Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 26 August 2026

RSS

741 vulnerabilities published on 26 August 2026

Severity:
KubePi lets anyone change login settings and hijack accounts
CVE-2026-65956 GHSA-wjrh-4j52-c664
The KubePi dashboard (versions up to 1.6.15) lets users who are not administrators modify the single‑sign‑on configuration and view user details. This can let a malicious person take over an admin acc...
10.0
UniFi Talk lets network attacker run commands
CVE-2026-77554
The UniFi Talk application does not properly check data it receives, so someone on the same network could trick it into running commands on the server. This could let an attacker take control of the d...
10.0
UniFi OS devices let network attacker skip login
CVE-2026-77550
Some UniFi OS devices can be tricked by a user on the same network to bypass the login screen. This means an attacker could gain access without proper credentials. Apply the latest firmware updates fr...
10.0
UniFi Protect lets network attacker run commands
CVE-2026-77537
The UniFi Protect software does not properly check data it receives from the network. An attacker who can reach the network can trick it into executing commands on the server, potentially taking contr...
10.0
NebulaGraph lets anyone read and change its settings
CVE-2026-81032
NebulaGraph runs a web service that shows all of its current configuration and lets anyone change those settings without needing a password. This means an attacker could view sensitive paths, turn off...
9.9
UniFi Access app lets low‑privilege network user gain admin rights
CVE-2026-77553
The UniFi Access software on your network can be tricked by someone with only basic access to take control of the whole system. This means a user with limited rights could become an administrator and ...
9.9
UniFi Protect lets low‑privilege network users run commands
CVE-2026-77548
The UniFi Protect application does not properly check data it receives, allowing someone on the same network with limited rights to run unauthorized commands on the server. This could let an attacker ...
9.9
UniFi Access app could let attackers run commands
CVE-2026-77543
The UniFi Access application does not properly check user input, so someone on the network with limited access can send specially crafted data that makes the system run arbitrary commands. This could ...
9.9
UniFi OS devices let low‑level users gain admin rights
CVE-2026-77536
Some UniFi OS devices do not properly check who can do what, so a person who only has basic network access could trick the system into giving themselves higher privileges. This could let them control ...
9.9
UniFi OS devices let network user gain admin rights
CVE-2026-77534
A flaw in certain UniFi OS devices lets someone who is already on your network and has only basic permissions take control of the device as an administrator. This can lead to full access to the device...
9.9
UniFi Protect lets low‑privilege network user run commands
CVE-2026-77533
Someone with only basic network access can trick the UniFi Protect software into running commands on the server it runs on. This could let an attacker take control of the device or disrupt its operati...
9.9
Smart-web2 1.3.1 backend report module can run any SQL
CVE-2026-75334
The reporting feature in Smart-web2 version 1.3.1 lets a user supply a text string that is stored and later executed directly against the database. An attacker could insert their own commands to read,...
9.8
DocSys Master 2.02.85 can let attackers upload any file
CVE-2026-75327
The part of DocSys that lets users add pictures to markdown documents does not check what kind of file is being uploaded. This allows a malicious user to place a script or other dangerous file on the ...
9.8
MCMS web page can let attackers run database commands
CVE-2026-68000
The MCMS content management system (versions up to 6.2.0) includes a web page that takes a size value and inserts it straight into a database query. By sending a crafted value, an attacker can make th...
9.8
Gitea can execute attacker commands via malicious patch
CVE-2026-60004
If someone can write to a repository in Gitea, they could upload a specially crafted change that places a script on the server and runs commands with the same rights as the Gitea service. This could l...
9.8 KEV
Stomper messaging server can crash from crafted client messages
CVE-2026-26448 UBUNTU-CVE-2026-26448
If a client sends several connection requests over the same network link and later another client tries to send messages to a destination that was previously set up, the server may try to use memory t...
9.8
Denx U-Boot may let attackers run code or crash system
UBUNTU-CVE-2025-70293 CVE-2025-70293
The boot loader software called Denx U‑Boot, versions before the 2026.04 release, does not correctly check the size of a data table when reading an EXT‑4 file system. This mistake can cause the progra...
9.8
Denx U‑Boot can crash or be hijacked by crafted ZFS data
CVE-2025-70290 UBUNTU-CVE-2025-70290
If your devices use Denx U‑Boot (versions before the 2026.04 release) and boot from a ZFS‑formatted storage, specially crafted disk data can cause the boot loader to miscalculate memory needs. This mi...
9.8
DWSurvey 6.14.0 allows attackers to skip login
CVE-2026-75325
The DWSurvey version 6.14.0 web tool can be tricked into granting access without proper login through certain web addresses. This could let unauthorized users view or change survey data. Apply the lat...
9.8
Bird Home Automation D1101V-F allows unauthorized access
UBUNTU-CVE-2023-42179 CVE-2023-42179
The D1101V-F controller from Bird Home Automation does not correctly verify passwords, meaning someone could bypass the login process and gain control of the device. This could let an attacker change ...
9.8
ILIAS allows unauthenticated user to execute code via logout
CVE-2026-80428
The ILIAS learning platform’s logout URL can be called by anyone, even without logging in. When it runs, it automatically converts stored session information into live objects without validation, lett...
9.3
SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authori...
GHSA-jrw6-7x4q-w25j CVE-2026-54569
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-...
9.8
Ceph can cause Linux kernel crash when handling file updates
DEBIAN-CVE-2026-80528 CVE-2026-80528 UBUNTU-CVE-2026-80528
A bug in the Ceph storage client could confuse the Linux file system’s bookkeeping, leading the entire system to stop (a kernel crash). This can happen when Ceph and a typical Linux file system (such ...
9.8
Linux kernel MPTCP may mishandle certain option combinations
DEBIAN-CVE-2026-80587 CVE-2026-80587 UBUNTU-CVE-2026-80587
The Linux operating system's network code could accept conflicting settings when using Multipath TCP, which might cause unexpected behavior or crashes. This primarily affects servers that use advanced...
9.8
Linux kernel can free disk while timer still running
DEBIAN-CVE-2026-80589 CVE-2026-80589 UBUNTU-CVE-2026-80589
A bug in the Linux kernel could cause the system to release a disk that was never fully added, leaving an internal timer still active. This can lead to the system trying to use memory that has already...
9.8