TrueConf Server Code Injection Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.0Security Advisory

TL;DR πŸ“Œ

  • TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
  • Highest CVSS: 9.0 (Critical).
  • Listed in CISA KEV (2026-08-20) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-72530.

What it is

CVE-2026-72530 is a code injection vulnerability in TrueConf Server. An attacker with network access to port 4307/TCP can submit a specially crafted script that breaks out of the server’s isolated execution environment and runs arbitrary code on the underlying host.

[]

TrueConf Server Missing Authentication for Critical Function Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.8Security Advisory

TL;DR πŸ“Œ

  • TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-20) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-72529.

What it is

CVE-2026-72529 is a missing authentication for critical function vulnerability in TrueConf Server. A critical function is reachable over the network on port 4307/TCP without any authentication check.

[]

MLflow Server-Side Request Forgery Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.3Security Advisory

TL;DR πŸ“Œ

  • MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
  • Highest CVSS: 9.3 (Critical).
  • Listed in CISA KEV (2026-08-19) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-64849.

What it is

CVE-2026-64849 is a server-side request forgery (SSRF) vulnerability in MLflow. The CVSS vector indicates the flaw is reachable over the network, requires no authentication and no user interaction, and can be exploited with low attack complexity.

[]

Apple macOS Improper Authentication Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.8Security Advisory

TL;DR πŸ“Œ

  • Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-65400.

What it is

CVE-2026-65400 is an improper authentication flaw in macOS Screen Sharing. The vulnerability allows an attacker on the network to authenticate to Screen Sharing without supplying valid credentials.

[]

Broadcom VMware vCenter Path Traversal Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.8Security Advisory

TL;DR πŸ“Œ

  • Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-59310.

What it is

CVE-2026-59310 is a path traversal vulnerability in Broadcom VMware vCenter. It has a CVSS score of 9.8 (Critical), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H β€” meaning it is reachable over the network, requires low attack complexity, needs no privileges and no user interaction, and results in full compromise of confidentiality, integrity and availability.

[]

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.8Security Advisory

TL;DR πŸ“Œ

  • Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-33824.

What it is

CVE-2026-33824 is a double free vulnerability in Microsoft’s Internet Key Exchange (IKE) Service Extensions. The IKE service handles key negotiation for IPsec, and on Windows this typically runs as part of the IKE/AuthIP IPsec Keying Modules service, which listens on the network to negotiate security associations with peers.

[]

Microsoft SharePoint Weak Authentication Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.1Security Advisory

TL;DR πŸ“Œ

  • Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
  • Highest CVSS: 9.1 (Critical).
  • Listed in CISA KEV (2026-08-18) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-55040.

What it is

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

[]

Ray-Project Ray Code Injection Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.4Security Advisory

TL;DR πŸ“Œ

  • Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
  • Highest CVSS: 9.4 (Critical).
  • Listed in CISA KEV (2026-08-18) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2025-62593.

What it is

Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.

[]

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

🚨SEVERITY: HIGH β€” CVSS 8.6Security Advisory

TL;DR πŸ“Œ

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
  • Highest CVSS: 8.6 (High).
  • Listed in CISA KEV (2026-08-11) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-20349.

What it is

CVE-2026-20349 is a heap inspection vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). The flaw sits in the code handling heap memory on affected devices.

[]

Metabase SQL Injection Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 10.0Security Advisory

TL;DR πŸ“Œ

  • Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export…
  • Highest CVSS: 10.0 (Critical).
  • Listed in CISA KEV (2026-08-11) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-72898.

What it is

CVE-2026-72898 is a SQL injection vulnerability in Metabase. An unauthenticated remote attacker can inject arbitrary SQL into the Metabase application database over the network, with no user interaction required.

[]