🛡️ 每日安全情报
🛡️ AI 安全情报日报 · 2026-08-30
_2026-08-30 · 共筛出 198 条 ≥4★_
1. -CVE-2018-0834-aab-aar exploit 🔓 ★★★★★
📋 Exploit for CVE-2018-0834. CVSS 9.3.
2. AVBypass exploit 🔓 ★★★★★
📋 Exploit.
3. Android-PIN-Bruteforce exploit 🔓 ★★★★★
📋 Exploit.
4. Better-CVE-2022-29464 exploit 🔓 ★★★★★
📋 Exploit for CVE-2022-29464. CVSS 10.
5. Burp_Collector exploit 🔓 ★★★★★
📋 Exploit.
6. C4 exploit 🔓 ★★★★★
📋 Exploit.
7. CANToolz exploit 🔓 ★★★★★
📋 Exploit.
8. CVE-2014-0226-poc exploit 🔓 ★★★★★
📋 Exploit for CVE-2014-0226. CVSS 6.8.
9. CVE-2016-2098 exploit 🔓 ★★★★★
📋 Exploit for CVE-2016-2098. CVSS 7.5.
10. CVE-2019-10685 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-10685. CVSS 6.1.
11. CVE-2019-11043 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-11043. CVSS 9.8.
12. CVE-2019-11581 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-11581. CVSS 9.8.
13. CVE-2020-0601_PoC exploit 🔓 ★★★★★
📋 Exploit for CVE-2020-0601. CVSS 8.1.
14. CVE-2020-17527-Tomcat exploit 🔓 ★★★★★
📋 Exploit for CVE-2020-17527. CVSS 7.5.
15. CVE-2020-2038 exploit 🔓 ★★★★★
📋 Exploit for CVE-2020-2038. CVSS 9.
---
其他 183 条:
- CVE-2020-29599 exploit (5★)
- CVE-2020-29607 exploit (5★)
- CVE-2021-21972-vCenter-6.5-7.0-RCE-POC exploit (5★)
- CVE-2021-24917 exploit (5★)
- CVE-2021-3129-piperpwn exploit (5★)
- CVE-2021-3156 exploit (5★)
- CVE-2021-41773 exploit (5★)
- CVE-2021-43326_Exploit (5★)
- CVE-2021-46073 exploit (5★)
- CVE-2022-0847 exploit (5★)
- CVE-2022-1388 exploit (5★)
- CVE-2022-1597 exploit (5★)
- CVE-2022-21661 exploit (5★)
- CVE-2022-22954-PoC exploit (5★)
- CVE-2022-29303 exploit (5★)
- CVE-2022-30190 exploit (5★)
- CVE-2022-34718-PoC exploit (5★)
- CVE-2022-41445 exploit (5★)
- CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC exploit (5★)
- CVE-2022-46395 exploit (5★)
- CVE-2023-21716 exploit (5★)
- CVE-2023-30765 exploit (5★)
- CVE-2023-32117 exploit (5★)
- CVE-2023-34599 exploit (5★)
- CVE-2023-38041-POC exploit (5★)
- CVE-2023-44487 exploit (5★)
- CVE-2023-46604 exploit (5★)
- CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ exploit (5★)
- CVE-2024-0012-poc exploit (5★)
- CVE-2024-0311 exploit (5★)
- CVE-2024-24919_POC exploit (5★)
- CVE-2024-27348 exploit (5★)
- CVE-2024-2961-Remote-File-Read exploit (5★)
- CVE-2024-3661VPN exploit (5★)
- CVE-2024-39929 exploit (5★)
- CVE-2024-4956 exploit (5★)
- CVE-2024-52317 exploit (5★)
- CVE-2024-57175 exploit (5★)
- CVE-2025-0411-MoTW-PoC exploit (5★)
- CVE-2025-24354-PoC exploit (5★)
- CVE-2025-24801 exploit (5★)
- CVE-2025-32433.py exploit (5★)
- CVE-2025-4802-Proof-of-Concept exploit (5★)
- CVE-2025-59528-PoC exploit (5★)
- CVE-2025-7461 exploit (5★)
- CVE-2026-24061 exploit (5★)
- CVE-2026-29000 exploit (5★)
- CVE-2026-38165-SSTI- exploit (5★)
- CVE-2026-44578-PoC exploit (5★)
- ClientInspectorV2 exploit (5★)
- DGA-Detection exploit (5★)
- DeepSleep exploit (5★)
- DevicePairedTool exploit (5★)
- DigiDuck-Framework exploit (5★)
- Disk-Arbitrator exploit (5★)
- DuplicateDump exploit (5★)
- Exploit for CVE-2026-12243 (5★)
- Exploit for CVE-2026-1357 (5★)
- Exploit for CVE-2026-81578 (5★)
- Exploit for CVE-2026-82286 (5★)
- Exploit for Improper Access Control in Oracle Http_Server (5★)
- Exploit for Incorrect Authorization in Heinlein Opencloud_Reva (5★)
- Exploit-Win32.CVE-2012-0158.F.doc (5★)
- FACT_core exploit (5★)
- FalconEye exploit (5★)
- Fiber exploit (5★)
- GG-AESY exploit (5★)
- HTB Nimbus渗透测试靶机 Writeup (5★)
- Insta-Crawler exploit (5★)
- KerberosRun exploit (5★)
- Klyda exploit (5★)
- KrbRelay exploit (5★)
- LFISuite exploit (5★)
- Log4j-Scanner-Exploit (5★)
- MifareClassicTool exploit (5★)
- NetCrackPi exploit (5★)
- OMLASP exploit (5★)
- OneRuleToRuleThemStill exploit (5★)
- OpenAttack exploit (5★)
- PEzor-Docker exploit (5★)
- PPLcontrol exploit (5★)
- PS-2018-002---CVE-2018-14442 exploit (5★)
- PenCrawLer exploit (5★)
- Phisher-man exploit (5★)
- PrintNightmare exploit (5★)
- Puwr exploit (5★)
- Py-RDP-Patcher exploit (5★)
- RedbloodC2 exploit (5★)
- Remote-Desktop-Caching- exploit (5★)
- Rubeus exploit (5★)
- Sandbox-Escape-iOS-18.0-26.0 exploit (5★)
- SecureForce exploit (5★)
- SharpUp exploit (5★)
- Sharperner exploit (5★)
- SwishDbgExt exploit (5★)
- TangledWinExec exploit (5★)
- VULNERAVEL-CVE-2018-14847---CREDENCIAIS-EXTRAIDAS exploit (5★)
- WHP exploit (5★)
- WP-GDPR-Compliance-Plugin-Exploit (5★)
- WdToggle exploit (5★)
- Web--Vulnerability-scanner exploit (5★)
- XXEinjector exploit (5★)
- XXRF-Shots exploit (5★)
- XposedFridaBridge exploit (5★)
- ZimbraExploit (5★)
- adversarial-robustness-toolbox exploit (5★)
- airborn-IOS-CVE-2025-24252 exploit (5★)
- authelia exploit (5★)
- capsulecorp-pentest exploit (5★)
- chapcrack exploit (5★)
- cli exploit (5★)
- clusterd exploit (5★)
- custom-bytecode-analyzer exploit (5★)
- cve-2019-6453-poc exploit (5★)
- cve-2020-16012 exploit (5★)
- cve-2021-29442-Nacos-Derby-rce-exp exploit (5★)
- cybersecurity-lab exploit (5★)
- dark-fantasy-hack-tool exploit (5★)
- dawgmon exploit (5★)
- dolos_cloak exploit (5★)
- dropengine exploit (5★)
- eLabFTW-1.8.5-EntityController-Arbitrary-File-Upload-RCE exploit (5★)
- evildork exploit (5★)
- exploitgym-eval (5★)
- expluatation_CVE-2022-29078 exploit (5★)
- extended-ssrf-search exploit (5★)
- falla exploit (5★)
- fetchfox exploit (5★)
- fhex exploit (5★)
- fleet exploit (5★)
- fses exploit (5★)
- ghidra2frida exploit (5★)
- hm-surf exploit (5★)
- houndsploit exploit (5★)
- iCUE_DllHijack_LPE-CVE-2024-22002 exploit (5★)
- json-sanitizer exploit (5★)
- kubescape exploit (5★)
- laf exploit (5★)
- laforge exploit (5★)
- lightbulb-framework exploit (5★)
- link exploit (5★)
- linux-4.19.72_CVE-2020-14381 exploit (5★)
- litmus exploit (5★)
- loboguara exploit (5★)
- log4j-CVE-2021-44228-Public-IoCs exploit (5★)
- magento2-template-filter-patch exploit (5★)
- miniOrange SAML SSO 存在严重漏洞,攻击者可接管 WordPress 管理员帐户 (5★)
- net-Shield exploit (5★)
- nex-forms_SQL-Injection-CVE-2023-2114 exploit (5★)
- o365-attack-toolkit exploit (5★)
- oathkeeper exploit (5★)
- opensshenum exploit (5★)
- p-invoke.net exploit (5★)
- platform_packages_providers_MediaProvider_CVE-2023-40127 exploit (5★)
- poc-CVE-2026-0073 exploit (5★)
- protobuf-inspector exploit (5★)
- punk.py exploit (5★)
- py3webfuzz exploit (5★)
- pymeta exploit (5★)
- r3con1z3r exploit (5★)
- red-detector exploit (5★)
- s3-account-search exploit (5★)
- sparta exploit (5★)
- spring4shell_victim exploit (5★)
- stringsifter exploit (5★)
- twifo-cli exploit (5★)
- twitter-advanced-search exploit (5★)
- uberscan exploit (5★)
- vajra exploit (5★)
- vulpy exploit (5★)
- watermarks-remover exploit (5★)
- web-wordlist-generator exploit (5★)
- wordlistctl exploit (5★)
- 【安全圈】ServiceNow曝3个满分10分漏洞可未授权RCE (5★)
- 【安全圈】ZBT路由器曝出厂双后门可未授权获Root权限 (5★)
- 【安全圈】宇树人形机器人曝Root漏洞可蓝牙近场劫持 (5★)
- AI 没有逃出沙箱,它只是用了我们主动给它的能力 (4★)
- Anthropic 将发招股书,预计募资 1300 亿美元超越 SpaceX;腾讯发布 HY4 preview 模型;科隆游戏展多个展位失窃 | 极客早知道 (4★)
- OpenAI 官宣断供 Cursor,点名马斯克是主要原因 (4★)
- 从Data到Agent:华为云AI-Ready数据基础设施全链路能力亮相数博会 (4★)
- 关停五年后,虾米被阿里用AI“复活”了 (4★)
- 突发,OpenAI彻底断供Cursor (4★)
- 腾讯的战略是混元4?WorkBuddy?AI token 工厂? (4★)
🚨 漏洞预警
🔴 CRITICAL · 59 条
1. CVE-2026-81578 🔥 `CVSS 8.8`
🎯 受影响:An improper access control vulnerability exists in the web management interface of PaperCut MF and P
📋 简介:An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81578
- https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
- https://sploitus.com/exploit?id=859BB400-2781-524F-B7D2-5BDBFD5082AE&utm_source=rss&utm_medium=rss
- https://sploitus.com/exploit?id=22CCF182-BE84-5BBC-B569-DA25837A73B7&utm_source=rss&utm_medium=rss
2. CVE-2021-21972 🔥 ⚡近期活跃 `CVSS 10.0`
🎯 受影响:The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin
📋 简介:The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2021-21972
- http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html
- http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html
- https://www.vmware.com/security/advisories/VMSA-2021-0002.html
3. CVE-2026-82266 `CVSS 9.8`
🎯 受影响:Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t
📋 简介:Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82266
- https://github.com/redpanda-data/redpanda/issues/30989
- https://github.com/redpanda-data/redpanda
- https://github.com/redpanda-data/redpanda/blob/3cfce474a872090e7c74d14181885f5838c54cf2/conf/redpanda.yaml
- https://github.com/redpanda-data/redpanda/blob/3cfce474a872090e7c74d14181885f5838c54cf2/src/v/security/request_auth.cc
4. CVE-2026-82448 `CVSS 9.8`
🎯 受影响:Shinobi
📋 简介:Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82448
- https://gitlab.com/Shinobi-Systems/Shinobi/-/merge_requests/554
- https://gitlab.com/Shinobi-Systems/Shinobi/-/commit/5a76c74f3977661ff3f9fd55a260db352c0b19c0
- https://gitlab.com/Shinobi-Systems/Shinobi
- https://gitlab.com/Shinobi-Systems/Shinobi/-/blob/f04e685b8bd4c6190fcd62993131b86a76c2b806/libs/childNode/utils.js
5. CVE-2021-29442 🔥 ⚡近期活跃 `CVSS 8.6`
🎯 受影响:Nacos
📋 简介:Nacos is a platform designed for dynamic service discovery and configuration and service management.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2021-29442
- https://github.com/advisories/GHSA-36hp-jr8h-556f
- https://github.com/alibaba/nacos/issues/4463
- https://github.com/alibaba/nacos/pull/4517
- https://github.com/advisories/GHSA-36hp-jr8h-556f
6. CVE-2026-82456 `CVSS 10`
🎯 受影响:argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions withou
📋 简介:argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82456
- https://github.com/argoproj-labs/mcp-for-argocd/security/advisories/GHSA-rp45-5x3v-48mr
- https://github.com/argoproj-labs/mcp-for-argocd
- https://www.vulncheck.com/advisories/argocd-mcp-0.8.0-authentication-bypass-via-unauthenticated-http
7. CVE-2026-3627 `CVSS 9.1`
🎯 受影响:IBM Concert 1.0.0 through 2.3.1
📋 简介:IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection.
🔗 参考:
8. CVE-2026-82286 🔥 `CVSS 8.8`
🎯 受影响:gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint
📋 简介:gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82286
- https://github.com/BuilderIO/gpt-crawler/issues/418
- https://github.com/BuilderIO/gpt-crawler
- https://github.com/BuilderIO/gpt-crawler/blob/d2245d66a5ad60bf227a55c849135394cbecc9b5/src/core.ts
- https://github.com/BuilderIO/gpt-crawler/blob/d2245d66a5ad60bf227a55c849135394cbecc9b5/src/config.ts
9. CVE-2026-82017 `CVSS 8.6`
🎯 受影响:IGEL OS 12
📋 简介:IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the s...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82017
- https://kb.igel.com/en/security-safety/current/isn-2026-19-code-execution-via-boot-registry
- https://blog.amberwolf.com/blog/2026/august/thin-client-thin-crypto-overview/
- https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Darren%20McDonald%20-%20Thin%20Client%20Thin%20Crypto%20-%20Bypassing%20Full-Desk%20Encryption%20Across%20Three%20Major%20Thin%20Clients%20Vendors%20without%20Breaking%20a%20Ci.pdf
- https://github.com/AmberWolfCyber/DEFCON34-ThinClientThinCrypto/blob/main/scripts/igel/inject_bootreg.py
10. CVE-2026-82283 `CVSS 8.6`
🎯 受影响:VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing a
📋 简介:VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82283
- https://github.com/VoltAgent/voltagent/issues/1371
- https://github.com/VoltAgent/voltagent
- https://github.com/VoltAgent/voltagent/blob/44b4c8e4998ce56095b2f0e4eaf1a988f5e6d0de/packages/server-core/src/handlers/memory.handlers.ts
- https://www.vulncheck.com/advisories/voltagent-memory-api-handlers-missing-ownership-checks
11. CVE-2026-54745 `CVSS 10`
🎯 受影响:Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows.
📋 简介:Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54745
- https://github.com/kubeflow/pipelines/security/advisories/GHSA-gqww-5pj5-8fq7
- https://github.com/kubeflow/pipelines/pull/13511
- https://github.com/kubeflow/pipelines/commit/a35f97aa4c17b25572369e5022546ab4421bdbdd
- https://github.com/kubeflow/pipelines/releases/tag/2.17.0
12. CVE-2026-18527 `CVSS 9.9`
🎯 受影响:IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow
📋 简介:IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing.
🔗 参考:
13. CVE-2026-82078 🔥 `CVSS 9.4`
🎯 受影响:An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCu
📋 简介:An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82078
- https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
- https://sploitus.com/exploit?id=859BB400-2781-524F-B7D2-5BDBFD5082AE&utm_source=rss&utm_medium=rss
- https://sploitus.com/exploit?id=22CCF182-BE84-5BBC-B569-DA25837A73B7&utm_source=rss&utm_medium=rss
14. CVE-2026-82291 `CVSS 8.1`
🎯 受影响:HeyForm
📋 简介:HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82291
- https://github.com/heyform/heyform/security/advisories/GHSA-fg7j-rmgr-rc9g
- https://github.com/heyform/heyform/blob/v3.0.0-rc.7/packages/server/src/main.ts
- https://github.com/heyform/heyform/commit/bf9d738ca70ae5641c0c7372982b00365c5144d4
- https://github.com/heyform/heyform
15. CVE-2026-19295 `CVSS 9.9`
🎯 受影响:IBM Langflow OSS 1.0.0 through 1.11.1
📋 简介:IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it.
🔗 参考:
16. CVE-2026-82466 `CVSS 9.4`
🎯 受影响:Rodauth
📋 简介:Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82466
- https://github.com/jeremyevans/rodauth/commit/35d74a9f07b2005a8ea75fc11a6539c04f3c2840
- https://github.com/jeremyevans/rodauth/security/advisories/GHSA-3pvr-v35r-4r75
- https://github.com/jeremyevans/rodauth
- https://www.vulncheck.com/advisories/rodauth-before-2.46.0-authentication-bypass-via-webauthn-login
17. CVE-2026-19286 `CVSS 9.8`
🎯 受影响:IBM Langflow OSS 1.0.0 through 1.11.1 could
📋 简介:IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
🔗 参考:
18. CVE-2026-80600 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
batman-adv: dat: acquire ARP hw source only after skb realloc
The pskb_may_pull() called by batadv_get_vid() could reallocate the buffer
behind the skb.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80600
- https://git.kernel.org/stable/c/a82fc217cb7a447313c76ebf9f09b100771b0ddf
- https://git.kernel.org/stable/c/86aa79b43e5b561fd3648891165bd7313b541315
- https://git.kernel.org/stable/c/d755cd001fa2c248e186c1fc3df3d11d97dc843c
- https://git.kernel.org/stable/c/3404be97b940a9b1ae1aea5fdbc6cdbbe9cd5146
19. CVE-2026-80609 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
qede: fix out-of-bounds check for cqe->len_list[]
Move index check before element access.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80609
- https://git.kernel.org/stable/c/6d203bdd227fca1787f8a80cf84b990936633c5a
- https://git.kernel.org/stable/c/bd3a6a083b408e96437dbd86ff543ba9ec3a788b
- https://git.kernel.org/stable/c/e30af53dca803893a29eb3bbe0539752ba435410
- https://git.kernel.org/stable/c/1aacefd074b5dcc99b8dbcd73e1c963ed5010110
20. CVE-2026-80612 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
net: lwtunnel: Drop skb metadata before LWT encapsulation
skb metadata is meant for passing information between XDP and TC.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80612
- https://git.kernel.org/stable/c/19eec11f3ab5dd29ba58f5f209c24e946c95ef12
- https://git.kernel.org/stable/c/c00320b0e355c4bf0ae4743a53b4180fea237546
21. CVE-2026-80617 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
net: airoha: fix foe_check_time allocation size
foe_check_time is declared as u16 pointer but was allocated with
only ppe_num_entries bytes instead of ppe_num_entries * sizeof(u16).
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80617
- https://git.kernel.org/stable/c/112b5eff24e044561ee9599a0d34e0fcea1df4e0
- https://git.kernel.org/stable/c/9f7cd1e26d2f1766438edc9b9254f2c618f9ae98
- https://git.kernel.org/stable/c/5c121ee635680c93d7074becf14cfbaac140f80d
22. CVE-2026-80630 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
Whenever fq_codel drops packets during peek, it calls
qdisc_tree_reduce_backlog.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80630
- https://git.kernel.org/stable/c/3e515188393e62a718ccebee651ee74514104ff6
- https://git.kernel.org/stable/c/20dd591d8f951e1e6aca5052be8785e6181055e2
- https://git.kernel.org/stable/c/94a5f1efdefb01f82cd228bf4e7ef1e8fc075c80
- https://git.kernel.org/stable/c/acc08a0c7f37ebb1901144e03a7cba7d4afd9203
23. CVE-2026-80634 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
The DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps
inside WARN_ON_ONCE(). num_encaps is u8, so if it's already 0 the
decrem...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80634
- https://git.kernel.org/stable/c/2f55fa28011c97d6495d5787808db10a8c2d690d
- https://git.kernel.org/stable/c/e052f920773b73be49eb4d8702a9f85de7464363
24. CVE-2026-80668 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
This patch replaces the timer API by GC worker approach for
expectations, as it already happened in many other subsystems.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80668
- https://git.kernel.org/stable/c/7ec786f4230c2a9b2eaf97a2d45368933b49d2b2
- https://git.kernel.org/stable/c/b8b09dc2bf35a00d4e0556b5d6308c7b917ebda2
25. CVE-2026-80673 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()
When resolving an attribute lookup with a non-zero @lowest_vcn,
ntfs_external_attr_find() peeks at the next $ATTRIBUTE_LIST entry ...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80673
- https://git.kernel.org/stable/c/44885c9b45eb4082fb7f558590d84bb254a08e94
- https://git.kernel.org/stable/c/344b18f389f9934d59c7b0cf3d20541ea2e0da58
26. CVE-2026-80674 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
ntfs: validate resident attribute lists and harden the validator
A base inode's $ATTRIBUTE_LIST is sanity-checked by load_attribute_list()
only on the non-resident path; ntfs_read_locked_inode() copies a *re...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80674
- https://git.kernel.org/stable/c/55e97648f7753c6097cb682d24d1abcfe878e812
- https://git.kernel.org/stable/c/7d19e1ffee084c4f7d321a360c14ba43404f7cc8
27. CVE-2026-80681 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
vxlan: re-fetch eth header after route_shortcircuit()
Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb).
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80681
- https://git.kernel.org/stable/c/6375093eb45cd7d89f1945f939eeae3b29d79f56
- https://git.kernel.org/stable/c/1b7f7b653e3557690047c62f03b80a24ea5a58a5
- https://git.kernel.org/stable/c/bf045341dfb3e767f0ff94cf240ce3c371973bd4
- https://git.kernel.org/stable/c/2355c8c26d2aa1b4385b369e67202e47d460d555
28. CVE-2026-80694 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
mtk_handle_irq_rx expects a struct mtk_eth * (matching the request_irq
cookie), but mtk_poll_controller incorrectly passed the net...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80694
- https://git.kernel.org/stable/c/3bd58ac9ca0c552651f533c1bd280dd19ae7d4e8
- https://git.kernel.org/stable/c/276f1f180f55d56cf5992a581e20ed2b3dfa6ced
- https://git.kernel.org/stable/c/7eb46318d53940dab63dea7130e720b67a656104
- https://git.kernel.org/stable/c/e095f249e2209674f6366f6db0383a2b96e19239
29. CVE-2026-80714 `CVSS 9.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
ipvs: do not propagate one-packet flag to synced conns
Synced connections can be created before their destination exists.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80714
- https://git.kernel.org/stable/c/06d1d9b56ef8132fbf85006885eb43d9510b8b02
- https://git.kernel.org/stable/c/acbdc276091b308ca7794acb86e761f8203e2f59
- https://git.kernel.org/stable/c/300348e3ba1521b003d59825f97e24f9a6859688
- https://git.kernel.org/stable/c/44af98cc7d5ef8e730488d5df1eecd5deeaa5947
30. CVE-2026-82277 `CVSS 9.8`
🎯 受影响:Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operatio
📋 简介:Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82277
- https://github.com/argoproj/argo-rollouts/issues/4747
- https://github.com/argoproj/argo-rollouts
- https://github.com/argoproj/argo-rollouts/blob/4e6a2798688e22868340d9871a3c8d78371f1568/server/server.go
- https://www.vulncheck.com/advisories/argo-rollouts-dashboard-unauthenticated-mutating-operations
31. CVE-2026-55068 `CVSS 9.3`
🎯 受影响:free5GC
📋 简介:free5GC is an open-source implementation of the 5G core network.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55068
- https://github.com/free5gc/free5gc/security/advisories/GHSA-x8mj-6p3q-g5pp
- https://github.com/free5gc/free5gc/issues/1056
- https://github.com/free5gc/nrf/pull/90
- https://github.com/free5gc/nrf/commit/bda0cf75be5556bb4c758c8b34710f3fe6bbe3ea
32. CVE-2026-55378 `CVSS 9.3`
🎯 受影响:JS Recon
📋 简介:JS Recon is a JavaScript enumeration and SAST tool.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55378
- https://github.com/js-recon/js-recon/security/advisories/GHSA-w9cj-mg3x-qjm4
- https://github.com/js-recon/js-recon/pull/121
- https://github.com/js-recon/js-recon/commit/447876c4bfa9ec5bc98cbc65d7a3e5f889412491
- https://github.com/js-recon/js-recon/releases/tag/v1.3.1-beta.2
33. CVE-2026-80671 `CVSS 9.3`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
register_pid() has several issues when processing untrusted perf.data:
1.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80671
- https://git.kernel.org/stable/c/652cea73b7b7b7c622a2be670e44e3c499c6d49f
- https://git.kernel.org/stable/c/5ea1dcc9418c4e06ce29ed5170596f497ba86872
- https://git.kernel.org/stable/c/5949d339f5ec98752d56dcd4e36f619a59d513a5
34. CVE-2026-80684 `CVSS 9.3`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
The airq_iv_create() can return NULL on failure, but the return value was
never checked.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80684
- https://git.kernel.org/stable/c/96099486b63985801c9c6ef22505e9aa635b2d20
- https://git.kernel.org/stable/c/0a95abe964400771ad82b027d7b84a0d183cd0db
- https://git.kernel.org/stable/c/df947d85e164a50a29d43a96e814f69ab1d0f7ed
- https://git.kernel.org/stable/c/e137d082325bbcae780087b57501d38585e625d9
35. CVE-2026-80693 `CVSS 9.3`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
idpf: bound interrupt-vector register fill to the allocated array
idpf_get_reg_intr_vecs() fills the caller-allocated reg_vals[] array from
the VIRTCHNL2_OP_ALLOC_VECTORS reply in adapter->req_vec_chunks, bo...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80693
- https://git.kernel.org/stable/c/41bb8748124d0d8ee5d8e1eace9dfbc874bc9564
- https://git.kernel.org/stable/c/9f7007ee9858c99aa43101bc8352c672fee85644
36. CVE-2026-82082 `CVSS 9.8`
🎯 受影响:NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remot
📋 简介:NUMail developed by Green-Computing has an OS Command Injection vulnerability.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82082
- https://www.twcert.org.tw/tw/cp-132-11144-45c6a-1.html
- https://www.twcert.org.tw/en/cp-139-11145-5361d-2.html
37. CVE-2026-82329 `CVSS 9.8`
🎯 受影响:JFrog Artifactory
📋 简介:JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82329
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories
- https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
38. CVE-2026-82452 `CVSS 9.8`
🎯 受影响:rust-iot-platform through commit 5df942ab
📋 简介:rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82452
- https://github.com/iot-ecology/rust-iot-platform/blob/5df942ab6bc46a3bf83dbee8c7970554f92c972d/api/src/controller/user_router.rs
- https://github.com/iot-ecology/rust-iot-platform
- https://www.vulncheck.com/advisories/rust-iot-platform-authentication-bypass-via-missing-request-guards
39. CVE-2026-80603 `CVSS 9.1`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
parse_dcc() treats data_end as an inclusive end pointer, but its only
caller passes data_limit = ib_ptr + datalen, which points one past the
l...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80603
- https://git.kernel.org/stable/c/abb8c32b88ea3f46beb68c34fe9a3ac8ed664e7e
- https://git.kernel.org/stable/c/437e0a3854b3a44ec15afa9ab88ec215adf3a2fd
- https://git.kernel.org/stable/c/910c33e4a8c046c3cc1fa5a465a4d41a1bb398f1
- https://git.kernel.org/stable/c/2b70f61f569bb29acb380e6f616a1bbdee15668f
40. CVE-2026-80670 `CVSS 9.1`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
machine__resolve() accesses env->cpu[al->cpu].socket_id after checking
al->cpu >= 0 and env->cpu != NULL, but without validating al->cpu
aga...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80670
- https://git.kernel.org/stable/c/b9e8406651dcc1c19238aad11861a758683525b4
- https://git.kernel.org/stable/c/eb266a14c16a93eb4db7b56a452d6be93f8bdcd4
- https://git.kernel.org/stable/c/5484b43a0ec8231c36fba6ead654cb72dbba8b8f
41. CVE-2026-82454 `CVSS 9.3`
🎯 受影响:The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass i
📋 简介:The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82454
- https://github.com/omnivore-app/omnivore/pull/4652
- https://github.com/omnivore-app/omnivore/commit/abf53d6508755d3d22a994e28e370a9193ea977a
- https://github.com/omnivore-app/omnivore
- https://www.vulncheck.com/advisories/omnivore-before-android-0.227.0-authentication-bypass-via-apple-sign-in
42. CVE-2026-82244 `CVSS 9.4`
🎯 受影响:Budibase
📋 简介:Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82244
- https://github.com/Budibase/budibase/security/advisories/GHSA-gwr2-pgg3-p7xp
- https://www.vulncheck.com/advisories/budibase-before-3.41.3-remote-code-execution-via-plugin-eval
43. CVE-2026-55565 `CVSS 9.9`
🎯 受影响:Yamcs
📋 简介:Yamcs is a mission control framework.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55565
- https://github.com/yamcs/yamcs/security/advisories/GHSA-c64q-hj4j-375f
- https://github.com/yamcs/yamcs/commit/640e1598b7097b521692e89dd47a39b6cb1fc663
- https://github.com/yamcs/yamcs/commit/a8fb4a0693fa62a6eb729b26016d1090dd8b289c
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8
44. CVE-2026-55634 `CVSS 9.9`
🎯 受影响:Pimcore
📋 简介:Pimcore is an Open Source Data & Experience Management Platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55634
- https://github.com/pimcore/pimcore/security/advisories/GHSA-9x44-4gxf-8c25
- https://github.com/pimcore/pimcore/pull/19183
- https://github.com/pimcore/pimcore/commit/a4f8c3cfee58b7d5fe4873d67782eff58dae9b9d
- https://github.com/advisories/GHSA-r2f4-ff2p-xc64
45. CVE-2026-55559 `CVSS 9.8`
🎯 受影响:Yamcs
📋 简介:Yamcs is a mission control framework.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55559
- https://github.com/yamcs/yamcs/security/advisories/GHSA-73mf-m39p-wpm9
- https://github.com/yamcs/yamcs/commit/549f295cf8c5496a5e799d6bec2432ef976c82aa
- https://github.com/yamcs/yamcs/commit/7192da1c49bdf5ab1d72e579a47766a7c43e87c8
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8
46. CVE-2026-78032 `CVSS 9.8`
🎯 受影响:SOY CMS
📋 简介:SOY CMS contains an issue with deserialization of untrusted data.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-78032
- https://saitodev.co/article/7105
- https://jvn.jp/en/jp/JVN04485476/
47. CVE-2026-82460 `CVSS 9.8`
🎯 受影响:Cloud Commander
📋 简介:Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82460
- https://github.com/coderaiser/cloudcmd/issues/474
- https://github.com/coderaiser/cloudcmd/commit/b9bdc9ed528350eeb2f9ef974c18998096fae919
- https://github.com/coderaiser/cloudcmd/releases/tag/v19.20.2
- https://github.com/coderaiser/cloudcmd/blob/v19.20.1/server/root.js
48. CVE-2026-54754 `CVSS 9.6`
🎯 受影响:Klever-Go
📋 简介:Klever-Go is the Go implementation of the Klever blockchain protocol.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54754
- https://github.com/klever-io/klever-go/security/advisories/GHSA-p7gw-2pcp-5pf8
- https://github.com/klever-io/klever-go/commit/8bcc600b0ac88070740c63c7ce1c8a968dd85251
- https://github.com/klever-io/klever-go/releases/tag/v1.7.19
49. CVE-2026-54755 `CVSS 9.6`
🎯 受影响:Klever-Go
📋 简介:Klever-Go is the Go implementation of the Klever blockchain protocol.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54755
- https://github.com/klever-io/klever-go/security/advisories/GHSA-cgc5-v3f2-8m2v
- https://github.com/klever-io/klever-go/commit/8bcc600b0ac88070740c63c7ce1c8a968dd85251
- https://github.com/klever-io/klever-go/releases/tag/v1.7.19
50. CVE-2026-55220 `CVSS 9.3`
🎯 受影响:Pimcore
📋 简介:Pimcore is an Open Source Data & Experience Management Platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55220
- https://github.com/pimcore/pimcore/security/advisories/GHSA-w23p-wrp7-ch38
- https://github.com/pimcore/pimcore/pull/19181
- https://github.com/pimcore/pimcore/commit/b184c01bf11e213e601d965b4e96c8bb7248e980
- https://github.com/pimcore/pimcore/releases/tag/v12.3.10
51. CVE-2026-82090 `CVSS 9.2`
🎯 受影响:Pocket through 8.33.0.0
📋 简介:Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82090
- https://github.com/FUNFACTOR1/pocket-android-xss-0click-cve
52. CVE-2026-18918 `CVSS 9.1`
🎯 受影响:In Eclipse Lyo
📋 简介:In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-18918
- https://github.com/eclipse-lyo/lyo/releases/tag/v6.0.1.Final
- https://github.com/eclipse-lyo/lyo/releases/tag/v7.0.0.Beta3
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/221
53. CVE-2026-42007 `CVSS 9.1`
🎯 受影响:An attacker that has valid credentials can use a Sieve script with the editheader extension to trigg
📋 简介:An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-42007
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0003.json
54. CVE-2026-55247 `CVSS 9.1`
🎯 受影响:plone.app.event provides the event content type for Plone. Prior to
📋 简介:plone.app.event provides the event content type for Plone.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55247
- https://github.com/plone/plone.app.event/security/advisories/GHSA-r82h-mqw3-fc56
- https://github.com/plone/plone.app.event/commit/1e3c83c15a24d1a789cdb012593505bc5620e28e
- https://github.com/plone/plone.app.event/commit/4de5eb3ea9e4f7f1781622e6d64fc086629d1437
- https://github.com/plone/plone.app.event/releases/tag/5.2.4
55. CVE-2026-55248 `CVSS 9.1`
🎯 受影响:plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior t
📋 简介:plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55248
- https://github.com/plone/plone.app.portlets/security/advisories/GHSA-x5g3-w747-2h8q
- https://github.com/plone/plone.app.portlets/commit/09da52ef7b297daa8e0cfd2361e47c37d9b073ad
- https://github.com/plone/plone.app.portlets/commit/9f16b6fb10211916686c6c346ea174bf517e3fbd
- https://github.com/plone/plone.app.portlets/commit/a3b2c2887165b308cd915cbb87b8276f90a76680
56. CVE-2026-55511 `CVSS 9.1`
🎯 受影响:Yamcs
📋 简介:Yamcs is a mission control framework.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55511
- https://github.com/yamcs/yamcs/security/advisories/GHSA-3g44-3m7x-cgg2
- https://github.com/yamcs/yamcs/commit/8c1070b12c0a6c003903325cb2a1013347e2dbde
- https://github.com/yamcs/yamcs/commit/b65a3d78178ba99a58b753feda6ecc3b5a694f13
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8
57. CVE-2026-82281 `CVSS 9.1`
🎯 受影响:Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_con
📋 简介:Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82281
- https://github.com/Cinnamon/kotaemon/issues/846
- https://github.com/Cinnamon/kotaemon
- https://github.com/Cinnamon/kotaemon/blob/9ad3e4e49aa35b8acddd235918a5d9753c1cfdf9/libs/ktem/ktem/pages/chat/control.py
- https://www.vulncheck.com/advisories/kotaemon-missing-ownership-check-in-conversation-functions
58. CVE-2026-40541 `CVSS 9`
🎯 受影响:An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit
📋 简介:An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-se...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-40541
- https://www.synology.com/en-global/security/advisory/Synology_SA_26_10
59. CVE-2026-82021 `CVSS 9`
🎯 受影响:Hermes Agent 0.18.2
📋 简介:Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82021
- https://github.com/NousResearch/hermes-agent/releases/tag/v2026.7.20
- https://github.com/NousResearch/hermes-agent/pull/64463
- https://github.com/NousResearch/hermes-agent/commit/9df5f879b4a5925c0f8f947e7e16ed8e845932c3
- https://www.vulncheck.com/advisories/hermes-agent-mcp-catalog-supply-chain-rce-via-mutable-branch-reference
🟠 HIGH · 10 条
1. CVE-2026-80628 `CVSS 7.8`
🎯 受影响:Linux kernel
📋 简介:In the Linux kernel, the following vulnerability has been resolved:
ALSA: seq: oss: Serialize readq reset state with q->lock
snd_seq_oss_readq_clear() resets qlen, head, and tail without
q->lock even though the normal reader and producer paths serialize the
same ring state u...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-80628
- https://git.kernel.org/stable/c/287d506d4e0865918cec82bb1361f283a08c979b
- https://git.kernel.org/stable/c/43e10709b1ba288bcbabb9b9cb6e518b2a5d8506
- https://git.kernel.org/stable/c/49ce92d207820f588b0406add82f053decfbe5d9
2. CVE-2026-82282 `CVSS 8.8`
🎯 受影响:Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticat
📋 简介:Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82282
- https://github.com/runatlantis/atlantis/issues/6622
- https://github.com/runatlantis/atlantis
- https://github.com/runatlantis/atlantis/blob/12bfa59f44d8f65bfdda132bff61d8f8f29af1d6/server/controllers/github_app_controller.go
- https://github.com/runatlantis/atlantis/blob/12bfa59f44d8f65bfdda132bff61d8f8f29af1d6/server/middleware.go
3. CVE-2026-81517 `CVSS 8.7`
🎯 受影响:An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance m
📋 简介:An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81517
- https://www.mongodb.com/docs/bi-connector/current/release-notes/
4. CVE-2026-55066 `CVSS 7.1`
🎯 受影响:Vikunja
📋 简介:Vikunja is an open-source self-hosted task management platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55066
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-5pg6-m483-7vrg
- https://github.com/go-vikunja/vikunja/pull/3239
- https://github.com/go-vikunja/vikunja/commit/36cdc2ce2be0b8ccc74227d178b92047d59cd65f
- https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0
5. CVE-2026-55848 `CVSS 8.6`
🎯 受影响:mapfish-print
📋 简介:mapfish-print is a component of MapFish for printing templated cartographic maps.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55848
- https://github.com/mapfish/mapfish-print/security/advisories/GHSA-5v29-34h8-v68r
- https://github.com/mapfish/mapfish-print/pull/4212
- https://github.com/mapfish/mapfish-print/pull/4215
- https://github.com/mapfish/mapfish-print/pull/4216
6. CVE-2026-82271 `CVSS 7.1`
🎯 受影响:R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handl
📋 简介:R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82271
- https://github.com/SciPhi-AI/R2R/issues/2292
- https://github.com/SciPhi-AI/R2R
- https://github.com/SciPhi-AI/R2R/blob/9c5a94d151f90876bd7eb860f300a8fd662dc481/py/core/main/api/v3/conversations_router.py
- https://www.vulncheck.com/advisories/r2r-missing-ownership-check-allows-modifying-other-users-conversations
7. CVE-2026-82280 `CVSS 7.1`
🎯 受影响:Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users
📋 简介:Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82280
- https://github.com/QuivrHQ/quivr/issues/3698
- https://github.com/QuivrHQ/quivr
- https://github.com/QuivrHQ/quivr/blob/v0.0.322/backend/api/quivr_api/modules/prompt/controller/prompt_routes.py
- https://www.vulncheck.com/advisories/quivr-prompt-endpoints-missing-ownership-validation
8. CVE-2026-82450 `CVSS 8.8`
🎯 受影响:BookStack
📋 简介:BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82450
- https://github.com/BookStackApp/BookStack/commit/e210cc32e4cbb1efeae5c5c9d0fef8e3c6a752e6
- https://github.com/BookStackApp/BookStack
- https://www.vulncheck.com/advisories/bookstack-before-26.05.4-remote-code-execution-via-book-cover
9. CHROME-87.0.4280.66 🔥 `CVSS 4.3`
🎯 受影响:Chrome 87.0.4280.66 安全更新包含 1 个漏洞,其中最高 CVSS 4.3:Side-channel information leakage in graphics in Googl
📋 简介:Chrome 87.0.4280.66 安全更新包含 1 个漏洞,其中最高 CVSS 4.3:Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cr。涉及 CVE:CVE-2020-16012。
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2020-16012
- https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_28.html
- https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ALEKSEJSPOPOVS-CVE-2020-16012&utm_source=rss&utm_medium=rss
10. CVE-2026-55484 `CVSS 7.5`
🎯 受影响:ALOS HTTP
📋 简介:ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55484
- https://github.com/guno1928/alos-http/security/advisories/GHSA-hr6j-w4mw-g9mj
- https://github.com/guno1928/alos-http/commit/314b6783e19698c85ea9d9b197ff52f7f6a3a374
---
新发现 232 条 · 热度升级 0 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级
📊 GitHub 热榜
📊 GitHub 日榜 · 2026-08-30
📋 Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.
📋 A spy satellite simulator in your browser, except the data is real. Live open source spatial intelligence on a photorealistic 3D globe.
3. K-Dense-AI/scientific-agent-skills
📋 Turn any AI agent into an AI Scientist. The #1 Agent Skills library for science, used by 190,000+ scientists worldwide. 165 ready-to-use validated skills plus 100+ scientific databases covering biology, chemistry, medicine, and drug discovery. Compatible with Cursor, Claude Code, Codex, Pi, Antigravity, and the open Agent Skills standard.
📋 like netcat, but over Tailscale's data plane, without Tailscale's control plane
📋 Open Multi-Agent Interactive Classroom — Get an immersive, multi-agent learning experience in just one click
📋 Fully automatic censorship removal for language models
📋 </> htmx - high power tools for HTML
8. JetBrains/go-modern-guidelines
📋 Help AI coding agents write modern Go
9. ComposioHQ/awesome-claude-skills
📋 A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows
📋 World's first open-source, agentic video production system. 12 production pipelines, 100+ tools, 700+ agent skill and production-knowledge files. Turn your AI coding assistant into a full video production studio.
🤖 AI 总结分析
今日整体形势:高危漏洞预警收录59条CRITICAL,风险偏高。热点集中在访问控制缺失、默认配置暴露与认证绕过,涉及MCP、流数据平台和打印管理;旧漏洞如vCenter、Nacos出现活跃利用迹象,技术趋势明显向AI/Agent相关基础设施蔓延。
漏洞预警中,CVE-2026-82456(argocd-mcp 0.8.0,CVSS 10)最值得警惕:配置ARGOCD_API_TOKEN后HTTP传输仍接受未认证MCP会话,等于把Argo CD编排能力暴露给匿名调用,直接放大Agent供应链风险。CVE-2026-82266(Redpanda 26.2.2,CVSS 9.8)同样高危,Admin API默认绑定0.0.0.0:9644且无需认证,未认证请求被当作超级用户,暴露即可能接管数据平台。此外,CVE-2026-81578(PaperCut MF/NG)访问控制漏洞和近期活跃的CVE-2021-21972(vCenter RCE)提示老漏洞与勒索路径仍在被利用。
安全情报源今日无新增条目,不等于威胁下降,漏洞预警仍是今天的主要风险输入。
GitHub热榜显示Agent技能库集中爆发:K-Dense-AI/scientific-agent-skills宣称超过19万科学家使用、提供165项技能,ComposioHQ/awesome-claude-skills与archify都在扩展AI代理工作流,OpenMAIC提供多智能体课堂。这类工具普遍依赖MCP与外部API,今天argocd-mcp的未认证漏洞恰好说明该扩张可能快于安全加固。
行动建议:今天优先排查所有公网可达的argocd-mcp和Redpanda实例,立即关闭默认无认证或收紧网络访问,并检查是否因配置ARGOCD_API_TOKEN而误暴露MCP端口。