{"date_iso":"2026-08-15","date_human":"Saturday, August 15, 2026","generated_utc":"2026-08-15 13:36 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"VINclarity Publishes Investigation Into Alleged Scam and Fraud Reputation Attack Across Search and AI","link":"https://cybersecuritynews.com/vinclarity-publishes-investigation-into-alleged-scam-and-fraud-reputation-attack-across-search-and-ai/","reason":"Google","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Register Security"],"coverage":7,"cve_ids":[],"summary":"Selidan, USA, August 14th, 2026, CyberNewswire New report examines suspicious Reddit activity, coordinated YouTube content and BBB Scam Tracker entries influencing how the vehicle history platform appears across Google\u2026","source":"Cyber Security News","date_rel":"19h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAKFffzGjkxmQtKa1Boy52FYRjPUhFH6nFz1T0VF8DnB764ZWWemdYgdjiQ-uUVNMjTlVv76-N6fQ9qtf7CXd-xBZoWBXB8Nkjs087J2Oo-M63ga9FdVcWOAU2obBOHwyRM87Gtv2OTYj9e3p1BCPJNcRIivDPv1_xtLYSR1BmTVXHMJ2YhUROHDu1a64/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20proj%20-%202026-08-14T213449.22.webp","description":"Selidan, USA, August 14th, 2026, CyberNewswire New report examines suspicious Reddit activity, coordinated YouTube content and BBB Scam Tracker entries influencing how the vehicle history platform appears across Google and AI systems VINclarity has published a new investigation into what researchers describe as a coordinated online reputation attack targeting the vehicle history platform across Reddit, YouTube, Google Search and AI-powered discovery systems. The investigation, \u201cVINclarity Becomes the Next Target: Inside the Coordinated Reputation Attack Playbook\u201d , examines a cluster of\u2026","related":[{"title":"The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI","link":"https://www.bleepingcomputer.com/news/security/the-modern-attack-chain-rethinking-google-workspace-security-in-the-age-of-ai/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal","link":"https://www.securityweek.com/google-cloud-sets-out-post-quantum-roadmap-with-2029-readiness-goal/","source":"SecurityWeek","date_rel":"14 Aug"},{"title":"Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone","link":"https://www.infosecurity-magazine.com/news/google-cloud-post-quantum-roadmap/","source":"Infosecurity Magazine","date_rel":"13 Aug"},{"title":"Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits","link":"https://www.malwarebytes.com/blog/privacy/2026/08/parents-take-on-meta-tiktok-google-and-snap-in-3000-youth-safety-lawsuits","source":"Malwarebytes Labs","date_rel":"13 Aug"},{"title":"Passwords stored in public Google Doc then showed up in search results","link":"https://www.theregister.com/security/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results/5287028","source":"The Register Security","date_rel":"13 Aug"},{"title":"Google security advisory (AV26-806)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-806","source":"CCCS Alerts & Advisories","date_rel":"12 Aug"}]},{"title":"Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication","link":"https://cybersecuritynews.com/microsoft-make-passkeys-default-in-entra-id/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Malwarebytes Labs","The Hacker News","The Register Security"],"coverage":5,"cve_ids":["CVE-2026-55040"],"summary":"Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods. The company will also retire Microsoft-provided SMS and voice\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Microsoft-to-make-passkeys-Default-in-Entra-ID-and-Retires-SMS-and-voice-authentication.webp","description":"Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods. The company will also retire Microsoft-provided SMS and voice authentication for multifactor authentication, pushing organizations toward phishing-resistant credentials. Beginning September 1, 2026, users currently enabled for SMS or voice authentication will be automatically enabled for passkeys. During a future MFA sign-in, these users will see prompts encouraging them to register a passkey. Microsoft will manage the passkey\u2026","related":[{"title":"Microsoft patches LegacyHive Windows zero-day vulnerability","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/","source":"Bleeping Computer","date_rel":"13 Aug"},{"title":"The backup Microsoft never promised you","link":"https://www.theregister.com/security/2026/08/13/sponsored-the-backup-microsoft-never-promised-you/5284957","source":"The Register Security","date_rel":"13 Aug"},{"title":"Attackers Exploit SharePoint Authentication Bypass After Public PoC Release","link":"https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html","source":"The Hacker News","date_rel":"13 Aug"},{"title":"Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor","link":"https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html","source":"The Hacker News","date_rel":"12 Aug"},{"title":"Patch Tuesday: Update now to fix 421 flaws, including three zero-days","link":"https://www.malwarebytes.com/blog/bugs/2026/08/patch-tuesday-update-now-to-fix-421-flaws-including-three-zero-days","source":"Malwarebytes Labs","date_rel":"12 Aug"}]},{"title":"Vulnerability giving attackers full control of Macs is under active exploitation","link":"https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/","reason":"Macos","category":"Media","sources":["Ars Technica Security","Bleeping Computer","Infosecurity Magazine","SecurityWeek"],"coverage":4,"cve_ids":[],"summary":"Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. \u201cThe NCSC has received a notification indicating that active abuse of\u2026","source":"Ars Technica Security","date_rel":"17h ago","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2026/08/macbook-pro-500x500.jpg","description":"Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. \u201cThe NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,\u201d the Netherlands National Cyber Security Centrum warned earlier this week. \u201cIn all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.\u201d Do you know if your screen sharing is on? The vulnerability, tracked as\u2026","related":[{"title":"Hackers exploit macOS Screen Sharing flaw to deploy Monero miner","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Novel macOS Infostealer AmnesiaStealer Spread via ClickFix","link":"https://www.infosecurity-magazine.com/news/macos-infostealer-spread-clickfix/","source":"Infosecurity Magazine","date_rel":"14 Aug"},{"title":"AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions","link":"https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/","source":"SecurityWeek","date_rel":"14 Aug"}]},{"title":"Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals","link":"https://cybersecuritynews.com/malware-crypter-services/","reason":"Windows","category":"News","sources":["Cyber Security News","Kaspersky Securelist","Microsoft Security"],"coverage":3,"cve_ids":["CVE-2026-61347","CVE-2026-62755","CVE-2026-62777"],"summary":"Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle to recognize it. Their operators promise customers a way around\u2026","source":"Cyber Security News","date_rel":"14 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Malware-Crypter-Services-Sell-Windows-Defender-EDR-and-SmartScreen-Bypasses-to-Cybercriminals.webp","description":"Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle to recognize it. Their operators promise customers a way around Windows Defender, endpoint detection and response tools, and Microsoft SmartScreen. The change helps attackers move familiar malware past controls that would otherwise flag it early. The danger is not a single new malware family. It is a commercial layer that helps many kinds of malware reach victims with less scrutiny. Criminals can package remote access tools, stealers, or\u2026","related":[{"title":"CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61347","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62755","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62777","source":"Microsoft Security","date_rel":"22h ago"},{"title":"APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit","link":"https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/","source":"Kaspersky Securelist","date_rel":"14 Aug"}]},{"title":"ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-576/","reason":"Linux","category":"Research","sources":["Infosecurity Magazine","SANS Internet Storm Center","Zero Day Initiative"],"coverage":3,"cve_ids":[],"summary":"This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to\u2026","source":"Zero Day Initiative","date_rel":"13 Aug","thumbnail":"","description":"This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.","related":[{"title":"New Mirai-Based Linux Botnet \u2018Evooo1Bot\u2019 Turns Victims Into Proxies","link":"https://www.infosecurity-magazine.com/news/new-linux-botnet-evooo1bot-victims/","source":"Infosecurity Magazine","date_rel":"23h ago"},{"title":"ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-575/","source":"Zero Day Initiative","date_rel":"13 Aug"},{"title":"ZDI-26-574: Linux Kernel Net Scheduler Connection Tracking Race Condition Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-574/","source":"Zero Day Initiative","date_rel":"13 Aug"},{"title":"Linux Kernel Process Accounting, (Wed, Aug 12th)","link":"https://isc.sans.edu/diary/rss/33240","source":"SANS Internet Storm Center","date_rel":"12 Aug"}]},{"title":"HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel","link":"https://cybersecuritynews.com/hackerai-malware/","reason":"Github","category":"News","sources":["Bleeping Computer","Cyber Security News","Wiz Research"],"coverage":3,"cve_ids":[],"summary":"A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data. The technique lets operators blend malicious traffic with a service that\u2026","source":"Cyber Security News","date_rel":"14 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/HACKERAI-Malware-Turns-GitHub-Gists-Into-a-Command-and-Control-Channel.webp","description":"A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data. The technique lets operators blend malicious traffic with a service that many organizations allow on their networks. The malware appeared during an investigation into a wider espionage campaign aimed at telecom, government, defense, energy, and critical infrastructure organizations in South Asia. Victims were lured with files that impersonated trusted telecom services, government updates, and software installers. Researchers at Acronis identified\u2026","related":[{"title":"AI 'watermark removers' flood the web. Almost none can prove they work","link":"https://www.bleepingcomputer.com/news/security/ai-watermark-removers-flood-the-web-almost-none-can-prove-they-work/","source":"Bleeping Computer","date_rel":"13 Aug"},{"title":"How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign","link":"https://www.wiz.io/blog/investigating-github-pat-compromise","source":"Wiz Research","date_rel":"13 Aug"}]},{"title":"AWS key exposed in JavaScript may have lit way to Beacon's charity data","link":"https://www.theregister.com/security/2026/08/13/aws-key-exposed-in-javascript-may-have-lit-way-to-beacons-charity-data/5287303","reason":"Aws","category":"News","sources":["Infosecurity Magazine","SecurityWeek","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Beacon, a CRM provider for charities and nonprofits, says an AWS access key \"potentially exposed in public JavaScript build artifacts\" is the leading suspect in its July breach. The revelation came in the company's\u2026","source":"The Register Security","date_rel":"13 Aug","thumbnail":"https://image.theregister.com/?imageId=1681829&width=800","description":"Beacon, a CRM provider for charities and nonprofits, says an AWS access key \"potentially exposed in public JavaScript build artifacts\" is the leading suspect in its July breach. The revelation came in the company's first update on the attack in more than a week. If the access key was exposed in public build artifacts, it raises questions about why Beacon's development pipeline and code review controls failed to catch it. Beacon used stronger wording about the potential data loss, confirming that a copy of the database was made and assessing that it was probably downloaded in readable form\u2026","related":[{"title":"Over 1,000 Charities Hit by Beacon CRM Data Breach","link":"https://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/","source":"SecurityWeek","date_rel":"14 Aug"},{"title":"Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities","link":"https://www.infosecurity-magazine.com/news/exposed-aws-key-data-charities/","source":"Infosecurity Magazine","date_rel":"13 Aug"}]},{"title":"Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root \u2013 PoC Released","link":"https://cybersecuritynews.com/citrix-netscaler-heap-overflow/","reason":"Citrix","category":"News","sources":["Cyber Security News","watchTowr Labs"],"coverage":2,"cve_ids":["CVE-2026-8452"],"summary":"A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned into unauthenticated root-level remote code execution (RCE). The\u2026","source":"Cyber Security News","date_rel":"22h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Citrix-NetScaler-Heap-Overflow.webp","description":"A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned into unauthenticated root-level remote code execution (RCE). The vulnerability was originally addressed in Cloud Software Group\u2019s June 30 security bulletin CTX696604, where Citrix described CVE-2026-8452 as a memory overflow that could result in denial-of-service (DoS) or \u201cunpredictable behavior.\u201d However, independent analysis confirms that the flaw is far more severe, granting remote attackers direct control over the core packet-processing\u2026","related":[{"title":"You\u2019re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))","link":"https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/","source":"watchTowr Labs","date_rel":"14 Aug"}]},{"title":"Apple now uses iPhone alerts for targets of mercenary spyware","link":"https://www.malwarebytes.com/blog/news/2026/08/apple-now-uses-iphone-alerts-for-targets-of-mercenary-spyware","reason":"Apple","category":"Threat Intel","sources":["Bleeping Computer","Malwarebytes Labs"],"coverage":2,"cve_ids":[],"summary":"Apple has expanded its threat-notification system for targets of mercenary spyware . Apple now shows a warning directly on an iPhone\u2019s Lock Screen and in Settings when it believes the device owner has been targeted by\u2026","source":"Malwarebytes Labs","date_rel":"23h ago","thumbnail":"","description":"Apple has expanded its threat-notification system for targets of mercenary spyware . Apple now shows a warning directly on an iPhone\u2019s Lock Screen and in Settings when it believes the device owner has been targeted by mercenary spyware. The new on-device alert is meant to make a high-risk warning harder to overlook and complements notifications by email and through the user\u2019s Apple Account page. In the explanation, Apple states: \u201cApple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.\u201d\u2026","related":[{"title":"Apple sends new \u2018Threat Notification\u2019 alerts over mercenary spyware attacks","link":"https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks/","source":"Bleeping Computer","date_rel":"14 Aug"}]},{"title":"RingCentral data breach exposed info of 1.6 million accounts","link":"https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/","reason":"Ringcentral Million Breach","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.","source":"Bleeping Computer","date_rel":"14 Aug","thumbnail":"","description":"","related":[{"title":"1.6 Million Likely Impacted by RingCentral Data Breach","link":"https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/","source":"SecurityWeek","date_rel":"14 Aug"}]}],"worth_reading":[{"title":"ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-582/","reason":"Cisco","category":"Research","sources":["CCCS Alerts & Advisories","Zero Day Initiative"],"coverage":2,"cve_ids":["CVE-2026-20349"],"summary":"This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a\u2026","source":"Zero Day Initiative","date_rel":"13 Aug","thumbnail":"","description":"This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20148.","related":[{"title":"AL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349","link":"https://cyber.gc.ca/en/alerts-advisories/al26-018-vulnerability-affecting-cisco-asa-secure-firewall-threat-defense-software-remote-access-ssl-vpn-cve-2026-20349","source":"CCCS Alerts & Advisories","date_rel":"13 Aug"},{"title":"ZDI-26-581: Cisco Identity Services Engine invokeScript Command Injection Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-581/","source":"Zero Day Initiative","date_rel":"13 Aug"},{"title":"ZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-580/","source":"Zero Day Initiative","date_rel":"13 Aug"},{"title":"Cisco security advisory (AV26-807)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-807","source":"CCCS Alerts & Advisories","date_rel":"12 Aug"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-72811","vendor":"siyuan-note","product":"siyuan","severity":"CRITICAL","score":10.0,"description":"SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72811"},{"id":"CVE-2026-19188","vendor":"Haiwell","product":"Haiwell IoT Cloud HMI Gateway","severity":"CRITICAL","score":10.0,"description":"A critical OS command injection vulnerability has been identified in the\n Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the \nNet Check feature accessible via the /setting endpoint. The cmdPing \nSocket.io event fails to \u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19188"},{"id":"CVE-2026-73678","vendor":"MindsDB","product":"Minds Platform","severity":"CRITICAL","score":10.0,"description":"MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73678"},{"id":"CVE-2026-19626","vendor":"Tenable, Inc.","product":"Security Center","severity":"CRITICAL","score":9.9,"description":"A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsaf\u2026","cwe":"CWE-95","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19626"},{"id":"CVE-2026-19681","vendor":"Tenable, Inc.","product":"Security Center","severity":"CRITICAL","score":9.9,"description":"An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution o\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19681"},{"id":"CVE-2026-19682","vendor":"Tenable, Inc.","product":"Security Center","severity":"CRITICAL","score":9.9,"description":"A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19682"},{"id":"CVE-2026-17186","vendor":"IBM","product":"Db2 Mirror for i","severity":"CRITICAL","score":9.9,"description":"IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-17186"},{"id":"CVE-2026-72822","vendor":"getgrav","product":"grav","severity":"CRITICAL","score":9.8,"description":"The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely \u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72822"},{"id":"CVE-2026-72824","vendor":"HashiCorp","product":"grav","severity":"CRITICAL","score":9.8,"description":"The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not consult api_key_scopes, so a least-\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72824"},{"id":"CVE-2026-72826","vendor":"getgrav","product":"grav","severity":"CRITICAL","score":9.8,"description":"The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline \u2026","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72826"}],"vendor_spikes":[{"vendor":"Linux","count":657,"critical_count":0},{"vendor":"WordPress","count":26,"critical_count":2},{"vendor":"Apple","count":25,"critical_count":0},{"vendor":"IBM","count":18,"critical_count":4},{"vendor":"HashiCorp","count":17,"critical_count":3},{"vendor":"Microsoft","count":17,"critical_count":1},{"vendor":"getgrav","count":12,"critical_count":3},{"vendor":"Red Hat","count":11,"critical_count":0},{"vendor":"Tenable, Inc.","count":11,"critical_count":3},{"vendor":"TOTOLINK","count":9,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":918,"has_news_data":true,"has_cve_data":true}