Latest Security Vulnerabilities
Friday August 21, 2026
Misp
CVE-2026-77761 MISP STIX Parser State Isolation Causing Integrity LeakCVE-2026-77710 MISP STIX Import: Spoofed Document Alters Attribute Metadata
CVE-2026-77755 DoS via SysExit & Large Documents in MISP-STIX Importer
CVE-2026-77751 Path Traversal in PyMISP Template Resolution via Untrusted STIX Names
Unclassified
CVE-2026-74866 CRLF Injection in @fastify/busboy 3.2.1, fixed in 3.2.2CVE-2026-16575 Unauth Disclosure in Dokan 5.0.14 via unauth REST endpoint
CVE-2026-19435 Duplicate Post WP Plugin <1.5.6: PrivEsc & Info Disclosure
CVE-2026-77264 Auth Bypass in WP OTP Plugin v4.8.6: Magic Token Leakage
CVE-2026-47827 Command Injection in Cloud Foundry BOSH CLI <2.840.0 on Windows
CVE-2026-19848 ProfilePress WP Plugin before 4.17.1 Shortcode XSS Exposes Email
CVE-2026-15150 myCred WP Plugin <3.2.5: Unauthenticated Payment Notification Bypass
CVE-2026-16577 Dokan WP Plugin 5.0.13 Reverse-Withdrawal Amount Validation Flaw
CVE-2026-16576 Dokan WP Plugin <5.0.14 Privilege Escalation via Admin REST API
And others...
Apache CloudStack
CVE-2026-66722 Apache CloudStack: Improper Auth for Project Role CRUD (4.15-4.20.3.0/4.21-4.22.1.0)CVE-2026-47359 Apache CloudStack OS Command Injection (NAS Backup Provider v4.20-4.22.1)
CVE-2026-61422 SSRF Pre-Validation in CloudStack 4.20.3.0-4.22.1.0 (template/ISO)
CVE-2026-61400 Command Injection in CloudStack 4.20.x4.22.x runDiagnostics
CVE-2026-61397 Apache CloudStack OAuth2 Plugin Info Leak before 4.20.3.1/4.22.1.1
CVE-2026-59657 Cleartext Storage via AsyncJob DB in Apache CloudStack 4.0.0-4.22.1.0
CVE-2026-50112 Apache CloudStack SSRF & KVM RCE via Metalink URLs 4.144.22
CVE-2026-65613 Apache CloudStack: webhook info leak 4.20-4.22 before 4.20.3.1/4.22.1.1
CVE-2026-66721 CloudStack HostTags API Missing Auth (4.124.20.3.0, 4.214.22.1.0)
And others...
Thursday August 20, 2026
Google Chrome
CVE-2026-76019 High-Severity Auth Bypass in Chrome Workers (151.0.7922.173)CVE-2026-76020 Race condition in V8 in Chrome <151.0.7922.173: RCE in sandbox
CVE-2026-76017 Chrome <151.0.7922.173 Chromoting UAF RCE
CVE-2026-76022 Chrome<151.0.7922.173 Buffer Overflow: RCE outside Sandbox
CVE-2026-76023 Google Chrome <151: Improper resource control in Linux Toolkit Theming
CVE-2026-76018 Chrome Import Priv Elevation <151.0.7922.173
CVE-2026-76021 Google Chrome < 151.0.7922.173 UAF in DOM leads to sandbox escape
IBM Aix
CVE-2026-16936 IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 buffer overflow local code execCVE-2026-16980 IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: Local DoS from Improper Symlink Validation
CVE-2026-18828 IBM AIX 7.2-7.3 / PowerVM VIOS 4.1 DoS via stack overflow
CVE-2026-17121 IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Recursion DoS
CVE-2026-17120 IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote DoS via Buffer Overflow
CVE-2026-17157 IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 stack buffer overflow RCE
CVE-2026-17159 IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Integer Overflow DoS
CVE-2026-17060 IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Kernel Heap Over-Read Remote Info Leak & DoS
CVE-2026-17003 IBM AIX 7.2-7.3 & PowerVM VIOS 4.1 OOB Write Remote RCE
And others...
Canonical Ubuntu Linux
CVE-2026-61897 Local PrivEsc via Ubuntu AccountsService 23.13.9-8ubuntu7CVE-2026-53586 CVE-2026-53586 libgit2 credentials leak via HTTP redirect (before 1.8.6/1.9.5)
CVE-2026-53584 libgit2 submodule path traversal before 1.8.6/1.9.5
CVE-2026-61898 accountsservice LPE via sed injection in PAM language script v<23.13.9
CVE-2026-53587 libgit2 Heap OOB Walk: smart_pkt.c <1.8.6/1.9.5
CVE-2026-53585 Memory Exhaustion in libgit2 <1.8.6/1.9.5 via Malicious delta
Unclassified
CVE-2026-74866 CRLF Injection in @fastify/busboy 3.2.1, fixed in 3.2.2CVE-2026-16575 Unauth Disclosure in Dokan 5.0.14 via unauth REST endpoint
CVE-2026-19435 Duplicate Post WP Plugin <1.5.6: PrivEsc & Info Disclosure
CVE-2026-77264 Auth Bypass in WP OTP Plugin v4.8.6: Magic Token Leakage
CVE-2026-47827 Command Injection in Cloud Foundry BOSH CLI <2.840.0 on Windows
CVE-2026-19848 ProfilePress WP Plugin before 4.17.1 Shortcode XSS Exposes Email
CVE-2026-15150 myCred WP Plugin <3.2.5: Unauthenticated Payment Notification Bypass
CVE-2026-16577 Dokan WP Plugin 5.0.13 Reverse-Withdrawal Amount Validation Flaw
CVE-2026-16576 Dokan WP Plugin <5.0.14 Privilege Escalation via Admin REST API
And others...
Torproject Tor
CVE-2026-77641 Tor <0.4.9.9 NULL Write After Free in relay_send_command_from_edgeCVE-2026-77587 Tor Use-After-Free in conflux component before 0.4.9.11
CVE-2026-77639 Tor pre-0.4.9.9 Compression Bomb Bypass via gzip/zlib Concatenation
CVE-2026-77642 Tor OOB Write in Consensus parsing before 0.4.9.9
Tp Link
CVE-2026-9033 TP-Link Captive Portal Session Termination (CVE-2026-9033)CVE-2026-19683 Unencrypted DDNS Credential Transmission in TP-Link Omada Gateway
CVE-2026-19586 TP-Link Omada Gateway OpenVPN Server Command Injection
Gimp
CVE-2026-18308 GIMP TIF Integer Overflow RCE in File ParserCVE-2026-18303 GIMP TIF Parsing Stack-Buffer Overflow RCE
CVE-2026-18301 GIMP PSD Parser Integer Overflow RCE
CVE-2026-18300 GIMP HDR Parsing Integer Overflow RCE
Red Hat Acm
CVE-2026-66788 Lighthouse Namespace Injection for Unauthorized EndpointSlice/ServiceImportCVE-2026-73137 RHACM multicloud-operators-subscription: privilege escalation allows exfil
CVE-2026-66787 RedHat AMK Lighthouse IP validation flaw enabling MITM
CVE-2026-66785 Red Hat Submariner Unauthorized Network Traffic Redirection Vulnerability
Apple
CVE-2026-64773 Apple Container Unbounded Forwarding Memory Leak Before 1.2.0CVE-2026-64777 Apple Container Builder <1.2.0: In-Context File Disclosure

