VulncastBriefing archive

Daily Brief - 2026-07-28

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-51303

critical · CVSS 9.8 · SQLite

A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprList object via sqlite3ExprListDelete and then subsequently accesses the dangling pointer of the released object. A remote adversary can supply specially crafted SQL queries to trigger this vulnerability during SQL statement parsing. Successful exploitation may result in application crash (denial of service), sensitive memory information leakage, and in some scenarios, arbitrary code execution on the affected host.

  • Use-After-Free
  • Denial Of Service
  • Remote Code Execution
  • database engine
  • sql

CVE-2026-59688

high · CVSS 8.4 · Progress Software LoadMaster

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.

  • OS Command Injection
  • load balancer
  • web application firewall

CVE-2026-63077

critical · CVSS 9.8 · JetBrains TeamCity

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

  • Remote Code Execution
  • ci/cd pipeline

CVE-2026-64747

Apple iOS

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges.

  • Buffer Overflow
  • Privilege Escalation
  • operating system

CVE-2026-66014

high · CVSS 8.8 · JFrog Artifactory

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

  • Privilege Escalation
  • devops
  • artifact repository