44 vulnerabilities across 15 products scored HIGH or above on August 20, 2026.

  • πŸ”΄ CRITICAL: 2
  • 🟠 HIGH: 42

πŸ”΄ [CRITICAL] spip/spip

1 CVE | CVSS 3.1: 9.8 | AAS 13.9

  • cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* (< 4.4.20)

SPIP β€” Critical Remote Code Execution Exploited in the Wild

SPIP versions prior to 4.4.20 are affected by a critical unauthenticated remote code execution vulnerability (CVE-2026-77647, CVSS 9.8). The flaw stems from incorrect handling of PHP code blocks and unsafe use of var_export, allowing remote attackers to execute arbitrary code without authentication. This vulnerability is confirmed to be actively exploited in the wild as of August 2026. All organizations running SPIP-based websites should treat this as an emergency update. Upgrade to SPIP 4.4.20 or later immediately and review systems for signs of compromise. Refer to the vendor advisory at blog.spip.net for full details.

Vendor Advisory


πŸ”΄ [CRITICAL] microsoft/microsoft_entra

2 CVEs | CVSS 3.1: 10.0 | AAS 12.2

  • cpe:2.3:a:microsoft:microsoft_entra:*:*:*:*:*:*:*:*

Microsoft Entra β€” Critical Remote Code Execution via Deserialization

Microsoft Entra ID is affected by 2 critical vulnerabilities, including at least one (CVSS 10.0) that allows an unauthorized attacker to execute arbitrary code over the network through deserialization of untrusted data. These flaws require no authentication to exploit, posing a severe risk to any organization relying on Microsoft Entra for identity and access management. All environments using Microsoft Entra ID should apply Microsoft’s security updates immediately and monitor for anomalous authentication or code execution activity. Consult the MSRC advisory for patch guidance and affected version details.

Vendor Advisory


🟠 [HIGH] ibm/aix

25 CVEs | CVSS 3.1: 9.9 | AAS 11.9

  • cpe:2.3:a:ibm:aix:*:*:*:*:*:*:*:* (>= 7.2)
  • cpe:2.3:a:ibm:aix:*:*:*:*:*:*:*:* (>= 7.3)

IBM AIX β€” 25 Vulnerabilities Including Critical Remote Code Execution

IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1 are affected by 25 vulnerabilities, including multiple critical-severity flaws (max CVSS 9.9) that could allow remote attackers to execute arbitrary code through issues such as integer overflow during size computation. The breadth of this advisory represents a significant attack surface expansion for organizations running AIX or PowerVM infrastructure. All administrators of affected IBM AIX and PowerVM VIOS systems should prioritize applying the latest security patches from IBM immediately and review the full advisory at the IBM support page for complete remediation guidance.

Vendor Advisory


🟠 [HIGH] n8n-io/n8n

4 CVEs | CVSS 4.0: 8.7 | AAS 11.1

  • cpe:2.3:a:n8n-io:n8n:*:*:*:*:*:*:*:* (< 2.33.4)
  • cpe:2.3:a:n8n-io:n8n:*:*:*:*:*:*:*:* (>= 2.34.0, < 2.34.1)

n8n β€” Multiple High-Severity Vulnerabilities Including RCE via Path Traversal

n8n versions before 2.33.4 and 2.34.x before 2.34.1 are affected by 4 vulnerabilities, including multiple high-severity flaws (max CVSS 8.7) with proof-of-concept exploit code publicly available. The lead vulnerability allows authenticated users with basic member privileges to achieve remote code execution in the n8n main process by exploiting a path traversal flaw in the MCP node-schema loader. Organizations running self-hosted n8n workflow automation instances should upgrade to version 2.33.4 or 2.34.1 immediately, as the availability of public PoC code significantly lowers the barrier to exploitation. Refer to the GitHub security advisory for full details.

Vendor Advisory


🟠 [HIGH] t8y2/dbx

1 CVE | CVSS 3.1: 9.8 | AAS 11.1

  • cpe:2.3:a:t8y2:dbx:*:*:*:*:*:*:*:*

t8y2 dbx β€” Critical Authentication Bypass Exposes Database Operations to Unauthenticated Attackers

The dbx cross-platform database client prior to version 0.5.51 contains a critical authentication bypass vulnerability (CVE-2026-55642, CVSS 9.8) in which the auth middleware passes all requests through without verification when no password hash is configured. In default deployments where DBX_PASSWORD is unset, the service binds to all network interfaces on port 4224, allowing unauthenticated remote attackers to connect to databases and execute arbitrary queries via exposed API routes. Anyone running dbx should upgrade to version 0.5.51 immediately, and in the interim ensure DBX_PASSWORD is explicitly set and network access to port 4224 is restricted to trusted hosts only.

Vendor Advisory


🟠 [HIGH] hashthemes/easy_elementor_addons

1 CVE | CVSS 3.1: 9.6 | AAS 10.9

  • cpe:2.3:a:hashthemes:easy_elementor_addons:*:*:*:*:*:*:*:*

HashThemes Easy Elementor Addons β€” Critical CSRF Vulnerability

The HashThemes Easy Elementor Addons WordPress plugin through version 2.3.7 is affected by a critical cross-site request forgery vulnerability (CVE-2026-28164, CVSS 9.6) that allows attackers to perform unauthorized actions by tricking authenticated users into submitting malicious requests. The high severity rating suggests the CSRF can be leveraged to carry out significant privileged operations on affected WordPress sites. Administrators running Easy Elementor Addons should update to a patched version as soon as one is available and consult the Patchstack advisory for interim mitigation guidance.

Vendor Advisory


🟠 [HIGH] libgit2/libgit2

1 CVE | CVSS 3.1: 7.5 | AAS 10.6

  • cpe:2.3:a:libgit2:libgit2:*:*:*:*:*:*:*:*

libgit2 β€” Out-of-Bounds Read via Malicious Git Server

libgit2 versions prior to 1.8.6 and 1.9.5 are affected by a high-severity vulnerability (CVE-2026-53587, CVSS 7.5) where a malicious Git server can trigger an out-of-bounds read in the smart-protocol packet line parser by sending a crafted capability buffer shorter than expected. Proof-of-concept exploit code is publicly available, and any application embedding libgit2 for Git operations over the network is potentially affected, including developer tools, CI/CD systems, and language bindings such as rugged and pygit2. Developers and platform operators using libgit2 should upgrade to version 1.8.6 or 1.9.5 immediately and review the referenced commit for details on the fix.

Vendor Advisory


🟠 [HIGH] unstructured-io/unstructured

1 CVE | CVSS 3.1: 9.3 | AAS 10.6

  • cpe:2.3:a:unstructured-io:unstructured:*:*:*:*:*:*:*:* (>= 0.4.7, < 0.24.0)

Unstructured β€” Critical Server-Side Request Forgery in Document Ingestion

The Unstructured document processing library versions 0.4.7 through 0.23.x are affected by a critical SSRF vulnerability (CVE-2026-71428, CVSS 9.3) in which the URL argument to partition, partition_html, and partition_md functions is fetched without host validation, allowing attackers to force server-side ingestion services to request internal or loopback addresses. This is particularly dangerous for organizations exposing Unstructured as a backend document ingestion service in AI and data pipelines, as it can be leveraged to access internal network resources, cloud metadata endpoints, and other sensitive services. Upgrade to Unstructured version 0.24.0 or later immediately, and audit any exposed ingestion endpoints for signs of unauthorized internal requests.

Vendor Advisory


🟠 [HIGH] centrifugal/centrifugo

1 CVE | CVSS 3.1: 9.1 | AAS 10.5

  • cpe:2.3:a:centrifugal:centrifugo:*:*:*:*:*:*:*:* (< 6.9.0)

Centrifugo β€” Critical Header Injection via Client-Controlled Request Headers

Centrifugo versions prior to 6.9.0 are affected by a critical vulnerability (CVE-2026-71485, CVSS 9.1) in which client-controlled connection request headers are insufficiently validated before being forwarded as trusted headers or metadata to backend services via HTTP and gRPC proxy paths. An attacker can exploit this to inject or spoof allowlisted headers, potentially bypassing authentication or authorization checks on downstream backend services that trust Centrifugo-forwarded headers. Organizations using Centrifugo for real-time messaging should upgrade to version 6.9.0 immediately and review backend trust assumptions around headers received from the Centrifugo proxy layer.

Vendor Advisory


🟠 [HIGH] libevent/libevent

2 CVEs | CVSS 4.0: 9.2 | AAS 10.5

  • cpe:2.3:a:libevent:libevent:*:*:*:*:*:*:*:*

libevent β€” Critical HTTP Request Smuggling via Transfer-Encoding Parsing Flaws

libevent versions prior to 2.1.13 and 2.2.2-alpha are affected by 2 high-severity vulnerabilities (max CVSS 9.2) in the evhttp parser, including multiple flaws in the handling of duplicate Transfer-Encoding headers, comma-separated encoding values, and bare line feeds in chunked framing. These inconsistencies enable HTTP request smuggling attacks against any application using libevent’s built-in HTTP server, potentially allowing attackers to bypass security controls, poison caches, or hijack other users’ requests. Given libevent’s widespread use as an embedded HTTP library across numerous applications and infrastructure components, teams should identify all software dependencies on libevent and upgrade to version 2.1.13 or 2.2.2-alpha or later as soon as possible.

Vendor Advisory


🟠 [HIGH] microsoft/microsoft_exchange_online

1 CVE | CVSS 3.1: 10.0 | AAS 10.3

  • cpe:2.3:a:microsoft:microsoft_exchange_online:*:*:*:*:*:*:*:*

Microsoft Exchange Online β€” Critical SSRF Enabling Privilege Escalation

Microsoft Exchange Online is affected by a critical server-side request forgery vulnerability (CVE-2026-65801, CVSS 10.0) that allows an unauthorized attacker to elevate privileges over the network without authentication. The maximum possible CVSS score reflects the severity of this flaw, which could allow attackers to compromise Exchange Online environments and potentially pivot to other connected Microsoft cloud services. As Exchange Online is a cloud-managed service, Microsoft is responsible for applying the fix, but organizations should consult the MSRC advisory to confirm remediation status, review audit logs for suspicious activity, and assess whether any compensating controls such as conditional access policies should be tightened in the interim.

Vendor Advisory


🟠 [HIGH] microsoft/azure_managed_instance_for_apache_cassandra

1 CVE | CVSS 3.1: 10.0 | AAS 10.3

  • cpe:2.3:a:microsoft:azure_managed_instance_for_apache_cassandra:*:*:*:*:*:*:*:*

Microsoft Azure Managed Instance for Apache Cassandra β€” Critical Unauthenticated Remote Code Execution

Azure Managed Instance for Apache Cassandra is affected by a critical argument injection vulnerability (CVE-2026-65770, CVSS 10.0) that allows an unauthorized attacker to execute arbitrary code over the network by exploiting improper neutralization of command argument delimiters. The maximum CVSS score and lack of authentication requirements make this an exceptionally high-risk flaw for any organization using this managed database service. As this is a Microsoft-managed cloud service, customers should consult the MSRC advisory to verify that remediation has been applied to their instances, review database access logs for signs of unauthorized activity, and ensure network access to Cassandra endpoints is restricted to trusted sources only.

Vendor Advisory


🟠 [HIGH] repute_infosystems/bookingpress_appointment_booking_pro

1 CVE | CVSS 3.1: 9.3 | AAS 10.3

  • cpe:2.3:a:repute_infosystems:bookingpress_appointment_booking_pro:*:*:*:*:*:*:*:*

BookingPress Appointment Booking Pro β€” Critical Unauthenticated SQL Injection

The BookingPress Appointment Booking Pro WordPress plugin version 6.0.2 and earlier is affected by a critical unauthenticated SQL injection vulnerability (CVE-2026-68566, CVSS 9.3) that allows remote attackers to interact directly with the WordPress database without any authentication. Successful exploitation could lead to extraction of sensitive data including user credentials, booking records, and payment information, or further compromise of the underlying WordPress installation. WordPress administrators using BookingPress Appointment Booking Pro should update to a patched version immediately and audit their databases for signs of unauthorized access or data exfiltration. Consult the Patchstack advisory for additional details.

Vendor Advisory


🟠 [HIGH] evershopcommerce/evershop

1 CVE | CVSS 4.0: 9.3 | AAS 10.2

  • cpe:2.3:a:evershopcommerce:evershop:*:*:*:*:*:*:*:*

EverShop β€” Critical Unauthenticated Customer Account Takeover

EverShop e-commerce platform is affected by a critical vulnerability (CVE-2026-72843, CVSS 9.3) in which the customer update API route is misconfigured as public, bypassing all authentication and session middleware. An unauthenticated attacker who knows or can enumerate customer UUIDs can modify any customer record, including resetting passwords, effectively enabling full account takeover across the platform. Organizations running EverShop should check the project’s GitHub repository for a patched release immediately, and in the interim consider restricting public access to the customer update API endpoint at the network or reverse proxy level.

Vendor Advisory


🟠 [HIGH] wpeverest/user_registration_&_membership_pro

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:wpeverest:user_registration_membership_pro:*:*:*:*:*:*:*:*

WPEverest User Registration & Membership Pro β€” Critical Unauthenticated Account Takeover

The User Registration & Membership Pro WordPress plugin by WPEverest version 5.4.5 and earlier is affected by a critical broken authentication vulnerability (CVE-2026-74001, CVSS 9.8) that allows unauthenticated attackers to take over user accounts, potentially including administrator accounts, without valid credentials. This flaw is especially dangerous on membership and e-commerce sites where the plugin manages user access, roles, and sensitive personal data. WordPress administrators using this plugin should update to a patched version immediately and review user account activity for any unauthorized access or privilege changes. See the Patchstack advisory for full details.

Vendor Advisory