{"date_iso":"2026-08-14","date_human":"Friday, August 14, 2026","generated_utc":"2026-08-14 14:18 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Download More RAM Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing","link":"https://cybersecuritynews.com/download-more-ram-attack/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cisco Talos","Cyber Security News","Dark Reading","Infosecurity Magazine","Krebs On Security","Malwarebytes Labs","Rapid7 Blog","SANS Internet Storm Center","Tenable Blog","The Hacker News","The Register Security"],"coverage":13,"cve_ids":["CVE-2026-62878","CVE-2026-63520","CVE-2026-68820"],"summary":"A new attack dubbed \u201cDownload More RAM\u201d can bypass Windows Virtualization-Based Security (VBS), weaken Hypervisor-Enforced Code Integrity (HVCI), and disable Microsoft Defender. Microsoft tracked the issue as\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Download-More-RAM-Attack-Bypasses-Windows-VBS-and-Disables-Defender-Through-Memory-Aliasing.webp","description":"A new attack dubbed \u201cDownload More RAM\u201d can bypass Windows Virtualization-Based Security (VBS), weaken Hypervisor-Enforced Code Integrity (HVCI), and disable Microsoft Defender. Microsoft tracked the issue as CVE-2026-23670 and released mitigations in its April 2026 security update. The attack abuses improperly protected Serial Presence Detect (SPD) data on certain consumer DDR4 and DDR5 memory modules. SPD is configuration data stored on a RAM module that specifies the system\u2019s capacity, speed, and operating parameters. If the SPD chip is writable, an attacker with local administrator\u2026","related":[{"title":"Microsoft patches LegacyHive Windows zero-day vulnerability","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/","source":"Bleeping Computer","date_rel":"18h ago"},{"title":"The backup Microsoft never promised you","link":"https://www.theregister.com/security/2026/08/13/sponsored-the-backup-microsoft-never-promised-you/5284957","source":"The Register Security","date_rel":"21h ago"},{"title":"Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor","link":"https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html","source":"The Hacker News","date_rel":"12 Aug"},{"title":"Patch Tuesday: Update now to fix 421 flaws, including three zero-days","link":"https://www.malwarebytes.com/blog/bugs/2026/08/patch-tuesday-update-now-to-fix-421-flaws-including-three-zero-days","source":"Malwarebytes Labs","date_rel":"12 Aug"},{"title":"Microsoft Fixes 400 Flaws on August Patch Tuesday","link":"https://www.infosecurity-magazine.com/news/microsoft-fixes-400-flaws-august/","source":"Infosecurity Magazine","date_rel":"12 Aug"},{"title":"ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access","link":"https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html","source":"The Hacker News","date_rel":"12 Aug"}]},{"title":"Passwords stored in public Google Doc then showed up in search results","link":"https://www.theregister.com/security/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results/5287028","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Hacker News","The Register Security"],"coverage":6,"cve_ids":[],"summary":"PWNED Welcome, once again, to PWNED, the weekly column where we highlight others\u2019 security failures. Hopefully, there\u2019s a lesson in all this, but it could just be \u201cstop shooting yourself in the foot.\u201d Have a story about\u2026","source":"The Register Security","date_rel":"13 Aug","thumbnail":"https://image.theregister.com/?imageId=5287048&width=800","description":"PWNED Welcome, once again, to PWNED, the weekly column where we highlight others\u2019 security failures. Hopefully, there\u2019s a lesson in all this, but it could just be \u201cstop shooting yourself in the foot.\u201d Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story today comes courtesy of Siim Kostabi, co-founder of Pageloot, a company that provides QR codes businesses can use for marketing. Kostabi\u2019s tale of tech terror reminds us that credentials, even for a staging server, have a lot of value in the\u2026","related":[{"title":"Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal","link":"https://www.securityweek.com/google-cloud-sets-out-post-quantum-roadmap-with-2029-readiness-goal/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone","link":"https://www.infosecurity-magazine.com/news/google-cloud-post-quantum-roadmap/","source":"Infosecurity Magazine","date_rel":"21h ago"},{"title":"Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits","link":"https://www.malwarebytes.com/blog/privacy/2026/08/parents-take-on-meta-tiktok-google-and-snap-in-3000-youth-safety-lawsuits","source":"Malwarebytes Labs","date_rel":"13 Aug"},{"title":"Google security advisory (AV26-806)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-806","source":"CCCS Alerts & Advisories","date_rel":"12 Aug"},{"title":"OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning","link":"https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html","source":"The Hacker News","date_rel":"12 Aug"}]},{"title":"Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals","link":"https://cybersecuritynews.com/malware-crypter-services/","reason":"Windows","category":"News","sources":["Cyber Security News","Fortinet PSIRT","Kaspersky Securelist","Microsoft Security"],"coverage":4,"cve_ids":["CVE-2026-49798","CVE-2026-50298","CVE-2026-50342"],"summary":"Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle to recognize it. Their operators promise customers a way around\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Malware-Crypter-Services-Sell-Windows-Defender-EDR-and-SmartScreen-Bypasses-to-Cybercriminals.webp","description":"Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle to recognize it. Their operators promise customers a way around Windows Defender, endpoint detection and response tools, and Microsoft SmartScreen. The change helps attackers move familiar malware past controls that would otherwise flag it early. The danger is not a single new malware family. It is a commercial layer that helps many kinds of malware reach victims with less scrutiny. Criminals can package remote access tools, stealers, or\u2026","related":[{"title":"APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit","link":"https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/","source":"Kaspersky Securelist","date_rel":"3h ago"},{"title":"Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2","link":"https://cybersecuritynews.com/aeternum-botnet-uses-polygon/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49798","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-50342 Windows MIDI Service Module Elevation of Privileges Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50342","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50298","source":"Microsoft Security","date_rel":"22h ago"},{"title":"Heap overflow in kernel driver due to missing size validation","link":"https://fortiguard.fortinet.com/psirt/FG-IR-26-156","source":"Fortinet PSIRT","date_rel":"12 Aug"}]},{"title":"HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel","link":"https://cybersecuritynews.com/hackerai-malware/","reason":"Github","category":"News","sources":["Bleeping Computer","Cyber Security News","Wiz Research"],"coverage":3,"cve_ids":[],"summary":"A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data. The technique lets operators blend malicious traffic with a service that\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/HACKERAI-Malware-Turns-GitHub-Gists-Into-a-Command-and-Control-Channel.webp","description":"A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data. The technique lets operators blend malicious traffic with a service that many organizations allow on their networks. The malware appeared during an investigation into a wider espionage campaign aimed at telecom, government, defense, energy, and critical infrastructure organizations in South Asia. Victims were lured with files that impersonated trusted telecom services, government updates, and software installers. Researchers at Acronis identified\u2026","related":[{"title":"AI 'watermark removers' flood the web. Almost none can prove they work","link":"https://www.bleepingcomputer.com/news/security/ai-watermark-removers-flood-the-web-almost-none-can-prove-they-work/","source":"Bleeping Computer","date_rel":"19h ago"},{"title":"How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign","link":"https://www.wiz.io/blog/investigating-github-pat-compromise","source":"Wiz Research","date_rel":"21h ago"}]},{"title":"AWS key exposed in JavaScript may have lit way to Beacon's charity data","link":"https://www.theregister.com/security/2026/08/13/aws-key-exposed-in-javascript-may-have-lit-way-to-beacons-charity-data/5287303","reason":"Aws","category":"News","sources":["Infosecurity Magazine","SecurityWeek","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Beacon, a CRM provider for charities and nonprofits, says an AWS access key \"potentially exposed in public JavaScript build artifacts\" is the leading suspect in its July breach. The revelation came in the company's\u2026","source":"The Register Security","date_rel":"13 Aug","thumbnail":"https://image.theregister.com/?imageId=1681829&width=800","description":"Beacon, a CRM provider for charities and nonprofits, says an AWS access key \"potentially exposed in public JavaScript build artifacts\" is the leading suspect in its July breach. The revelation came in the company's first update on the attack in more than a week. If the access key was exposed in public build artifacts, it raises questions about why Beacon's development pipeline and code review controls failed to catch it. Beacon used stronger wording about the potential data loss, confirming that a copy of the database was made and assessing that it was probably downloaded in readable form\u2026","related":[{"title":"Over 1,000 Charities Hit by Beacon CRM Data Breach","link":"https://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities","link":"https://www.infosecurity-magazine.com/news/exposed-aws-key-data-charities/","source":"Infosecurity Magazine","date_rel":"21h ago"}]},{"title":"Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA","link":"https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa","reason":"Fortinet","category":"News","sources":["CCCS Alerts & Advisories","CISA Alerts & Advisories","CISA ICS Advisories","Dark Reading","Infosecurity Magazine"],"coverage":5,"cve_ids":[],"summary":"The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.","source":"Dark Reading","date_rel":"11 Aug","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt468a31de0930ebef/6a7b87a0f0b097cbb1a7bb39/ransomware-jittawit.21-Getty-2178699306.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Fortinet security advisory (AV26-812)","link":"https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-812","source":"CCCS Alerts & Advisories","date_rel":"12 Aug"},{"title":"Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure","link":"https://www.infosecurity-magazine.com/news/gunra-ransomware-fortinet-flaws/","source":"Infosecurity Magazine","date_rel":"12 Aug"},{"title":"Siemens RUGGEDCOM APE1808","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-06","source":"CISA Alerts & Advisories","date_rel":"12 Aug"},{"title":"Siemens RUGGEDCOM APE1808","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-06","source":"CISA ICS Advisories","date_rel":"12 Aug"}]},{"title":"In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities","link":"https://www.securityweek.com/in-other-news-rapid7-layoffs-hacking-a-boeing-737-refrigeration-system-vulnerabilities/","reason":"Rapid7","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption.","source":"SecurityWeek","date_rel":"44m ago","thumbnail":"","description":"","related":[{"title":"Rapid7 security advisory (AV26-801)","link":"https://cyber.gc.ca/en/alerts-advisories/rapid7-security-advisory-av26-801","source":"CCCS Alerts & Advisories","date_rel":"11 Aug"}]},{"title":"Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws","link":"https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-71362"],"summary":"Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and\u2026","source":"The Hacker News","date_rel":"12 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj36vXq6xqWIDA09DIFwTp0gAZyTEpTdUoOrczmHr0NAOmxBDBySv4K6oEmzSup0sZylULeZlzf2unPADh99H5kx8-oktejFUPTM2t5aM6WrdTy99m6Qs12z4A58UYbqU2LhZRa20yY9FGy8FFB-pMvUFsA3MolrrA4nYOWVf9IS42Y0vUn3sMtu0BCty3g/s1600/adobe-cve.jpg","description":"Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could","related":[{"title":"Adobe Commerce Bug Targeted Immediately After Disclosure","link":"https://www.securityweek.com/adobe-commerce-bug-targeted-immediately-after-disclosure/","source":"SecurityWeek","date_rel":"22h ago"},{"title":"Adobe security advisory (AV26-808)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-808","source":"CCCS Alerts & Advisories","date_rel":"12 Aug"}]},{"title":"Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS","link":"https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html","reason":"Asa","category":"News","sources":["CCCS Alerts & Advisories","Cisco Security Advisories","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-20349"],"summary":"Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw\u2026","source":"The Hacker News","date_rel":"12 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRIn51DQNDe2IfVEJzqiWXY9k8QyRhulSTcOh67As0Pj7Da1DCB5Lu1RBhjI55Y7_TF9PW9F9HOBn6moaPRNrpl0G_OGeMbC9z5BMfdOqtF6sHpd5tJLvQqnvlCd77R-4oCYiDVfFlUtRe4mp7W8cFDCHmJ8kz4TueVL06-jbGzpVdWasZF02YRwYyrZJc/s1600/cisco-powerhouse.jpg","description":"Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger","related":[{"title":"AL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349","link":"https://cyber.gc.ca/en/alerts-advisories/al26-018-vulnerability-affecting-cisco-asa-secure-firewall-threat-defense-software-remote-access-ssl-vpn-cve-2026-20349","source":"CCCS Alerts & Advisories","date_rel":"23h ago"},{"title":"Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Remote%20Access%20SSL%20VPN%20Denial%20of%20Service%20Vulnerability%26vs_k=1","source":"Cisco Security Advisories","date_rel":"11 Aug"}]},{"title":"Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing","link":"https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html","reason":"Android","category":"News","sources":["CyberScoop","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct\u2026","source":"The Hacker News","date_rel":"11 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieGDZmdQhY70KqvppH4w5wMVhbs804WeageCN1UXtRK4KpFkYWNk-wkTeTv9CUSNGYQMsaZ04XYWimXsIQmfl0uYSFgNJe7uBbXsg1xPw-cukXwJY3O3TAHUpWiiYmleWgDpu4PLMRfjgIQtOxb6Wq2yFjvqyb6lpoCOcOyWOpZoURLpddzyGkmc8soRHe/s1600/android-botnet.jpg","description":"Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. \"Kimwolf v7 adds an HTTP/2-based","related":[{"title":"New Android malware lets criminals use your bank card in real time","link":"https://www.malwarebytes.com/blog/mobile/2026/08/new-android-malware-lets-criminals-use-your-bank-card-in-real-time","source":"Malwarebytes Labs","date_rel":"13 Aug"},{"title":"Kimwolf botnet rebuilt to survive takedowns, researchers say","link":"https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/","source":"CyberScoop","date_rel":"12 Aug"}]}],"worth_reading":[{"title":"Researchers found a way to hijack devices through Zoom screen sharing","link":"https://arstechnica.com/security/2026/08/researchers-found-a-way-to-hijack-devices-through-zoom-screen-sharing/","reason":"Zoom","category":"Media","sources":["Ars Technica Security","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them , and even carry out autonomous hacking sprees , researchers offered a sobering new example on Tuesday\u2026","source":"Ars Technica Security","date_rel":"12 Aug","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2022/08/GettyImages-1233188488-500x500.jpg","description":"As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them , and even carry out autonomous hacking sprees , researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets\u2019 devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim. Researchers from the digital defense firm A Security\u2026","related":[{"title":"\u201cZoomsday\u201d flaws could let one Zoom participant attack another","link":"https://www.malwarebytes.com/blog/bugs/2026/08/zoomsday-flaws-could-let-one-zoom-participant-attack-another","source":"Malwarebytes Labs","date_rel":"12 Aug"},{"title":"Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client","link":"https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html","source":"The Hacker News","date_rel":"11 Aug"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-15413","vendor":"WordPress","product":"Link Factory","severity":"CRITICAL","score":10.0,"description":"The Link Factory WordPress plugin is a backdoor. Distributed as a \"homepage sentence publisher\", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a h\u2026","cwe":"CWE-912","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15413"},{"id":"CVE-2026-59500","vendor":"Priority","product":"Portal Generator addon to Priority ERP (developed by Soft Solutions)","severity":"CRITICAL","score":10.0,"description":"CWE-287: Improper Authentication","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.0038,"url":"https://cve.blackmesa.ca/?q=CVE-2026-59500"},{"id":"CVE-2026-27544","vendor":"QuarkA","product":"QA Analytics","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-27544"},{"id":"CVE-2026-61962","vendor":"Hakan Ozevin","product":"WP BASE Booking","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61962"},{"id":"CVE-2026-72851","vendor":"budibase","product":"server","severity":"CRITICAL","score":10.0,"description":"Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads tha\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72851"},{"id":"CVE-2026-73656","vendor":"triggerdotdev","product":"trigger.dev","severity":"CRITICAL","score":9.9,"description":"Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73656"},{"id":"CVE-2026-72841","vendor":"openwrt","product":"luci","severity":"CRITICAL","score":9.9,"description":"luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious pay\u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72841"},{"id":"CVE-2026-72842","vendor":"openwrt","product":"luci","severity":"CRITICAL","score":9.9,"description":"luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E`\u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72842"},{"id":"CVE-2026-49827","vendor":"SMEWebify","product":"WebErpMesv2","severity":"CRITICAL","score":9.8,"description":"WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Cod\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-49827"},{"id":"CVE-2026-28008","vendor":"miniOrange","product":"OAuth Single Sign On \u2013 SSO (OAuth Client)","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Broken Authentication in OAuth Single Sign On \u2013 SSO (OAuth Client) <= 7.0.0 versions.","cwe":"CWE-290","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-28008"}],"vendor_spikes":[{"vendor":"IBM","count":74,"critical_count":3},{"vendor":"Elastic","count":48,"critical_count":0},{"vendor":"Gitea","count":47,"critical_count":0},{"vendor":"Unknown","count":36,"critical_count":0},{"vendor":"RsyncProject","count":28,"critical_count":1},{"vendor":"WordPress","count":24,"critical_count":3},{"vendor":"Priority","count":9,"critical_count":5},{"vendor":"FlowiseAI","count":9,"critical_count":0},{"vendor":"silabs.com","count":9,"critical_count":0},{"vendor":"Tenda","count":9,"critical_count":1}],"epss_risers":[],"developing_map":{"https://www.theregister.com/security/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results/5287028":5},"trending_count":20,"new_cve_count":612,"has_news_data":true,"has_cve_data":true}