Security Advisories
150 advisoriesCVE-2026-56142
2026-08-22
Critical Privilege Escalation Vulnerability in JetBrains Hub (CVE-2026-56142)
A critical vulnerability in JetBrains Hub allows privilege escalation through authentication detail attachment. Affected versions include multiple prior releases. Immediate patching is recommended to prevent unauthorized access and data breaches.
Read full advisory →CVE-2026-54305
2026-08-22
Critical Vulnerability in n8n Allows Credential Enumeration and Overwrite via Dynamic Credentials (CVE-2026-54305)
A critical vulnerability in n8n (platform) allows authenticated users to enumerate credentials and overwrite tokens via Dynamic Credentials. Affected versions: < 1.123.55, 2.25.7, 2.26.2. CVSS 9.9. Patch urgently recommended.
Read full advisory →CVE-2026-55454
2026-08-22
Critical Vulnerability in Appsmith and Caddy Allows Remote Code Execution (CVE-2026-55454)
A critical vulnerability in Appsmith and Caddy allows an authenticated user to take over the Caddy configuration, leading to remote code execution. Affected versions are prior to Appsmith 2.1 and Caddy with default settings.
Read full advisory →CVE-2026-48584
2026-08-22
Critical Privilege Escalation Vulnerability in Azure Synapse (CVE-2026-48584)
A critical vulnerability in Azure Synapse allows attackers to escalate privileges over a network. This affects all versions of the platform and requires authorization to exploit. Immediate mitigation is strongly advised.
Read full advisory →CVE-2026-54158
2026-08-22
Critical Vulnerability in SiYuan Allows Remote Code Execution via XSS (CVE-2026-54158)
A critical vulnerability in SiYuan versions prior to 3.7.0 allows remote code execution through a cross-site scripting flaw in the attribute-view cell renderer. Attackers can exploit this to execute arbitrary JavaScript and gain system-level access on Electron-based desktop installations.
Read full advisory →CVE-2026-50748
2026-08-22
Critical Vulnerability in UniFi Access Application Allows Command Injection (CVE-2026-50748)
A critical vulnerability in the UniFi Access Application (CVE-2026-50748) allows command injection via improper input validation. Attackers with network access can exploit this to execute arbitrary commands on the host, posing a severe risk to system integrity.
Read full advisory →CVE-2026-54402
2026-08-22
Critical Command Injection Vulnerability in UniFi OS (CVE-2026-54402)
A critical command injection vulnerability (CVE-2026-54402) allows low-privilege attackers to execute arbitrary commands on affected UniFi devices, impacting multiple appliance models and requiring immediate mitigation.
Read full advisory →CVE-2026-44791
2026-08-22
Critical RCE Vulnerability in n8n Workflow Automation Platform (CVE-2026-44791)
A critical remote code execution vulnerability exists in n8n versions prior to 1.123.43, 2.22.1, and 2.20.7. Authenticated users could exploit this to execute arbitrary code on the host through the XML node.
Read full advisory →CVE-2026-50551
2026-08-22
Critical RCE Vulnerability in SiYuan (CVE-2026-50551)
SiYuan versions prior to 3.7.0 contain a critical stored XSS vulnerability leading to RCE. Attackers can exploit this to execute arbitrary code on affected systems. Users are advised to upgrade immediately.
Read full advisory →CVE-2026-54067
2026-08-22
Critical XSS to RCE Vulnerability in SiYuan (CVE-2026-54067)
A critical vulnerability in SiYuan allows arbitrary code execution via malicious CSS snippets. Attackers can exploit this to gain remote control of affected systems. Patch to version 3.7.0 or later immediately.
Read full advisory →CVE-2026-46386
2026-08-22
Critical Vulnerability in OpenProject Allows Remote Code Execution (CVE-2026-46386)
A critical vulnerability in OpenProject (CVE-2026-46386) allows remote code execution via a default Rails master key and Marshal deserialization. Affected versions require immediate patching to prevent exploitation.
Read full advisory →CVE-2026-50195
2026-08-22
Critical Vulnerability in containerd Allows Image Cache Poisoning (CVE-2026-50195)
A critical vulnerability in containerd (CVE-2026-50195) allows attackers to poison local image caches by exploiting improper validation during checkpoint import, enabling malicious image pulls with arbitrary tags.
Read full advisory →Get These Delivered to Your Inbox
Subscribe to receive advisories as soon as they are published — filtered to your environment.