{"date_iso":"2026-08-18","date_human":"Tuesday, August 18, 2026","generated_utc":"2026-08-18 14:46 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Windows 11 File Explorer Gets Faster, Customizable Right-Click Menu With App Extension Controls","link":"https://cybersecuritynews.com/windows-11-file-explorer-gets-faster/","reason":"Microsoft","category":"News","sources":["Any.Run Malware Analysis","Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Malwarebytes Labs","The Register Security"],"coverage":6,"cve_ids":[],"summary":"Microsoft has introduced a redesigned File Explorer context menu for Windows 11 Insiders , promising faster right-click performance, less clutter, and new controls over built-in commands and third-party app extensions\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Windows-11-File-Explorer-Gets-Faster-Customizable-Right-Click-Menu-With-App-Extension-Controls.webp","description":"Microsoft has introduced a redesigned File Explorer context menu for Windows 11 Insiders , promising faster right-click performance, less clutter, and new controls over built-in commands and third-party app extensions. The update is part of Microsoft\u2019s wider effort to improve File Explorer\u2019s responsiveness, stability, and day-to-day usability. File Explorer is central to everyday Windows activity, including browsing folders, copying files, renaming documents, and accessing cloud-stored content. Microsoft said it has focused on reducing freezes, loading delays, visual flashes, and other\u2026","related":[{"title":"Microsoft tests faster Windows File Explorer, new context menu","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-tests-faster-windows-explorer-customizable-context-menu/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Mirage2FA Hijacks Companies\u2019 Microsoft 365 Sessions, with Over 4K Victims in the US","link":"https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/","source":"Any.Run Malware Analysis","date_rel":"2h ago"},{"title":"Microsoft confirms outage affecting search in Microsoft 365 apps","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-bug-behind-microsoft-365-search-issues/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Microsoft starts removing WMIC tool used by cybercriminals","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/","source":"Bleeping Computer","date_rel":"4h ago"},{"title":"Microsoft Edge security advisory (AV26-822)","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-edge-security-advisory-av26-822","source":"CCCS Alerts & Advisories","date_rel":"22h ago"},{"title":"ShieldBreak bypasses Microsoft\u2019s patch for earlier Defender flaw","link":"https://www.malwarebytes.com/blog/bugs/2026/08/shieldbreak-bypasses-microsofts-patch-for-earlier-defender-flaw","source":"Malwarebytes Labs","date_rel":"22h ago"}]},{"title":"16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets","link":"https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html","reason":"Windows","category":"News","sources":["Bleeping Computer","Cyber Security News","Microsoft Security","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-40400","CVE-2026-56188"],"summary":"Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the\u2026","source":"The Hacker News","date_rel":"45m ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9BsXf9I7m4IoC0hb3fSwYiBJsaB1_vSj9kGhfi0HsWGeR0xVl_W1O_Z0bd6IxvQ-vUQP5FDsj5mpiwUjv72JG3vNdViDwAKDG1uswOPDfb84xN_n8AgafhIP2sCx8x1Jd4L0mptrXuzCCGze-safV0V13WiWsFbKrKYvIC6CPBncYuhwgaDafyqSJx9Kv/s1600/ruby.jpg","description":"Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn","related":[{"title":"Shadow hVNC Gives Attackers Remote Desktop Control Without Moving the Victim\u2019s Mouse","link":"https://cybersecuritynews.com/shadow-hvnc-gives-attackers/","source":"Cyber Security News","date_rel":"1h ago"},{"title":"CISA: Windows Task Host flaw now exploited by ransomware gangs","link":"https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40400","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188","source":"Microsoft Security","date_rel":"22h ago"}]},{"title":"Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks","link":"https://cybersecuritynews.com/wordpress-forminator-plugin-vulnerability/","reason":"Wordpress","category":"News","sources":["Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-15748"],"summary":"A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files , potentially enabling them to take full control of vulnerable websites. The issue\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Critical-WordPress-Plugin-Vulnerability-Exposes-600000-Sites-to-File-Upload-Attacks.webp","description":"A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files , potentially enabling them to take full control of vulnerable websites. The issue, tracked as CVE-2026-15748, affects Forminator Forms versions 1.56.1 and earlier and carries a CVSS severity score of 9.8. Forminator Forms is a widely used drag-and-drop plugin for building contact, payment, poll, quiz, and file-upload forms. With more than 600,000 active installations, the vulnerability poses a significant risk to WordPress administrators who have not yet\u2026","related":[{"title":"300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw","link":"https://www.securityweek.com/300000-wordpress-sites-potentially-exposed-to-hacking-due-to-form-plugin-flaw/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads","link":"https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html","source":"The Hacker News","date_rel":"18h ago"},{"title":"WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover","link":"https://www.infosecurity-magazine.com/news/wordpress-plugin-flaw-40000-sites/","source":"Infosecurity Magazine","date_rel":"22h ago"}]},{"title":"Video Call Exploit Chains Two Flaws in Unisoc Modems","link":"https://www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modems","reason":"Android","category":"News","sources":["Dark Reading","Malwarebytes Labs","Microsoft Security","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-65767"],"summary":"Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.","source":"Dark Reading","date_rel":"14h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt3b0d5e1880afeee0/6a836ae7cff1172eaef5b7c9/videocall_Kumeko_shutterstock.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access","link":"https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html","source":"The Hacker News","date_rel":"17 Aug"},{"title":"A week in security (August 10 \u2013 August 16)","link":"https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-august-10-august-16","source":"Malwarebytes Labs","date_rel":"17 Aug"},{"title":"CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65767","source":"Microsoft Security","date_rel":"16 Aug"}]},{"title":"Crook hawks millions of records allegedly plundered from corporate Azure tenants","link":"https://www.theregister.com/security/2026/08/17/crook-hawks-millions-of-records-allegedly-plundered-from-corporate-azure-tenants/5288305","reason":"Azure","category":"News","sources":["Bleeping Computer","Microsoft Security","Tenable Blog","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-57104"],"summary":"A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans\u2026","source":"The Register Security","date_rel":"17 Aug","thumbnail":"https://image.theregister.com/?imageId=253523&width=800","description":"A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans nine organizations and is being advertised for sale by a threat actor using the name \"TheHatman,\" according to research published by Hudson Rock. McDonald's accounts for the largest alleged dataset on TheHatman's shopping list, with 1.7 million records purportedly up for grabs. Another 800,000 records supposedly come from Tata Consultancy Services, 425,000 from Vodafone, and\u2026","related":[{"title":"Hacker claims 3.6 million Azure account records stolen from major companies","link":"https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/","source":"Bleeping Computer","date_rel":"16h ago"},{"title":"Detecting cloud ransomware in Azure with Tenable One\u2019s cloud detection and response capabilities","link":"https://www.tenable.com/blog/detecting-cloud-ransomware-in-azure-with-tenable-ones-cloud-detection-and-response","source":"Tenable Blog","date_rel":"21h ago"},{"title":"CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57104","source":"Microsoft Security","date_rel":"16 Aug"}]},{"title":"Apple Patches iOS and macOS, (Mon, Aug 17th)","link":"https://isc.sans.edu/diary/rss/33254","reason":"Apple","category":"Research","sources":["CCCS Alerts & Advisories","Malwarebytes Labs","SANS Internet Storm Center"],"coverage":3,"cve_ids":[],"summary":"Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing\u2026","source":"SANS Internet Storm Center","date_rel":"15h ago","thumbnail":"","description":"Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.","related":[{"title":"Apple security advisory (AV26-823)","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-823","source":"CCCS Alerts & Advisories","date_rel":"20h ago"},{"title":"Apple Screen Sharing Security, (Mon, Aug 17th)","link":"https://isc.sans.edu/diary/rss/33252","source":"SANS Internet Storm Center","date_rel":"21h ago"},{"title":"Update your Mac: Screen Sharing vulnerability exploited in the wild","link":"https://www.malwarebytes.com/blog/bugs/2026/08/update-your-mac-screen-sharing-vulnerability-exploited-in-the-wild","source":"Malwarebytes Labs","date_rel":"17 Aug"}]},{"title":"Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public Projects","link":"https://cybersecuritynews.com/gitlab-graphql-vulnerability/","reason":"Gitlab","category":"News","sources":["Cyber Security News","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public projects and user data remotely. The issue, tracked as\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Critical-GitLab-GraphQL-Vulnerability-Allow-Attackers-to-Delete-Public-Projects.webp","description":"GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public projects and user data remotely. The issue, tracked as CVE-2026-19478, affects GitLab Community Edition and Enterprise Edition installations across several supported release branches. The vulnerability was addressed in GitLab versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11, released on August 17, 2026. GitLab strongly recommends that administrators of self-managed instances upgrade immediately. GitLab.com and GitLab Dedicated have already\u2026","related":[{"title":"GitLab Patches Critical Code Injection Vulnerability","link":"https://www.securityweek.com/gitlab-patches-critical-code-injection-vulnerability/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects","link":"https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html","source":"The Hacker News","date_rel":"15h ago"}]},{"title":"Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection","link":"https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html","reason":"Github","category":"News","sources":["Bleeping Computer","The Hacker News","Wiz Research"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a\u2026","source":"The Hacker News","date_rel":"17h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJW5BJKjwNfnH2t8RrvgW0wUO3_ZJWnw30aS6GlU9qoaOWMQcyoZ9ZOZmTgLo7hWAqHlKDK2b4MrtF23Jv_1-1Ffd6bo6VlR8exLvIISBANwjHnW3dv7wLgCtyCIDlndpJ67TajeEpN-Ww9eVVutmS4fTpcDPJtlAk_ZU0GLtnkDvYLlqWPv75uMH7ob__/s1600/snowflake.jpg","description":"Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a","related":[{"title":"Microsoft confirms GitHub is down worldwide","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Wiz Red Agent Finds Its Way Into Snowflake\u2019s Internal Jira Through a Flaw in a GitHub Copilot\u2013Assisted PR","link":"https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug","source":"Wiz Research","date_rel":"22h ago"}]},{"title":"Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic","link":"https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html","reason":"Google","category":"News","sources":["Malwarebytes Labs","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian\u2026","source":"The Hacker News","date_rel":"18h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhu-MyaPNuRr2_NJ_TMqLf7OYW5AzCqgHpQ6HMfxlc-qsMzwSkfWlZDbHfecZ3IRp639FVDelhMZgpbnN87Fdchoh-g08R-cAiXxr7RvfdGy_ihvMxg152HK-rbOTIOnEueRTnPT-wU0eID3vplpIN1GBClvJC5e0egCGpDb_H0ykwH1x6a4zOvpW8V-Ssy/s1600/google.jpg","description":"Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the","related":[{"title":"Be careful what you put in \u201canyone with the link\u201d Google Docs","link":"https://www.malwarebytes.com/blog/news/2026/08/be-careful-what-you-put-in-anyone-with-the-link-google-docs","source":"Malwarebytes Labs","date_rel":"1h ago"}]},{"title":"CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/ray-project-ray-code-injection/","reason":"CVE-2025-62593","category":"News","sources":["CISA Alerts & Advisories","Cyber Security News"],"coverage":2,"cve_ids":["CVE-2025-62593"],"summary":"CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593 , to its Known Exploited Vulnerabilities catalog after confirming exploitation in the wild. The flaw can allow remote code execution on\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/CISA-Warns-of-Ray-Project-Ray-Code-Injection-Vulnerability-Exploited-in-Attacks.webp","description":"CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593 , to its Known Exploited Vulnerabilities catalog after confirming exploitation in the wild. The flaw can allow remote code execution on systems where vulnerable Ray development environments are running. Ray is an open-source distributed computing framework widely used by Python developers and AI teams for scaling machine learning, data processing, and application workloads. The issue affects Ray versions before 2.52.0 and is especially dangerous for developers using Firefox or Safari. At the same time, Ray is\u2026","related":[{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"17 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-66792","vendor":"Red Hat","product":"Multicluster Global Hub","severity":"CRITICAL","score":9.9,"description":"A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation g\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":0.003,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66792"},{"id":"CVE-2026-47686","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":9.9,"description":"vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sand\u2026","cwe":"CWE-693","kev":false,"kev_action":"","kev_due":"","epss":0.0032,"url":"https://cve.blackmesa.ca/?q=CVE-2026-47686"},{"id":"CVE-2026-65974","vendor":"HashiCorp","product":"erpnext","severity":"CRITICAL","score":9.9,"description":"ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forci\u2026","cwe":"CWE-1336","kev":false,"kev_action":"","kev_due":"","epss":0.0056,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65974"},{"id":"CVE-2026-75843","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.9,"description":"ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers ca\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75843"},{"id":"CVE-2026-75851","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.9,"description":"ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on \u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75851"},{"id":"CVE-2026-32444","vendor":"Cwicly","product":"Cwicly","severity":"CRITICAL","score":9.9,"description":"Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-32444"},{"id":"CVE-2026-32463","vendor":"Kamlesh Parmar","product":"Sync Post With Other Site","severity":"CRITICAL","score":9.9,"description":"Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-32463"},{"id":"CVE-2026-50768","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.0059,"url":"https://cve.blackmesa.ca/?q=CVE-2026-50768"},{"id":"CVE-2026-47698","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":9.8,"description":"vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing san\u2026","cwe":"CWE-913","kev":false,"kev_action":"","kev_due":"","epss":0.0049,"url":"https://cve.blackmesa.ca/?q=CVE-2026-47698"},{"id":"CVE-2026-75110","vendor":"MemTensor","product":"MemOS","severity":"CRITICAL","score":9.8,"description":"MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request()\u2026","cwe":"CWE-697","kev":false,"kev_action":"","kev_due":"","epss":0.0052,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75110"}],"vendor_spikes":[{"vendor":"Mozilla","count":58,"critical_count":0},{"vendor":"Unknown","count":35,"critical_count":9},{"vendor":"Apple","count":35,"critical_count":0},{"vendor":"JetBrains","count":18,"critical_count":1},{"vendor":"ArcadeData","count":14,"critical_count":4},{"vendor":"getgrav","count":12,"critical_count":1},{"vendor":"Mattermost","count":11,"critical_count":0},{"vendor":"Microsoft","count":10,"critical_count":0},{"vendor":"Zabbix","count":10,"critical_count":0},{"vendor":"HashiCorp","count":8,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":15,"new_cve_count":377,"has_news_data":true,"has_cve_data":true}