VulncastBriefing archive

Daily Brief - 2026-08-13

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-17218

critical · CVSS 9.8 · IBM i

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

  • Remote Code Execution
  • Buffer Overflow
  • operating system

CVE-2026-66898

critical · CVSS 9.9 · Canonical LXD

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

  • Path Traversal
  • linux container
  • system software

CVE-2026-70468

high · CVSS 8.1 · Fortinet FortiManager

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

  • Authentication Bypass
  • network management
  • management console

CVE-2026-73269

critical · CVSS 9.9 · Red Hat Cluster Curator Controller

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.

  • Privilege Escalation
  • kubernetes
  • orchestration

CVE-2026-73296

critical · CVSS 9.4 · Microsoft UFO

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.

  • Broken Access Control
  • automation
  • python
  • mobile device management