Daily digest
Friday 7 August 2026
114 new CVEs this day, in line with the recent average. Of those, 11 critical and 38 high. 12 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. sonatype was the most-affected vendor with 10.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 12 that matter most of the 114 published.
CVE-2026-61808Critical· 9.8PoCLightRAG provides simple and fast retrieval-augmented generation
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to rea…
CVE-2026-19264Critical· 9.8PoCPostiz is an open-source social media scheduling tool
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that direct…
CVE-2026-47243Critical· 9.2PoCKata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root t…
CVE-2026-71851Critical· 9.0PoCcrypto-js is a JavaScript library of crypto standards
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded …
CVE-2026-56162Critical· 10.0Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-19195High· 7.8PoCA vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack ne…
CVE-2026-19193High· 7.8PoCA flaw has been found in Jiangmin Antivirus 21
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to…
CVE-2022-4995Critical· 9.8Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request …
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request …
CVE-2026-62295High· 7.5PoCHAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arra…
CVE-2026-50540Critical· 9.6Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalida…
CVE-2026-46409Critical· 9.6OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without ser…
GHSA-wg23-69c2-gjc8CriticalCraft CMS: Passkey login accepts replayed WebAuthn assertions
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-8037OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…kev, exploited98
- CVE-2026-48939A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.epss83
Most-affected vendors
By CVEs published in the period.