Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 August 2026
RSS843 vulnerabilities published on 21 August 2026
Severity:
Wasmtime lets Windows device files with superscript digits be accessed
JLSEC-2026-1348
On Windows, Wasmtime’s file protection stops regular device names like COM1, but it forgets to block names that use superscript numbers (e.g., COM¹). This allows untrusted WebAssembly code that can re...
7.9
Xinference may let attackers run code on server via chat API
CVE-2026-61539
GHSA-x2rj-828p-hx9m
The Xinference service processes chat requests and, in its default setup, runs a piece of code that can interpret text as a program. An attacker who can send specially crafted chat prompts can cause t...
10.0
Azure SQL Database may let attackers gain higher access
CVE-2026-69502
A flaw in Azure SQL Database could let an outside attacker trick the system into making network requests on its behalf. This can allow the attacker to increase their permissions and access more data t...
10.0
Phalcon Volt templates can run attacker code
CVE-2026-59989
GHSA-hrwp-4hh9-c8r8
If a website uses Phalcon's Volt template engine and allows users to influence the text passed to the join filter, the engine can insert that text directly into generated PHP code. This lets an attack...
9.9
JSONata library can execute arbitrary code via crafted expression
CVE-2026-77413
GHSA-8gq3-vp5j-2grp
Versions of the JSONata library older than 2.2.0 and 1.8.8 allow specially formed expressions to run any code on the server. An attacker who can supply a JSONata expression could execute commands, pot...
9.9
Wasmtime Winch backend on aarch64 can read host memory
JLSEC-2026-1361
If you run Wasmtime with the optional Winch compiler on aarch64, a specially crafted WebAssembly program could read or write memory outside its safe area, potentially exposing or corrupting data on th...
9.4
Nezha Terminal/File Manager Session Hijacking via WebSocket
GHSA-q6xx-5vr8-p898
CVE-2026-62283
GO-2026-5821
Nezha's terminal and file manager features have a security flaw that allows an attacker to take control of a session on a remote server. This can happen if an attacker learns the ID of a live session ...
9.9
Athena queries can expose Neptune connector Lambda settings
CVE-2026-77810
GHSA-v7c2-5wfg-qg44
If you let users run Athena federated queries against Neptune, they could see internal details of the Lambda function that runs the connector. This could reveal configuration information that should s...
9.4
Security update for incus
CVE-2026-63125
DEBIAN-CVE-2026-63125
UBUNTU-CVE-2026-63125
GHSA-6rqx-22hc-qm36
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Incus client can be tricked to write files as root
DEBIAN-CVE-2026-48769
UBUNTU-CVE-2026-48769
GHSA-f6m5-xw2g-xc4x
CVE-2026-48769
If an Incus server pulls an image from an untrusted source, a malicious image server can send special instructions that cause Incus to create a file anywhere on the host, letting an attacker run comma...
9.9
Incus backup function can overwrite any file on server
CVE-2026-48755
GO-2026-5808
DEBIAN-CVE-2026-48755
UBUNTU-CVE-2026-48755
Incus lets users pick a program to compress backup data, but it only verifies the first word of the command. Extra options are not checked, so an attacker can add commands that cause the system to wri...
9.9
Incus containers can let attackers read or write host files
DEBIAN-CVE-2026-48749
UBUNTU-CVE-2026-48749
GO-2026-5798
GHSA-2q3f-q5pq-g8wv
Incus may accept a specially crafted container image that includes a symbolic link pointing to the host's file system. This lets an attacker read sensitive files like password data or create/modify fi...
9.9
Security update for incus
CVE-2026-63343
GHSA-fmjx-5j3g-997p
DEBIAN-CVE-2026-63343
UBUNTU-CVE-2026-63343
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Incus containers can write files to host system
DEBIAN-CVE-2026-48750
UBUNTU-CVE-2026-48750
CVE-2026-48750
GHSA-73hr-m85f-64v9
Incus lets a container specify where command output is saved. If a container tricks Incus into using a symbolic link, it can place files anywhere on the host, such as the system's cron directory, and ...
9.9
Incus lets restricted projects run any command
DEBIAN-CVE-2026-48751
UBUNTU-CVE-2026-48751
GHSA-48q5-w887-33wv
GO-2026-5799
Incus snapshots ignore a setting that should block low-level container hooks, so a user can craft a snapshot that runs their own code on the host server. When the snapshot is moved into a restricted p...
9.9
Security update for incus
CVE-2026-62940
DEBIAN-CVE-2026-62940
UBUNTU-CVE-2026-62940
GHSA-qw5c-v953-38gw
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Incus S3 upload can write files anywhere
DEBIAN-CVE-2026-48753
UBUNTU-CVE-2026-48753
CVE-2026-48753
GHSA-ccjc-4qc3-jxqc
Incus's S3-compatible upload feature lets attackers trick the system into creating files in any location by using specially crafted path names. This could let a malicious user place scripts that run a...
9.9
Security update for incus
CVE-2026-62867
GHSA-q7xw-r4w2-2wcm
DEBIAN-CVE-2026-62867
UBUNTU-CVE-2026-62867
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Security update for incus
CVE-2026-62941
DEBIAN-CVE-2026-62941
GHSA-mq9x-prm8-3vpw
UBUNTU-CVE-2026-62941
A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details.
9.9
Incus lets attackers read and change host files
DEBIAN-CVE-2026-48752
UBUNTU-CVE-2026-48752
GO-2026-5803
CVE-2026-48752
Incus can be tricked with a specially crafted container image or backup to follow a hidden link that points to any folder on the server. This lets an attacker view or overwrite files on the host, pote...
9.9
Comfast CF-N1-S router allows remote command execution
CVE-2026-77683
The CF-N1-S device’s web configuration page can be tricked into running any command the attacker provides. This can be done over the network without needing physical access, potentially letting attack...
8.6
GeoTools lets attackers run SQL via jsonArrayContains
CVE-2026-76904
GHSA-mqjf-5f49-2fjh
The GeoTools library can insert untrusted data into database queries when using the jsonArrayContains function with PostGIS version 12 or newer. This could let an attacker execute any SQL commands on ...
9.8
Linux kernel IPv6 routing can reuse released network path
DEBIAN-CVE-2026-74581
CVE-2026-74581
BELL-CVE-2026-74581
UBUNTU-CVE-2026-74581
A bug in the Linux kernel's IPv6 routing code could cause the system to use an outdated network route that has already been released. This can lead to unexpected network behavior or crashes. Updating ...
9.8
SPIP versions before 4.4.21 let attackers run code
CVE-2026-77806
DEBIAN-CVE-2026-77806
Websites using SPIP older than version 4.4.21 can be tricked by anyone on the internet into running unwanted programs on the server. The problem comes from a special HTTP header that the software does...
9.8
Automation Web Platform up to 4.8.6 lets attackers log in without password
CVE-2026-77264
The Automation Web Platform for WordPress (including the Notifications and OTP for WooCommerce and Advanced Country Code extensions) can reveal a secret login token when anyone requests a one‑time pas...
9.8