Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 20 August 2026
RSS1117 vulnerabilities published on 20 August 2026
Severity:
Azure Arc lets attacker gain higher privileges
CVE-2026-69555
The Azure Arc service, which links on‑premises and cloud resources, has a flaw that could let an unauthorized user increase their access rights across the network. This could allow the attacker to vie...
10.0
Azure Arc lets attackers gain higher permissions
CVE-2026-65816
Azure Arc, the tool that links on‑premise resources to Azure, has a flaw that could let an outsider raise their access level across the network. This could expose sensitive data or allow changes to sy...
10.0
Azure Managed Cassandra can let attackers run code remotely
CVE-2026-65770
The Azure Managed Instance for Apache Cassandra does not properly handle special characters in commands, which could let an unauthorized user send crafted requests and cause the system to run their co...
10.0
Microsoft Entra ID can let attackers run code remotely
CVE-2026-69836
Microsoft Entra ID can process data that an attacker controls, which could let them run their own programs on your system over the network. This could give an unauthorized user the ability to take act...
10.0
Microsoft Exchange Online lets attackers gain higher access
CVE-2026-65801
The cloud email service Microsoft Exchange Online can be tricked into contacting internal systems, allowing an outsider to raise their access level. This could let an attacker see or change sensitive ...
10.0
IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 let logged‑in attackers run commands
CVE-2026-18835
If someone who already has a user account on these IBM server operating systems sends specially crafted input, they can cause the system to run any command they choose. This could let an attacker take...
9.9
Azure SQL Database lets authorized users gain higher rights
CVE-2026-68782
A flaw in Azure SQL Database could let someone who already has access use crafted database commands to raise their permission level across the network. This could let them view or change data they sho...
9.9
Microsoft Fabric can let attackers gain higher access
CVE-2026-63509
Microsoft Fabric may allow a person who already has some access to move to a higher level of control across your network. This could let the attacker view or change sensitive information. Install the ...
9.9
Azure Active Directory may let attackers gain higher access
CVE-2026-69851
Azure Active Directory can be tricked into making internal network requests, allowing a user with limited rights to increase their privileges. This could let an attacker move beyond their original per...
9.9
Azure SQL Database lets authorized user gain higher rights
CVE-2026-68789
A flaw in Azure SQL Database could let someone who already has access run specially crafted queries to boost their permissions. This could allow them to view or change data they shouldn’t. Apply the l...
9.9
Multicloud Operators Subscription lets tenant deploy any resource
CVE-2026-67567
The Multicloud Operators Subscription component lets a user who can create HelmRelease objects run Helm charts with high‑privilege permissions. Because the system does not check what the chart contain...
9.9
Comfast CF-N1-S router web setup can be crashed remotely
CVE-2026-77148
The web‑based management interface on Comfast CF‑N1‑S routers (firmware version 2.6.0.1) has a coding mistake that can let an attacker send specially crafted data and overflow the device’s memory. Thi...
8.6
Comfast CF-N1-S router remote code risk via SSID setting
CVE-2026-77022
The wireless router model Comfast CF-N1-S can be attacked from the network by sending a specially crafted Wi‑Fi name (SSID) to its configuration page. This triggers a memory error that could let an at...
8.6
Warehouse Cargo theme lets attackers upload files
CVE-2026-74018
The Warehouse Cargo theme for WordPress, up through version 2.6.9, can be tricked into accepting any file an attacker provides. This could let a malicious file be placed on your website, potentially g...
9.9
Smart Cleaning theme can let strangers add files
CVE-2026-74016
The WordPress theme called Smart Cleaning, up through version 4.8.6, allows a user with basic permissions to upload any type of file to the site. An attacker could place harmful files on your server, ...
9.9
WordPress IT Residence theme allows attackers to upload files
CVE-2026-74014
The IT Residence theme for WordPress, up through version 3.2.1, lets anyone with a basic user account place any file onto the website. This could let a malicious person add harmful code, steal data, o...
9.9
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVE-2026-73992
9.9
SPIP before 4.4.20 lets attackers run code
CVE-2026-77647
DEBIAN-CVE-2026-77647
Websites using SPIP versions older than 4.4.20 can be accessed by anyone on the internet who can then cause the server to run their own programs. This happens because the software misinterprets certai...
9.8
EverShop allows anyone to hijack customer accounts
CVE-2026-72843
EverShop’s API for updating a customer record does not check who is making the request. Anyone who knows a customer’s identifier can send a request that changes the email address and password, giving ...
9.3
IBM AIX and PowerVM VIOS could let attackers run code remotely
CVE-2026-18832
The AIX operating system versions 7.2 and 7.3, and the PowerVM VIOS version 4.1, contain a flaw that lets a remote attacker send crafted data to cause the system to execute unwanted code. This could l...
9.8
IBM AIX and PowerVM VIOS could let attackers run code
CVE-2026-17436
Versions of IBM AIX (7.2 and 7.3) and PowerVM VIOS 4.1 contain a flaw where specially crafted data can overflow memory and let an outsider execute their own programs on the server. This could give a r...
9.8
IBM AIX and PowerVM VIOS could let remote code run
CVE-2026-17160
Versions of IBM AIX (7.2 and 7.3) and PowerVM VIOS 4.1 have a flaw that could let someone on the network run their own programs on the server. This happens because the software miscalculates a size va...
9.8
IBM AIX and PowerVM VIOS let attackers run code remotely
CVE-2026-17157
Versions of IBM AIX (7.2 and 7.3) and PowerVM VIOS (4.1) contain a coding error that could let a remote attacker run any program on the server. This could give the attacker full control of the system....
9.8
IBM AIX and PowerVM VIOS could let remote code run
CVE-2026-17152
Versions of IBM AIX (7.2 and 7.3) and PowerVM VIOS 4.1 contain a flaw that lets specially crafted data overflow memory and run the attacker’s own programs from outside the network. If exploited, an at...
9.8
IBM AIX and PowerVM VIOS let attackers run commands remotely
CVE-2026-17142
The IBM AIX operating system (versions 7.2 and 7.3) and the IBM PowerVM Virtual I/O Server version 4.1 have a weakness that could let someone on the network execute any command they choose. This could...
9.8