| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-81673 | Multiple Vulnerabilities in TOOOLS' iSquad | TOOOLS | iSquad | Critical | 9.3 | 2026-08-27 12:05:45 | Deep Dive |
| CVE-2026-81672 | Multiple Vulnerabilities in TOOOLS' iSquad | TOOOLS | iSquad | Critical | 9.3 | 2026-08-27 11:53:35 | Deep Dive |
| CVE-2026-74233 | Zbtlink MQWrt infosrvd Command Injection | Zbtlink | WE1326 | Critical | 9.8 | 2026-08-27 10:40:11 | Deep Dive |
| CVE-2026-74232 | Zbtlink MQWrt yunmgrd Cloud C2 Implant | Zbtlink | L3_V2_8 | Critical | 9.8 | 2026-08-27 10:39:14 | Deep Dive |
| CVE-2026-78292 | WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability | hashthemes | Hash Form | Critical | 9.8 | 2026-08-27 09:00:05 | Deep Dive |
| CVE-2026-78288 | WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability | Jonathan de Jong | Beautiful Taxonomy Filters | Critical | 9.3 | 2026-08-27 09:00:03 | Deep Dive |
| CVE-2026-78286 | WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability | INFINITUM FORM | Geo Controller | Critical | 9.8 | 2026-08-27 09:00:03 | Deep Dive |
| CVE-2026-78274 | WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerability | WP Manage Ninja | Fluent Boards Pro | Critical | 9.1 | 2026-08-27 08:59:58 | Deep Dive |
| CVE-2026-78260 | WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability | ePayco | Epayco | Critical | 9.3 | 2026-08-27 08:59:55 | Deep Dive |
| CVE-2026-32566 | WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability | ACPT | ACPT (Pro) - Custom Post Types Plugin for WordPress | Critical | 9.8 | 2026-08-27 08:59:54 | Deep Dive |
| CVE-2026-32479 | WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Injection vulnerability | CODEPRESS IT Solutions LLC | Visitor Traffic Real Time Statistics Pro | Critical | 9.3 | 2026-08-27 08:59:51 | Deep Dive |
| CVE-2026-59354 | Spring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadata | VMware by Broadcom | Spring Security (OAuth2 Authorization Server module) | Critical | 9.6 | 2026-08-27 06:33:03 | Deep Dive |
| CVE-2026-77991 | Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 | joomlaeventmanager.net | JEM - Joomla Event Manager extension for Joomla | Critical | 9.4 | 2026-08-27 05:50:14 | Deep Dive |
| CVE-2026-59270 | Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces | Spring | Spring Security | Critical | 9.4 | 2026-08-27 05:20:33 | Deep Dive |
| CVE-2026-65956 🧪 | KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF | 1Panel-dev | KubePi | Critical | 10.0 | 2026-08-26 22:40:56 | Deep Dive |
| CVE-2026-65641 | Veeam one 授权问题漏洞 | Veeam | One | Critical | 9.3 | 2026-08-26 21:21:41 | Deep Dive |
| CVE-2026-60004 KEV 🧪 💣 | Gitea 代码注入漏洞 EPSS 0.87 | Gitea | Gitea | Critical | 9.8 | 2026-08-26 19:45:00 | Deep Dive |
| CVE-2026-70419 | Dell Cloud Disaster Recovery 命令注入漏洞 | Dell | Cloud Disaster Recovery | Critical | 9.1 | 2026-08-26 18:24:28 | Deep Dive |
| CVE-2026-19485 | Bucket Squatting in Vertex AI Search for Commerce | Google Cloud | Vertex AI Search for Commerce | Critical | 9.3 | 2026-08-26 18:06:01 | Deep Dive |
| CVE-2026-81032 🧪 | NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration | vesoft-inc | nebula | Critical | 9.8 | 2026-08-26 15:45:00 | Deep Dive |