Daily digest
Thursday 20 August 2026
207 new CVEs this day, in line with the recent average. Of those, 21 critical and 61 high. 10 arrived with exploitation evidence or public exploit code already attached. Microsoft was the most-affected vendor with 21.
New this day, ranked by depth score
The 12 that matter most of the 207 published.
CVE-2026-77647Critical· 9.8⚠ ExploitedPoCSPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases suc…
CVE-2026-18294High· 7.80dayOriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction i…
CVE-2026-18293High· 7.80dayOriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction…
CVE-2026-69836Critical· 10.0PoCMicrosoft Entra ID Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
CVE-2026-15686High· 7.20dayAdminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to ex…
CVE-2026-63382Critical· 9.2PoCLibevent is an event notification library
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in…
CVE-2026-73040High· 8.8PoCDockge validates a stack name only on the write path
Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.serv…
CVE-2026-63383High· 8.7PoCLibevent is an event notification library
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates u…
CVE-2026-69851Critical· 9.9Microsoft Entra ID Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVE-2026-69555Critical· 10.0Azure Arc Elevation of Privilege Vulnerability
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-68789Critical· 9.9Azure SQL Database Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVE-2026-68782Critical· 9.9Azure SQL Database Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-64849mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …epss75
- CVE-2026-20896Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.epss66
- CVE-2020-1102A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application packageepss61
- CVE-2020-0901A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memoryepss55
- CVE-2020-1023A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application packageepss49
- CVE-2020-1024A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application packageepss49
- CVE-2020-1069A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controlsepss49
- CVE-2020-1117A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memoryepss49
Most-affected vendors
By CVEs published in the period.