Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 21 August 2026

RSS

843 vulnerabilities published on 21 August 2026

Severity:
Wasmtime lets Windows device files with superscript digits be accessed
JLSEC-2026-1348
On Windows, Wasmtime’s file protection stops regular device names like COM1, but it forgets to block names that use superscript numbers (e.g., COM¹). This allows untrusted WebAssembly code that can re...
7.9
Xinference may let attackers run code on server via chat API
CVE-2026-61539 GHSA-x2rj-828p-hx9m
The Xinference service processes chat requests and, in its default setup, runs a piece of code that can interpret text as a program. An attacker who can send specially crafted chat prompts can cause t...
10.0
Azure SQL Database may let attackers gain higher access
CVE-2026-69502
A flaw in Azure SQL Database could let an outside attacker trick the system into making network requests on its behalf. This can allow the attacker to increase their permissions and access more data t...
10.0
Phalcon Volt templates can run attacker code
CVE-2026-59989 GHSA-hrwp-4hh9-c8r8
If a website uses Phalcon's Volt template engine and allows users to influence the text passed to the join filter, the engine can insert that text directly into generated PHP code. This lets an attack...
9.9
JSONata library can execute arbitrary code via crafted expression
CVE-2026-77413 GHSA-8gq3-vp5j-2grp
Versions of the JSONata library older than 2.2.0 and 1.8.8 allow specially formed expressions to run any code on the server. An attacker who can supply a JSONata expression could execute commands, pot...
9.9
Wasmtime Winch backend on aarch64 can read host memory
JLSEC-2026-1361
If you run Wasmtime with the optional Winch compiler on aarch64, a specially crafted WebAssembly program could read or write memory outside its safe area, potentially exposing or corrupting data on th...
9.4
Nezha Terminal/File Manager Session Hijacking via WebSocket
GHSA-q6xx-5vr8-p898 CVE-2026-62283 GO-2026-5821
Nezha's terminal and file manager features have a security flaw that allows an attacker to take control of a session on a remote server. This can happen if an attacker learns the ID of a live session ...
9.9
Athena queries can expose Neptune connector Lambda settings
CVE-2026-77810 GHSA-v7c2-5wfg-qg44
If you let users run Athena federated queries against Neptune, they could see internal details of the Lambda function that runs the connector. This could reveal configuration information that should s...
9.4
Security update for incus
CVE-2026-63125 DEBIAN-CVE-2026-63125 UBUNTU-CVE-2026-63125 GHSA-6rqx-22hc-qm36
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Incus client can be tricked to write files as root
DEBIAN-CVE-2026-48769 UBUNTU-CVE-2026-48769 GHSA-f6m5-xw2g-xc4x CVE-2026-48769
If an Incus server pulls an image from an untrusted source, a malicious image server can send special instructions that cause Incus to create a file anywhere on the host, letting an attacker run comma...
9.9
Incus backup function can overwrite any file on server
CVE-2026-48755 GO-2026-5808 DEBIAN-CVE-2026-48755 UBUNTU-CVE-2026-48755
Incus lets users pick a program to compress backup data, but it only verifies the first word of the command. Extra options are not checked, so an attacker can add commands that cause the system to wri...
9.9
Incus containers can let attackers read or write host files
DEBIAN-CVE-2026-48749 UBUNTU-CVE-2026-48749 GO-2026-5798 GHSA-2q3f-q5pq-g8wv
Incus may accept a specially crafted container image that includes a symbolic link pointing to the host's file system. This lets an attacker read sensitive files like password data or create/modify fi...
9.9
Security update for incus
CVE-2026-63343 GHSA-fmjx-5j3g-997p DEBIAN-CVE-2026-63343 UBUNTU-CVE-2026-63343
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Incus containers can write files to host system
DEBIAN-CVE-2026-48750 UBUNTU-CVE-2026-48750 CVE-2026-48750 GHSA-73hr-m85f-64v9
Incus lets a container specify where command output is saved. If a container tricks Incus into using a symbolic link, it can place files anywhere on the host, such as the system's cron directory, and ...
9.9
Incus lets restricted projects run any command
DEBIAN-CVE-2026-48751 UBUNTU-CVE-2026-48751 GHSA-48q5-w887-33wv GO-2026-5799
Incus snapshots ignore a setting that should block low-level container hooks, so a user can craft a snapshot that runs their own code on the host server. When the snapshot is moved into a restricted p...
9.9
Security update for incus
CVE-2026-62940 DEBIAN-CVE-2026-62940 UBUNTU-CVE-2026-62940 GHSA-qw5c-v953-38gw
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Incus S3 upload can write files anywhere
DEBIAN-CVE-2026-48753 UBUNTU-CVE-2026-48753 CVE-2026-48753 GHSA-ccjc-4qc3-jxqc
Incus's S3-compatible upload feature lets attackers trick the system into creating files in any location by using specially crafted path names. This could let a malicious user place scripts that run a...
9.9
Security update for incus
CVE-2026-62867 GHSA-q7xw-r4w2-2wcm DEBIAN-CVE-2026-62867 UBUNTU-CVE-2026-62867
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Security update for incus
CVE-2026-62941 DEBIAN-CVE-2026-62941 GHSA-mq9x-prm8-3vpw UBUNTU-CVE-2026-62941
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Incus lets attackers read and change host files
DEBIAN-CVE-2026-48752 UBUNTU-CVE-2026-48752 GO-2026-5803 CVE-2026-48752
Incus can be tricked with a specially crafted container image or backup to follow a hidden link that points to any folder on the server. This lets an attacker view or overwrite files on the host, pote...
9.9
Comfast CF-N1-S router allows remote command execution
CVE-2026-77683
The CF-N1-S device’s web configuration page can be tricked into running any command the attacker provides. This can be done over the network without needing physical access, potentially letting attack...
8.6
GeoTools lets attackers run SQL via jsonArrayContains
CVE-2026-76904 GHSA-mqjf-5f49-2fjh
The GeoTools library can insert untrusted data into database queries when using the jsonArrayContains function with PostGIS version 12 or newer. This could let an attacker execute any SQL commands on ...
9.8
Linux kernel IPv6 routing can reuse released network path
DEBIAN-CVE-2026-74581 CVE-2026-74581 BELL-CVE-2026-74581 UBUNTU-CVE-2026-74581
A bug in the Linux kernel's IPv6 routing code could cause the system to use an outdated network route that has already been released. This can lead to unexpected network behavior or crashes. Updating ...
9.8
SPIP versions before 4.4.21 let attackers run code
CVE-2026-77806 DEBIAN-CVE-2026-77806
Websites using SPIP older than version 4.4.21 can be tricked by anyone on the internet into running unwanted programs on the server. The problem comes from a special HTTP header that the software does...
9.8
Automation Web Platform up to 4.8.6 lets attackers log in without password
CVE-2026-77264
The Automation Web Platform for WordPress (including the Notifications and OTP for WooCommerce and Advanced Country Code extensions) can reveal a secret login token when anyone requests a one‑time pas...
9.8