CVE Daily Brief
Date: 2026-08-06
Summary
- Total qualifying CVEs: 132
- Critical: 67
- High: 65
- With GitHub PoC references: 24
- In CISA KEV: 0
Critical
All Critical CVE details are preserved across this issue and managed follow-up comments.
High Index
- 🟠 CVE-2026-15572 | CVSS
8.8 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, wh…
- 🟠 CVE-2026-17623 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation…
- 🟠 CVE-2026-17626 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Do…
- 🟠 CVE-2026-17630 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration p…
- 🟠 CVE-2026-20200 | CVSS
8.8 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to exe…
- 🟠 CVE-2026-20312 | CVSS
8.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a…
- 🟠 CVE-2026-17625 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 throug…
- 🟠 CVE-2026-70431 | CVSS
8.8 | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugi…
- 🟠 CVE-2026-70432 | CVSS
8.8 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute ar…
- 🟠 CVE-2026-17624 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 throug…
- 🟠 CVE-2026-17632 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of P…
- 🟠 CVE-2026-17633 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.
- 🟠 CVE-2026-8182 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any creden…
- 🟠 CVE-2026-8478 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of…
- 🟠 CVE-2026-9196 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation…
- 🟠 CVE-2026-9201 | CVSS
8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in th…
- 🟠 CVE-2026-17556 | CVSS
8.8 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary file… | PoC 5
- 🟠 CVE-2026-15991 | CVSS
8.8 | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector fu…
- 🟠 CVE-2026-28111 | CVSS
8.8 | Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
- 🟠 CVE-2026-65542 | CVSS
8.8 | Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
- 🟠 CVE-2026-69111 | CVSS
8.7 | Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate servi… | PoC 3
- 🟠 CVE-2026-66733 | CVSS
8.7 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that all… | PoC 1
- 🟠 CVE-2026-20263 | CVSS
8.6 | A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote a…
- 🟠 CVE-2026-20268 | CVSS
8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…
- 🟠 CVE-2026-20269 | CVSS
8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…
- 🟠 CVE-2026-20270 | CVSS
8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…
- 🟠 CVE-2026-20271 | CVSS
8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…
- 🟠 CVE-2026-20273 | CVSS
8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…
- 🟠 CVE-2026-20301 | CVSS
8.6 | A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software…
- 🟠 CVE-2026-66298 | CVSS
8.6 | Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard… | PoC 4
- 🟠 CVE-2026-70617 | CVSS
8.6 | Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselv… | PoC 2
- 🟠 CVE-2026-71309 | CVSS
8.6 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rcl… | PoC 3
- 🟠 CVE-2026-9203 | CVSS
8.5 | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-pri…
- 🟠 CVE-2026-17617 | CVSS
8.5 | IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of U…
- 🟠 CVE-2026-9077 | CVSS
8.5 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitr…
- 🟠 CVE-2026-18485 | CVSS
8.5 | There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated…
- 🟠 CVE-2026-70615 | CVSS
8.5 | boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation p… | PoC 1
- 🟠 CVE-2026-18597 | CVSS
8.5 | The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attack…
- 🟠 CVE-2026-65547 | CVSS
8.5 | Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
- 🟠 CVE-2026-65569 | CVSS
8.5 | Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
- 🟠 CVE-2026-55978 | CVSS
8.4 | An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel…
- 🟠 CVE-2026-17583 | CVSS
8.3 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker co…
- 🟠 CVE-2026-34966 | CVSS
8.3 | Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections b… | PoC 3
- 🟠 CVE-2026-66732 | CVSS
8.3 | Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established conn… | PoC 1
- 🟠 CVE-2026-16731 | CVSS
8.3 | OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism…
- 🟠 CVE-2026-10025 | CVSS
8.2 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability.…
- 🟠 CVE-2026-71315 | CVSS
8.2 | Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to ma… | PoC 5
- 🟠 CVE-2026-19024 | CVSS
8.2 | NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose versio… | PoC 1
- 🟠 CVE-2026-14829 | CVSS
8.2 | The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict acc…
- 🟠 CVE-2026-16268 | CVSS
8.2 | The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied…
- 🟠 CVE-2026-66708 | CVSS
8.2 | Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
- 🟠 CVE-2026-70637 | CVSS
8.2 | LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by… | PoC 1
- 🟠 CVE-2026-7327 | CVSS
8.1 | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and…
- 🟠 CVE-2026-8400 | CVSS
8.1 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB comp…
- 🟠 CVE-2026-70429 | CVSS
8.1 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attack…
- 🟠 CVE-2026-10547 | CVSS
8.1 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint…
- 🟠 CVE-2025-63822 | CVSS
8.1 | SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier pa… | PoC 1
- 🟠 CVE-2026-71320 | CVSS
8.1 | Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key thro… | PoC 5
- 🟠 CVE-2026-15459 | CVSS
8.1 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites no…
- 🟠 CVE-2026-57817 | CVSS
8.1 | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the c_hash parameter when operating in the Hybrid Flow. If a…
- 🟠 CVE-2026-57818 | CVSS
8.1 | A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests,…
- 🟠 CVE-2026-16315 | CVSS
8.1 | OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism…
- 🟠 CVE-2026-65570 | CVSS
8.1 | Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.
- 🟠 CVE-2026-66710 | CVSS
8.1 | Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
- 🟠 CVE-2026-71312 | CVSS
8.0 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone inte… | PoC 3
Notes
- PoC links are collected from NVD references and GitHub repository search. They are untrusted and may include unsafe code.
- Critical CVE details may span multiple managed comments to guarantee completeness without exceeding GitHub issue size limits.
CVE Daily Brief
Date:
2026-08-06Summary
Critical
All Critical CVE details are preserved across this issue and managed follow-up comments.
High Index
8.8| A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, wh…8.8| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation…8.8| IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Do…8.8| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration p…8.8| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to exe…8.8| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a…8.8| IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 throug…8.8| Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugi…8.8| A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute ar…8.8| IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 throug…8.8| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of P…8.8| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.8.8| IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any creden…8.8| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of…8.8| IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation…8.8| IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in th…8.8| A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary file… | PoC58.8| The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector fu…8.8| Contributor Privilege Escalation in Forminator <= 1.56.0 versions.8.8| Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.8.7| Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate servi… | PoC38.7| Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that all… | PoC18.6| A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote a…8.6| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…8.6| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…8.6| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…8.6| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…8.6| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…8.6| A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software…8.6| Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard… | PoC48.6| Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselv… | PoC28.6| rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rcl… | PoC38.5| A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-pri…8.5| IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of U…8.5| IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitr…8.5| There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated…8.5| boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation p… | PoC18.5| The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attack…8.5| Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.8.5| Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.8.4| An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel…8.3| The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker co…8.3| Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections b… | PoC38.3| Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established conn… | PoC18.3| OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism…8.2| IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability.…8.2| Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to ma… | PoC58.2| NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose versio… | PoC18.2| The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict acc…8.2| The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied…8.2| Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.8.2| LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by… | PoC18.1| An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and…8.1| IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB comp…8.1| Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attack…8.1| IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint…8.1| SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier pa… | PoC18.1| Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key thro… | PoC58.1| The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites no…8.1| The OpenID Connect Core 1.0 specification mandates that the RP MUST validate thec_hashparameter when operating in the Hybrid Flow. If a…8.1| A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests,…8.1| OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism…8.1| Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.8.1| Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.8.0| rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone inte… | PoC3Notes