VulnSea

Daily digest

Wednesday 12 August 2026

188 new CVEs this day, in line with the recent average. Of those, 25 critical and 63 high. 7 arrived with exploitation evidence or public exploit code already attached. apache was the most-affected vendor with 13.

188
New CVEs
25
Critical
0
KEV additions
4
Records changed

New this day, ranked by depth score

The 12 that matter most of the 188 published.

CVE-2026-42018High· 7.5CISA KEVPoC
1mo ago

Anonymous user token generation exposure in JFrog Artifactory

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Abyssaljfrog · artifactoryEPSS 11%via CVEORG
CVE-2026-63297Critical· 9.9PoC
1mo ago

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a tar…

Abyssalcanonical · lxdEPSS 0.24%via NVD
CVE-2026-73296Critical· 9.4PoC
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed…

AbyssalEPSS 2.9%via NVD
CVE-2026-73292High· 8.3PoC
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-pa…

Midnightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.23%via NVD
CVE-2026-73299Critical· 10.0
1mo ago

Prompty is a markdown file format (.prompty) for LLM prompts

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controll…

Midnightmicrosoft · promptyEPSS 1.2%via NVD
CVE-2026-73294Critical· 9.9
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/projec…

Midnightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.57%via NVD
CVE-2026-73269Critical· 9.9
1mo ago

A flaw was found in the cluster-curator-controller component

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to…

MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.33%via NVD
CVE-2026-73268Critical· 9.9
1mo ago

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE)

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the Cre…

MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.47%via NVD
CVE-2026-73263Critical· 9.9
1mo ago

Prowler is a cloud security platform

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_au…

MidnightEPSS 0.35%via NVD
CVE-2026-66898Critical· 9.9
1mo ago

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names c…

Midnightcanonical · lxdEPSS 0.43%via NVD
CVE-2026-63300Critical· 9.9
1mo ago

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…

Midnightcanonical · lxdEPSS 0.36%via NVD
CVE-2026-63299Critical· 9.9
1mo ago

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove f…

Midnightcanonical · lxdEPSS 0.40%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-61447PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement67
  • CVE-2026-61459MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…66
  • CVE-2026-61876LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup61
  • CVE-2026-3576The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.054

Most-affected vendors

By CVEs published in the period.