VulncastBriefing archive

Weekly Brief - 2026-08-10

· 1815 vulnerabilities · 11 min listen

▶ Listen to this briefing

CVE-2026-48330

critical · CVSS 10 · Adobe Campaign Classic

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this issue does not require user interaction. Scope is changed.

  • SQL Injection
  • Remote Code Execution
  • enterprise software

CVE-2026-63456

critical · CVSS 9.8 · HPE SD-WAN Orchestrator

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

  • Authentication Bypass
  • sd-wan
  • web application
  • rest api

CVE-2026-20304

critical · CVSS 9.9 · Cisco Catalyst SD-WAN

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.

  • Improper Access Control
  • sd-wan

CVE-2026-70426

critical · CVSS 9 · Jenkins Remoting

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.

  • Deserialization Vulnerability
  • Remote Code Execution
  • agent communication

CVE-2026-9193

critical · CVSS 9.9

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.

CVE-2026-19170

critical · CVSS 9.6 · Google Chrome

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • Use After Free
  • Sandbox Escape
  • web browser

CVE-2026-66909

critical · CVSS 9.8 · Apache CXF

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

  • Insecure Deserialization
  • Remote Code Execution
  • java
  • messaging system

CVE-2026-67261

critical · CVSS 9.8 · Dell Virtual Storage Integrator

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.

  • Command Injection
  • Remote Code Execution
  • virtualization management

CVE-2026-68823

critical · CVSS 9.1 · Microsoft Azure Confidential Ledger

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

  • Remote Code Execution
  • cloud platform

CVE-2026-14526

critical · CVSS 9.8 · AI Copilot – Content Generator

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-level user account and achieve full site takeover by saving and executing a malicious workflow containing a wp_create_user action node specifying role=administrator. This vulnerability is exploitable by unauthenticated attackers on any site where the [aiwu-form] shortcode or public chatbot is rendered on a frontend page, as the waic-nonce value is emitted into publicly accessible JavaScript (WAIC_DATA.waicNonce) on those pages, rendering the nonce check a non-functional authorization barrier.

  • Authentication Bypass
  • Remote Code Execution
  • php
  • web application
  • wordpress plugin