VulncastBriefing archive

Daily Brief - 2026-08-21

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-17142

critical · CVSS 9.8 · IBM AIX

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.

  • Remote Code Execution
  • Improper Authentication
  • unix operating system
  • virtualization software

CVE-2026-18420

high · CVSS 8.8 · OpenSearch Dashboards

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

  • Remote Code Execution
  • Prototype Pollution
  • web application
  • data visualization

CVE-2026-69836

critical · CVSS 10 · Microsoft Entra ID

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

  • Insecure Deserialization
  • Remote Code Execution
  • cloud platform
  • authentication service

CVE-2026-76017

Google Chrome

Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

  • Use After Free
  • Remote Code Execution
  • web browser

CVE-2026-77645

PTC Windchill

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

  • Remote Code Execution
  • Deserialization
  • product lifecycle management
  • web application