
vulnerability |
nvd |
CVE-2026-72860 |
|
2026-08-20 |
| high |
CVE-2026-72848 — SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente… |
vulnerability |
nvd |
CVE-2026-72848 |
|
2026-08-20 |
| medium |
CVE-2026-72846 — Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendW… |
vulnerability |
nvd |
CVE-2026-72846 |
|
2026-08-20 |
| critical |
CVE-2026-72843 — The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/m… |
vulnerability |
nvd |
CVE-2026-72843 |
|
2026-08-20 |
| high |
CVE-2026-72818 — The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app… |
vulnerability |
nvd |
CVE-2026-72818 |
|
2026-08-20 |
| medium |
CVE-2026-70105 — Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose infor… |
vulnerability |
nvd |
CVE-2026-70105 |
|
2026-08-20 |
| high |
CVE-2026-69855 — Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di… |
vulnerability |
nvd |
CVE-2026-69855 |
|
2026-08-20 |
| critical |
CVE-2026-69851 — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat… |
vulnerability |
nvd |
CVE-2026-69851 |
|
2026-08-20 |
| critical |
CVE-2026-69836 — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c… |
vulnerability |
nvd |
CVE-2026-69836 |
|
2026-08-20 |
| high |
CVE-2026-69558 — Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized… |
vulnerability |
nvd |
CVE-2026-69558 |
|
2026-08-20 |
| critical |
CVE-2026-69555 — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne… |
vulnerability |
nvd |
CVE-2026-69555 |
|
2026-08-20 |
| high |
CVE-2026-69543 — Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat… |
vulnerability |
nvd |
CVE-2026-69543 |
|
2026-08-20 |
| high |
CVE-2026-69519 — Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor… |
vulnerability |
nvd |
CVE-2026-69519 |
|
2026-08-20 |
| high |
CVE-2026-69419 — Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe… |
vulnerability |
nvd |
CVE-2026-69419 |
|
2026-08-20 |
| critical |
CVE-2026-69400 — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a… |
vulnerability |
nvd |
CVE-2026-69400 |
|
2026-08-20 |
| critical |
CVE-2026-68782 — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… |
vulnerability |
nvd |
CVE-2026-68782, CVE-2026-68789 |
|
2026-08-20 |
| medium |
CVE-2026-67448 — Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/… |
vulnerability |
nvd |
CVE-2026-67448 |
|
2026-08-20 |
| medium |
CVE-2026-67447 — Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's interna… |
vulnerability |
nvd |
CVE-2026-67447 |
|
2026-08-20 |
| high |
CVE-2026-66800 — Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose… |
vulnerability |
nvd |
CVE-2026-66800 |
|
2026-08-20 |
| critical |
CVE-2026-66309 — Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov… |
vulnerability |
nvd |
CVE-2026-66309 |
|
2026-08-20 |
| critical |
CVE-2026-65816 — Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat… |
vulnerability |
nvd |
CVE-2026-65816 |
|
2026-08-20 |
| critical |
CVE-2026-65801 — Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e… |
vulnerability |
nvd |
CVE-2026-65801 |
|
2026-08-20 |