Security Advisories
150 advisoriesCVE-2026-16812
2026-08-14
Critical Remote Code Execution Vulnerability in VeloCloud Orchestrator (CVE-2026-16812)
A critical vulnerability in VeloCloud Orchestrator allows remote attackers to access privileged internal functionality, risking data confidentiality, integrity, and availability. Immediate patching is required for on-premises deployments.
Read full advisory →CVE-2026-66012
2026-08-14
Critical Authorization Bypass in SiYuan Exposing Sensitive MCP Tools (CVE-2026-66012)
SiYuan versions prior to v3.7.2 contain a critical authorization vulnerability in the /mcp endpoint, allowing unauthenticated attackers to execute file operations across the workspace. CVSS score of 10.0. Immediate upgrade recommended.
Read full advisory →CVE-2026-56163
2026-08-14
Critical Privilege Escalation Vulnerability in Microsoft Azure Kubernetes Service (CVE-2026-56163)
A critical vulnerability in Microsoft Azure Kubernetes Service allows unauthorized attackers to escalate privileges due to missing authentication for critical functions. With a CVSS score of 10.0, this affects Azure Kubernetes Service and Microsoft Azure platforms. Immediate patching is required to mitigate exploitation risks.
Read full advisory →CVE-2026-57106
2026-08-14
Critical SSRF Vulnerability in Data Quality Software Allows Privilege Escalation (CVE-2026-57106)
A critical server-side request forgery (SSRF) vulnerability in Data Quality software enables unauthorized attackers to escalate privileges over a network. Immediate patching is required for all affected systems.
Read full advisory →CVE-2026-58630
2026-08-14
Critical Privilege Escalation Vulnerability in Azure App Service (CVE-2026-58630)
A critical vulnerability in Azure App Service allows unauthorized attackers to escalate privileges over a network due to improper access controls. Assigned a CVSS score of 10.0, this issue affects all Azure App Service platforms. Immediate remediation is strongly recommended.
Read full advisory →CVE-2026-56191
2026-08-14
Critical Authentication Vulnerability in Microsoft Exchange Online (CVE-2026-56191)
A critical authentication flaw in Microsoft Exchange Online enables remote attackers to tamper with data. Immediate patching is required to mitigate exploitation risks.
Read full advisory →CVE-2026-58275
2026-08-14
Critical Privilege Escalation Vulnerability in Azure DNS - CVE-2026-58275
A critical vulnerability in Azure DNS allows unauthorized attackers to escalate privileges over a network due to missing authorization checks. This affects Azure DNS and Microsoft Azure platforms. Immediate remediation is required to mitigate potential exploitation.
Read full advisory →CVE-2026-62825
2026-08-14
Critical Privilege Escalation Vulnerability in Azure Key Vault - CVE-2026-62825
Azure Key Vault contains a critical authentication flaw enabling unauthorized privilege escalation. With a CVSS score of 10.0, this vulnerability affects all Azure Key Vault users, requiring immediate mitigation to prevent unauthorized access and data compromise.
Read full advisory →CVE-2026-42933
2026-08-14
Pronetiqs IntraVUE Proxy Bypass Vulnerability (CVE-2026-42933)
Critical vulnerability in Pronetiqs IntraVUE allows proxy bypass, enabling attackers to circumvent operational technology (OT) network segmentation. Unpatched systems running versions 3.2.1a14 or earlier are at risk of unauthorized access and lateral movement.
Read full advisory →CVE-2025-71389
2026-08-13
Critical Remote Code Execution Vulnerability in Cal.com and Next.js Platforms (CVE-2025-71389)
A critical remote code execution vulnerability (CVE-2025-71389) affects Cal.com, Cal.diy, and Next.js platforms. Unauthenticated attackers can exploit this flaw to execute arbitrary code via crafted RSC requests. Immediate patching to version 5.9.9 or later is required to mitigate the risk.
Read full advisory →CVE-2026-47668
2026-08-13
Critical RCE Vulnerability in DbGate JSON Script Runner (CVE-2026-47668)
DbGate versions 7.1.8 and earlier contain a remote code execution vulnerability in the JSON script runner. Attackers can exploit this flaw via malicious `functionName` parameters in `assign` commands. Upgrade to 7.1.9 to mitigate.
Read full advisory →CVE-2026-6516
2026-08-13
Critical RCE Vulnerability in ManageEngine ADAudit Plus (CVE-2026-6516)
ManageEngine ADAudit Plus versions before 8606 contain an unauthenticated remote code execution vulnerability in the agent API. Attackers can exploit this to execute arbitrary code. Immediate patching is required to mitigate critical risks.
Read full advisory →Get These Delivered to Your Inbox
Subscribe to receive advisories as soon as they are published — filtered to your environment.