VulncastBriefing archive

Daily Brief - 2026-08-26

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-65093

critical · CVSS 9.9 · NVIDIA OpenShell

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • Sandbox Escape
  • linux
  • sandbox
  • virtualization

CVE-2026-68525

Apache Tomcat

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

  • Improper Authorization
  • web server
  • application server

CVE-2026-76197

critical · CVSS 10 · Adobe Campaign Classic

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

  • OS Command Injection
  • enterprise software

CVE-2026-78581

medium · CVSS 4.2 · Elastic Kibana

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify a conversation they do not own. Successful exploitation requires knowledge of a hard-to-guess identifier.

  • Authorization Bypass
  • Broken Access Control
  • web application

CVE-2026-79290

Google Chrome

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • Use After Free
  • Remote Code Execution
  • web browser