CVE ID :CVE-2026-71193 Published : Aug. 12, 2026, 11:17 p.m. | 54 minutes ago Description :In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to…
CVE-2026-49481 – UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd
CVE ID :CVE-2026-49481 Published : Aug. 12, 2026, 11:17 p.m. | 54 minutes ago Description :UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability…
CVE-2026-73519 – WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
CVE ID :CVE-2026-73519 Published : Aug. 12, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant…
CVE-2026-73501 – kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
CVE ID :CVE-2026-73501 Published : Aug. 12, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces…
CVE-2026-73500 – etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
CVE ID :CVE-2026-73500 Published : Aug. 12, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33,…
CVE-2026-6484 – Lack of verified boot to certain FV may cause arbitrary code execution
CVE ID :CVE-2026-6484 Published : Aug. 12, 2026, 1:17 a.m. | 44 minutes ago Description :In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution. Severity: 8.2 |…
CVE-2026-70398 – Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace
CVE ID :CVE-2026-70398 Published : Aug. 12, 2026, 1:10 a.m. | 51 minutes ago Description :A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows…
CVE-2026-72526 – Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation
CVE ID :CVE-2026-72526 Published : Aug. 12, 2026, 1:10 a.m. | 51 minutes ago Description :A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an…
CVE-2026-73248 – calibre: Bypass of Python template restrictions via nested `template()` leading to RCE
CVE ID :CVE-2026-73248 Published : Aug. 11, 2026, 10:19 p.m. | 1 hour, 42 minutes ago Description :calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB,…
CVE-2026-73247 – Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
CVE ID :CVE-2026-73247 Published : Aug. 11, 2026, 10:19 p.m. | 1 hour, 42 minutes ago Description :Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra’s core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri…