{"date_iso":"2026-08-19","date_human":"Wednesday, August 19, 2026","generated_utc":"2026-08-19 13:51 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)","link":"https://unit42.paloaltonetworks.com/large-scale-credential-attacks/","reason":"Microsoft","category":"Threat Intel","sources":["Any.Run Malware Analysis","Ars Technica Security","Bleeping Computer","CCCS Alerts & Advisories","Dark Reading","Malwarebytes Labs","Palo Alto Unit 42","Sophos Threat Research","The Hacker News","The Register Security"],"coverage":10,"cve_ids":[],"summary":"In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks.","source":"Palo Alto Unit 42","date_rel":"17h ago","thumbnail":"https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-1.jpg","description":"","related":[{"title":"Microsoft fixes known issue causing Windows Defender crashes","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-known-issue-causing-windows-defender-crashes/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Windows 11 24H2 Home and Pro reach end of support in 2 months","link":"https://www.bleepingcomputer.com/news/microsoft/windows-11-24h2-home-and-pro-reach-end-of-support-in-2-months/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"18h ago"},{"title":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps","link":"https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html","source":"The Hacker News","date_rel":"18h ago"},{"title":"Microsoft Copilot reveals secret input that allowed it to be hacked","link":"https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/","source":"Ars Technica Security","date_rel":"23h ago"},{"title":"Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud","link":"https://www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud","source":"Dark Reading","date_rel":"23h ago"}]},{"title":"Apple plugs image-processing hole ripe for spyware abuse","link":"https://www.theregister.com/security/2026/08/18/apple-plugs-image-processing-hole-ripe-for-spyware-abuse/5289031","reason":"Apple","category":"News","sources":["CCCS Alerts & Advisories","Malwarebytes Labs","SANS Internet Storm Center","SecurityWeek","The Register Security","Wired Security"],"coverage":6,"cve_ids":[],"summary":"Apple has released a batch of vulnerability fixes for iPhones, iPads, and Macs, including an image-processing flaw that experts say has the hallmarks of a spyware delivery vector. The most notable patch is for\u2026","source":"The Register Security","date_rel":"21h ago","thumbnail":"https://image.theregister.com/?imageId=5243350&width=800","description":"Apple has released a batch of vulnerability fixes for iPhones, iPads, and Macs, including an image-processing flaw that experts say has the hallmarks of a spyware delivery vector. The most notable patch is for CVE-2026-65346, a defect in the ImageIO framework Apple uses to parse image files. Discovered and reported by Nik Tsytsarkin of Meta's Red Team X, CVE-2026-65346 is an integer-overflow bug that could allow arbitrary code execution when an affected device processes an image. The bug affects macOS Tahoe, iPhone 11 and later, and supported iPad Pro, iPad Air, iPad, and iPad mini models\u2026","related":[{"title":"CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities","link":"https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-microsoft-vmware-apple-vulnerabilities/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"Apple security advisory (AV26-823) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-823","source":"CCCS Alerts & Advisories","date_rel":"17h ago"},{"title":"Apple fixes another image-processing flaw that could allow code execution","link":"https://www.malwarebytes.com/blog/bugs/2026/08/apple-fixes-another-image-processing-flaw-that-could-allow-code-execution","source":"Malwarebytes Labs","date_rel":"21h ago"},{"title":"Meta Ran Ads for an App That Promised to Nudify Female Politicians","link":"https://www.wired.com/story/meta-ran-ads-for-an-app-promising-to-nudify-female-politicians/","source":"Wired Security","date_rel":"21h ago"},{"title":"Apple Patches iOS and macOS, (Mon, Aug 17th)","link":"https://isc.sans.edu/diary/rss/33254","source":"SANS Internet Storm Center","date_rel":"17 Aug"},{"title":"Apple Screen Sharing Security, (Mon, Aug 17th)","link":"https://isc.sans.edu/diary/rss/33252","source":"SANS Internet Storm Center","date_rel":"17 Aug"}]},{"title":"Hackers Use Fake Claude Install Guide to Deploy MacSync Stealer and Trojanize Crypto Wallet Apps","link":"https://cybersecuritynews.com/fake-claude-install-guide/","reason":"Google","category":"News","sources":["Cyber Security News","Huntress","Malwarebytes Labs","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Mac users searching for help with Claude Code are being lured into a malware campaign that turns a routine installation task into a full device compromise. The operation uses paid Google search results and a convincing\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Use-Fake-Claude-Install-Guide-to-Deploy-MacSync-Stealer-and-Trojanize-Crypto-Wallet-Apps.webp","description":"Mac users searching for help with Claude Code are being lured into a malware campaign that turns a routine installation task into a full device compromise. The operation uses paid Google search results and a convincing shared Claude conversation to persuade victims to run a command in Terminal. The campaign puts everyday Mac users at serious risk. The page is hosted on Claude.ai, which gives the lure an air of legitimacy, but it is not an official installation guide. It tells visitors to copy and paste a curl command that downloads MacSync, an information stealer built to collect credentials\u2026","related":[{"title":"Claude Can Now Send Emails in Gmail and Manage Files in Google Drive","link":"https://cybersecuritynews.com/claude-can-now-send-emails-in-gmail/","source":"Cyber Security News","date_rel":"2h ago"},{"title":"Be careful what you put in \u201canyone with the link\u201d Google Docs","link":"https://www.malwarebytes.com/blog/news/2026/08/be-careful-what-you-put-in-anyone-with-the-link-google-docs","source":"Malwarebytes Labs","date_rel":"18 Aug"},{"title":"Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic","link":"https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html","source":"The Hacker News","date_rel":"17 Aug"},{"title":"MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer","link":"https://www.huntress.com/blog/fake-claude-macsync","source":"Huntress","date_rel":"17 Aug"}]},{"title":"Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000","link":"https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html","reason":"Exchange","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-33824"],"summary":"A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging\u2026","source":"The Hacker News","date_rel":"19h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjo_eOapavOiIGXF7klCQPyN0-Qg2nWk9KlUYzPHuLwAyMKM75P3E2jciQR3v9gt2UBmez3XRSC57e5Fe9Oowm2brtgRXz5nJMPN8iQnBYddnTI4DyffnBAh4iLQFSOhA-8RhbbwuXqbJQOkhiXo5asFku1kFfmQd-UsHT6ulzdvRvw7WXwFKYFBTU_Q9nB/s1600/ransom.jpg","description":"A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. \"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,\" GuidePoint Research","related":[{"title":"Critical RCE flaw in Windows IKE Extension now actively exploited","link":"https://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"18 Aug"},{"title":"Microsoft blames AI for delayed Exchange update, can\u2019t say when it will arrive","link":"https://www.theregister.com/software/2026/08/17/microsoft-blames-ai-for-delayed-exchange-update-cant-say-when-it-will-arrive/5288227","source":"The Register Security","date_rel":"17 Aug"}]},{"title":"BeyondTrust Windows EPM Vulnerabilities Allows Attackers to Escalate Privileges","link":"https://cybersecuritynews.com/beyondtrust-windows-epm-vulnerabilities/","reason":"Windows","category":"News","sources":["Bleeping Computer","Cyber Security News","Microsoft Security","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-50419","CVE-2026-65791","CVE-2026-66804"],"summary":"BeyondTrust has disclosed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) product for Windows that could allow attackers with local access to elevate privileges or bypass anti-tamper\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/BeyondTrust-Windows-EPM-Vulnerabilities-.webp","description":"BeyondTrust has disclosed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) product for Windows that could allow attackers with local access to elevate privileges or bypass anti-tamper controls. Tracked as CVE-2026-40144 and CVE-2026-40145, the flaws affect all versions of BeyondTrust Endpoint Privilege Management (Windows Deployment) released before version 26.1.2. The company published the advisory, BT26-04, on August 17, 2026. BeyondTrust said the vulnerabilities were discovered internally during security assessment activities using frontier AI models and\u2026","related":[{"title":"Critical Cursor 0-day Vulnerability Enables Arbitrary Code Execution Attacks","link":"https://cybersecuritynews.com/cursor-0-day-vulnerability/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65791","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-50419 Windows Kernel Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50419","source":"Microsoft Security","date_rel":"22h ago"},{"title":"16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets","link":"https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html","source":"The Hacker News","date_rel":"18 Aug"},{"title":"CISA: Windows Task Host flaw now exploited by ransomware gangs","link":"https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/","source":"Bleeping Computer","date_rel":"18 Aug"}]},{"title":"StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data","link":"https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html","reason":"Wordpress","category":"News","sources":["Check Point Research","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHtWFBMa_xYpIkK39I2gvAJrksqJBAkRSnEZ-WjwpQtbV9mgfPRzWp3qtdhk_v1yOG67pAZ5H3DAFRVv7rEzbns9IuAa4_DV-MUBDIb6fuWzLyRvFXyC1fOaTUPbwxdoY4cykbPy3wXEn3HvlnbjbqH37vkLKMSJA799pVeD50RqMGlJJztFJZcFzR2xTf/s1600/wordpress-hacks.jpg","description":"Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. \"The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software","related":[{"title":"Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect","link":"https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/","source":"Check Point Research","date_rel":"23h ago"},{"title":"Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads","link":"https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html","source":"The Hacker News","date_rel":"17 Aug"},{"title":"WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover","link":"https://www.infosecurity-magazine.com/news/wordpress-plugin-flaw-40000-sites/","source":"Infosecurity Magazine","date_rel":"17 Aug"}]},{"title":"Oracle Releases 943 Security Patches Including Critical WebLogic Full Takeover Vulnerability","link":"https://cybersecuritynews.com/oracle-releases-943-security-patches/","reason":"Oracle","category":"News","sources":["Cyber Security News","SecurityWeek","Tenable Blog"],"coverage":3,"cve_ids":[],"summary":"Oracle has released 943 new security patches in its August 2026 Critical Security Patch Update , addressing flaws across its enterprise software portfolio. The release includes several critical Oracle WebLogic Server\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Oracle-Releases-943-Security-PatchesIncluding-Critical-WebLogic-Full-Takeover-Vulnerability.webp","description":"Oracle has released 943 new security patches in its August 2026 Critical Security Patch Update , addressing flaws across its enterprise software portfolio. The release includes several critical Oracle WebLogic Server vulnerabilities that could allow an unauthenticated remote attacker to take complete control of affected servers. The update, published on August 18, covers Oracle Database, Fusion Middleware, E-Business Suite, Java SE, MySQL, Enterprise Manager, PeopleSoft, Communications products, and many other platforms. Oracle strongly urged customers to apply the updates without delay\u2026","related":[{"title":"943 Patches Rolled Out With Oracle\u2019s August 2026 Security Update","link":"https://www.securityweek.com/943-patches-rolled-out-with-oracles-august-2026-security-update/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs","link":"https://www.tenable.com/blog/oracle-august-2026-critical-security-patch-update-cspu-addresses-925-cves","source":"Tenable Blog","date_rel":"11h ago"}]},{"title":"Google Fixes Two Critical Chrome Flaws in WebGL and Dawn \u2014 Update Your Browser","link":"https://cybersecuritynews.com/google-fixes-two-chrome-flaws-in-webgl-and-dawn/","reason":"Chrome","category":"News","sources":["Cyber Security News","Malwarebytes Labs","SecurityWeek"],"coverage":3,"cve_ids":[],"summary":"Google has released a new Chrome Stable channel update that fixes two critical security vulnerabilities affecting graphics-related components. Users should update their browsers as soon as the release becomes available\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Google-Fixes-Two-Critical-Chrome-Flaws-in-WebGL-and-Dawn-\u2014-Update-Your-Browser.webp","description":"Google has released a new Chrome Stable channel update that fixes two critical security vulnerabilities affecting graphics-related components. Users should update their browsers as soon as the release becomes available for their device. The update moves Chrome to version 151.0.7922.169/.170 on Windows and macOS, while Linux users receive version 151.0.7922.169. Google said the rollout will occur gradually over the coming days and weeks. The two critical issues are tracked as CVE-2026-76034 and CVE-2026-76036. Both are buffer overflow vulnerabilities, a memory-safety flaw that can occur when\u2026","related":[{"title":"Update Chrome now: Two critical vulnerabilities fixed","link":"https://www.malwarebytes.com/blog/bugs/2026/08/update-chrome-now-two-critical-vulnerabilities-fixed","source":"Malwarebytes Labs","date_rel":"1h ago"},{"title":"Chrome, Firefox Updates Patch Dozens of Vulnerabilities","link":"https://www.securityweek.com/chrome-firefox-updates-patch-dozens-of-vulnerabilities/","source":"SecurityWeek","date_rel":"4h ago"}]},{"title":"Crook hawks millions of records allegedly plundered from corporate Azure tenants","link":"https://www.theregister.com/security/2026/08/17/crook-hawks-millions-of-records-allegedly-plundered-from-corporate-azure-tenants/5288305","reason":"Azure","category":"News","sources":["Bleeping Computer","Microsoft Security","Tenable Blog","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-47632","CVE-2026-57104"],"summary":"A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans\u2026","source":"The Register Security","date_rel":"17 Aug","thumbnail":"https://image.theregister.com/?imageId=253523&width=800","description":"A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans nine organizations and is being advertised for sale by a threat actor using the name \"TheHatman,\" according to research published by Hudson Rock. McDonald's accounts for the largest alleged dataset on TheHatman's shopping list, with 1.7 million records purportedly up for grabs. Another 800,000 records supposedly come from Tata Consultancy Services, 425,000 from Vodafone, and\u2026","related":[{"title":"CVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47632","source":"Microsoft Security","date_rel":"22h ago"},{"title":"Hacker claims 3.6 million Azure account records stolen from major companies","link":"https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/","source":"Bleeping Computer","date_rel":"17 Aug"},{"title":"Detecting cloud ransomware in Azure with Tenable One\u2019s cloud detection and response capabilities","link":"https://www.tenable.com/blog/detecting-cloud-ransomware-in-azure-with-tenable-ones-cloud-detection-and-response","source":"Tenable Blog","date_rel":"17 Aug"},{"title":"CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57104","source":"Microsoft Security","date_rel":"16 Aug"}]},{"title":"Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection","link":"https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html","reason":"Github","category":"News","sources":["Bleeping Computer","Infosecurity Magazine","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a\u2026","source":"The Hacker News","date_rel":"17 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJW5BJKjwNfnH2t8RrvgW0wUO3_ZJWnw30aS6GlU9qoaOWMQcyoZ9ZOZmTgLo7hWAqHlKDK2b4MrtF23Jv_1-1Ffd6bo6VlR8exLvIISBANwjHnW3dv7wLgCtyCIDlndpJ67TajeEpN-Ww9eVVutmS4fTpcDPJtlAk_ZU0GLtnkDvYLlqWPv75uMH7ob__/s1600/snowflake.jpg","description":"Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a","related":[{"title":"Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed","link":"https://www.infosecurity-magazine.com/news/wiz-ai-agent-finds-snowflake/","source":"Infosecurity Magazine","date_rel":"20h ago"},{"title":"Microsoft confirms GitHub is down worldwide","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/","source":"Bleeping Computer","date_rel":"17 Aug"},{"title":"Wiz Red Agent Finds Its Way Into Snowflake\u2019s Internal Jira Through a Flaw in a GitHub Copilot\u2013Assisted PR","link":"https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug","source":"Wiz Research","date_rel":"17 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-75874","vendor":"Mozilla","product":"Firefox","severity":"CRITICAL","score":10.0,"description":"Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.","cwe":"CWE-693","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75874"},{"id":"CVE-2026-73343","vendor":"AresIT","product":"WP Compress","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73343"},{"id":"CVE-2026-75784","vendor":"F5","product":"TEW-WLC100","severity":"CRITICAL","score":10.0,"description":"A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in st\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75784"},{"id":"CVE-2026-61241","vendor":"Oracle","product":"Oracle Internet Directory","severity":"CRITICAL","score":10.0,"description":"Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated a\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61241"},{"id":"CVE-2026-70880","vendor":"Oracle","product":"Oracle Hyperion Data Relationship Management","severity":"CRITICAL","score":10.0,"description":"Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticate\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-70880"},{"id":"CVE-2026-70921","vendor":"Oracle","product":"Oracle Hyperion Financial Management","severity":"CRITICAL","score":10.0,"description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with net\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-70921"},{"id":"CVE-2026-76008","vendor":"Comfast","product":"CF-N1-S","severity":"CRITICAL","score":10.0,"description":"A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer \u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76008"},{"id":"CVE-2026-75843","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.9,"description":"ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers ca\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75843"},{"id":"CVE-2026-75851","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.9,"description":"ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on \u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75851"},{"id":"CVE-2026-32444","vendor":"Cwicly","product":"Cwicly","severity":"CRITICAL","score":9.9,"description":"Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-32444"}],"vendor_spikes":[{"vendor":"Oracle","count":891,"critical_count":144},{"vendor":"Mozilla","count":58,"critical_count":5},{"vendor":"WordPress","count":48,"critical_count":0},{"vendor":"Unknown","count":37,"critical_count":0},{"vendor":"mybb","count":18,"critical_count":2},{"vendor":"Google","count":18,"critical_count":0},{"vendor":"Red Hat","count":14,"critical_count":3},{"vendor":"ArcadeData","count":14,"critical_count":4},{"vendor":"Netflix","count":13,"critical_count":1},{"vendor":"HashiCorp","count":12,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":1481,"has_news_data":true,"has_cve_data":true}