VulnSea

Daily digest

Thursday 6 August 2026

A busier-than-usual day with 181 new CVEs (recent average about 120). Severity skewed high: 29 critical and 73 high, 56% of the total. 7 arrived with exploitation evidence or public exploit code already attached. Microsoft was the most-affected vendor with 15.

181
New CVEs
29
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 12 that matter most of the 181 published.

CVE-2026-65400Critical· 9.8CISA KEVPoC
1mo ago

An authentication issue was addressed with improved state management

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to…

Hadalapple · macosEPSS 10%via NVD
CVE-2026-53976Critical· 9.1PoC
1mo ago

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorksp…

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorksp…

AbyssalEPSS 1.9%via NVD
CVE-2026-7867High· 7.8PoC
1mo ago

A flaw was found in udisks2

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker…

MidnightRed Hat · udisksEPSS 0.18%via NVD
CVE-2026-70638High· 7.8PoC
1mo ago

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflo…

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflo…

Midnightggml · llama.cppEPSS 0.21%via NVD
CVE-2026-67622Critical· 9.9
1mo ago

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary crede…

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary crede…

Midnightflowiseai · flowiseEPSS 0.32%via NVD
CVE-2026-65667Critical· 10.0
1mo ago

Microsoft Teams Elevation of Privilege Vulnerability

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft TeamsEPSS 0.62%via CVEORG
CVE-2026-63508Critical· 10.0
1mo ago

Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft Planetary Computer Pro (GeoCatalog)EPSS 0.53%via CVEORG
CVE-2026-62830Critical· 9.9
1mo ago

Azure SRE Agent Elevation of Privilege Vulnerability

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure SRE AgentEPSS 0.52%via CVEORG
CVE-2026-59115Critical· 9.9
1mo ago

Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft Entra Provisioning ServiceEPSS 0.77%via CVEORG
CVE-2026-50515Critical· 9.9
1mo ago

Azure Service Bus Remote Code Execution Vulnerability

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

MidnightMicrosoft · Azure Service BusEPSS 1.1%via CVEORG
CVE-2026-50481Critical· 9.9
1mo ago

Azure Active Directory Elevation of Privilege Vulnerability

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure Active DirectoryEPSS 0.56%via CVEORG
CVE-2026-48086Critical· 9.9
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-u…

MidnightEPSS 0.33%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…88
  • CVE-2026-47928ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user53
  • CVE-2026-47932ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current u…49

Most-affected vendors

By CVEs published in the period.