CRITICAL CVSS 9.9 CVE-2026-52782 2026-08-22

CVE-2026-52782: Critical IDOR Vulnerability in OpenProject Allows Resource Hijacking

A critical IDOR vulnerability in OpenProject (CVE-2026-52782) allows project-admins to hijack storage folders of other projects. CVSS 9.9. Affected versions: prior to 17.3.3 and 17.4.1. Patching is strongly recommended.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-50747 2026-08-22

Critical SQL Injection Vulnerability in UniFi Talk Application (CVE-2026-50747)

A critical SQL injection vulnerability in UniFi Talk Application allows privilege escalation. Affected systems include the appliance version. CVSS 9.9. Immediate mitigation required.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-61445 2026-08-22

Critical Vulnerability in PraisonAI AICoder Component (CVE-2026-61445)

CVE-2026-61445 is a critical vulnerability in PraisonAI versions before 4.6.78, allowing arbitrary file write and command execution via the AICoder component due to insufficient input validation.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-27419 2026-08-21

Critical Vulnerability in Zegen Platform Allows Arbitrary File Upload (CVE-2026-27419)

A critical vulnerability in Zegen platform versions <=1.1.9 allows attackers to upload arbitrary files via subscriber endpoints. This poses a high risk of remote code execution and data compromise. Immediate mitigation is required.

Read full advisory →
CRITICAL CVSS 9.9 CVE-2026-44935 2026-08-21

Critical Vulnerability in Rancher Fleet Allows Tenant Credential Access (CVE-2026-44935)

A critical vulnerability in Rancher Fleet allows tenant credential access via improper validation of 'valuesFrom' references. Affected versions include 0.15 before 0.15.2, 0.14 before 0.14.6, and earlier versions. Immediate patching is required.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-20030 2026-08-21

Critical SQL Injection Vulnerability in Cisco Crosswork (CVE-2026-20030)

A critical SQL injection vulnerability (CVE-2026-20030) affects Cisco Crosswork, allowing unauthorized data access. CVSS 10.0. Immediate patching required to prevent exploitation.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-69555 2026-08-21

Critical Privilege Escalation Vulnerability in Azure Arc (CVE-2026-69555)

A critical vulnerability in Azure Arc allows unauthorized privilege escalation. CVSS 10.0. Affected users should apply patches immediately to prevent exploitation.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-69836 2026-08-21

Critical Remote Code Execution Vulnerability in Microsoft Entra ID (CVE-2026-69836)

A critical remote code execution vulnerability (CVE-2026-69836) exists in Microsoft Entra ID, allowing unauthorized attackers to execute arbitrary code over a network due to improper deserialization of untrusted data.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-65816 2026-08-21

Critical Privilege Escalation Vulnerability in Azure Arc (CVE-2026-65816)

A critical vulnerability in Azure Arc (CVE-2026-65816) allows unauthorized attackers to escalate privileges over a network. This affects Azure Arc platform users and requires immediate mitigation.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-20357 2026-08-21

Critical Vulnerability in Cisco Crosswork (CVE-2026-20357)

A critical vulnerability (CVE-2026-20357) with a CVSS score of 10.0 affects Cisco Crosswork. It involves missing authentication for critical functions, allowing unauthorized access and posing a severe risk to affected systems.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-65770 2026-08-21

Critical Remote Code Execution Vulnerability in Azure Managed Instance for Apache Cassandra (CVE-2026-65770)

A critical remote code execution vulnerability (CVE-2026-65770) allows unauthorized attackers to execute arbitrary code over a network due to improper argument delimiter neutralization in Azure Managed Instance for Apache Cassandra.

Read full advisory →
CRITICAL CVSS 10.0 CVE-2026-65801 2026-08-21

Critical SSRF Vulnerability in Microsoft Exchange Online (CVE-2026-65801)

A critical server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online allows unauthorized attackers to elevate privileges over a network. This affects all versions of the platform and requires immediate mitigation.

Read full advisory →
← Newer Page 6 of 13 Older →