CVE-2026-19478: Critical GitLab GraphQL Code Injection
Published August 18, 2026
CVE-2026-19478 is a critical CVSS 9.4 GitLab GraphQL code injection vulnerability that can allow unauthenticated attackers to modify or delete public projects and user data. No verified public PoC or active exploitation has been confirmed as of August 18, 2026.
CVE-2026-64633: Veeam ONE Agent RCE Needs No Password
Published August 6, 2026
A CVSS 10.0 code-injection vulnerability in Veeam ONE allows a remote, unauthenticated attacker to execute code on the agent host. No active exploitation is known, but affected systems should be upgraded to 13.1.0.7034 immediately.
CVE-2026-68771: ComfyUI Pickled Its Way to Unauthenticated RCE
Published August 3, 2026
An unsafe PyTorch deserialization path in ComfyUI allows unauthenticated attackers to execute arbitrary commands using a malicious pickle shard. CVSS 9.3; no public PoC or confirmed successful exploitation, although exploitation attempts are reportedly being tracked.
CVE-2026-63030 (wp2shell): One Bad REST Batch, One WordPress Shell
Published July 19, 2026
A CVSS 9.8 WordPress Core vulnerability chain lets unauthenticated attackers turn REST route confusion and SQL injection into remote code execution. Public PoCs are available, with early signs of in-the-wild activity reported.
CVE-2026-53359 (Januscape): The 16-Year-Old KVM Bug That Lets a Guest Own the Host
Published July 13, 2026
Januscape is a Linux KVM/x86 use-after-free that can turn nested virtualization into host-root code execution. Red Hat scores it CVSS 7.8; a host-crash PoC is public, while the full escape exploit remains withheld.
CVE-2026-48908: Joomla's Page Builder Handed Attackers the Keys, No Knock Required
Published June 26, 2026
A missing access check in SP Page Builder's icon-upload endpoint gave unauthenticated attackers direct RCE on every Joomla site running the extension. CVSS 10.0, actively exploited, patch available.
CVE-2026-36537: ThingsBoard OAuth Login Lets Attackers Become Any User
Published June 19, 2026
A CVSS 9.8 authentication bypass in ThingsBoard's Apple OAuth 2.0 flow lets a remote attacker impersonate an existing user and take over the account. A public PoC exists, while active exploitation has not been reported.
CVE-2026-20253: Splunk's PostgreSQL Sidecar Hands Out Shells. No Credentials Required
Published June 18, 2026
A CVSS 9.8 pre-authentication RCE in Splunk Enterprise's PostgreSQL sidecar service lets any network-reachable attacker chain file-write primitives into full code execution, with active exploitation reported within five days of disclosure.
CVE-2026-10520: Ivanti Sentry's Internal Config API Was Open to the Whole Internet
Published June 11, 2026
A perfect 10.0 pre-authenticated OS command injection in Ivanti Sentry lets any unauthenticated attacker execute arbitrary commands as root. Public PoC released June 10, 2026. Patch immediately.
CVE-2026-32625: LibreChat MCP Server Leaks Your Entire Secret Vault to Any Logged-In User
Published June 7, 2026
A critical (CVSS 9.6) information-disclosure flaw in LibreChat lets any authenticated user exfiltrate JWT signing keys, AES encryption keys, and database credentials by injecting environment-variable placeholders into a malicious MCP server URL. Patched in v0.8.4-rc1.