| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-65770 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | Microsoft | Azure Managed Instance for Apache Cassandra | Critical | 10.0 | 2026-08-20 21:47:06 | Deep Dive |
| CVE-2026-69836 KEV | Microsoft Entra ID Remote Code Execution Vulnerability | Microsoft | Microsoft Entra | Critical | 10.0 | 2026-08-20 21:43:13 | Deep Dive |
| CVE-2026-69851 | Microsoft Entra ID Elevation of Privilege Vulnerability | Microsoft | Microsoft Entra | Critical | 9.9 | 2026-08-20 21:43:12 | Deep Dive |
| CVE-2026-68789 | Azure SQL Database Elevation of Privilege Vulnerability | Microsoft | Azure SQL Database | Critical | 9.9 | 2026-08-20 21:43:11 | Deep Dive |
| CVE-2026-65801 | Microsoft Exchange Online Elevation of Privilege Vulnerability | Microsoft | Microsoft Exchange Online | Critical | 10.0 | 2026-08-20 21:43:11 | Deep Dive |
| CVE-2026-62834 | Azure Data Factory Elevation of Privilege Vulnerability | Microsoft | Azure Data Factory | Critical | 9.3 | 2026-08-20 21:43:10 | Deep Dive |
| CVE-2026-55769 🧪 | CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path` | cloudnative-pg | cloudnative-pg | Critical | 9.4 | 2026-08-20 21:41:51 | Deep Dive |
| CVE-2026-71485 🧪 | Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends | centrifugal | centrifugo | Critical | 9.1 | 2026-08-20 21:01:01 | Deep Dive |
| CVE-2026-67567 | Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.11 | Critical | 9.9 | 2026-08-20 20:34:10 | Deep Dive |
| CVE-2026-19586 | Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways | TP-Link Systems Inc. | ER7212PC v2 | Critical | 9.3 | 2026-08-20 18:32:07 | Deep Dive |
| CVE-2026-77148 🧪 | Comfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow | Comfast | CF-N1-S | Critical | 9.9 | 2026-08-20 18:15:09 | Deep Dive |
| CVE-2026-2334 🧪 | ) Missing Server-Side File Extension Validation in vsDesk | vsDesk | vsDesk | Critical | 9.4 | 2026-08-20 18:03:39 | Deep Dive |
| CVE-2026-63385 🧪 | Libevent: HTTP header handling bugs create risk of access control bypass. | libevent | libevent | Critical | 9.2 | 2026-08-20 17:55:36 | Deep Dive |
| CVE-2026-63382 🧪 | libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling | libevent | libevent | Critical | 9.2 | 2026-08-20 17:51:15 | Deep Dive |
| CVE-2026-73253 | Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching | cesanta | mongoose | Critical | 9.1 | 2026-08-20 17:41:02 | Deep Dive |
| CVE-2026-73256 | Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE | cesanta | mongoose | Critical | 9.1 | 2026-08-20 17:37:55 | Deep Dive |
| CVE-2026-73251 | Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification | cesanta | mongoose | Critical | 9.3 | 2026-08-20 17:34:50 | Deep Dive |
| CVE-2026-73257 | Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling | cesanta | mongoose | Critical | 9.1 | 2026-08-20 17:30:58 | Deep Dive |
| CVE-2026-53424 | Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions | dropbox | samly | Critical | 9.1 | 2026-08-20 17:27:11 | Deep Dive |
| CVE-2026-77022 🧪 | Comfast CF-N1-S SSID Configuration mbox-config sub_44B438 stack-based overflow | Comfast | CF-N1-S | Critical | 9.9 | 2026-08-20 16:45:07 | Deep Dive |