VulncastBriefing archive

Daily Brief - 2026-08-18

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-19478

critical · CVSS 9.4 · GitLab CE/EE

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

  • Broken Access Control
  • web application

CVE-2026-59910

high · CVSS 7.8 · Dell ObjectScale

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • Command Injection
  • Privilege Escalation
  • storage software

CVE-2026-65346

Apple Operating System

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to arbitrary code execution.

  • Integer Overflow
  • Remote Code Execution
  • mobile operating system
  • desktop operating system

CVE-2026-65640

high · CVSS 8.8 · WordPress

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

  • Remote Code Execution
  • web application
  • php

CVE-2026-75045

critical · CVSS 9.1 · JetBrains YouTrack

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

  • Broken Access Control
  • web application