VulncastBriefing archive

Weekly Brief - 2026-08-17

· 3838 vulnerabilities · 11 min listen

▶ Listen to this briefing

CVE-2026-72898

critical · CVSS 10 · Metabase

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

  • SQL Injection
  • data analytics

CVE-2026-58231

critical · CVSS 10 · SAP Commerce Cloud

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

  • Remote Code Execution
  • Improper Input Validation
  • web application
  • cloud platform

CVE-2026-62878

critical · CVSS 9.8 · Microsoft Windows

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

  • Stack-based Buffer Overflow
  • Remote Code Execution
  • network services

CVE-2026-71398

critical · CVSS 10 · Adobe Campaign Classic

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

  • Incorrect Authorization
  • Remote Code Execution
  • web application
  • enterprise software

CVE-2026-17218

critical · CVSS 9.8 · IBM i

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

  • Remote Code Execution
  • Buffer Overflow
  • operating system

CVE-2026-66898

critical · CVSS 9.9 · Canonical LXD

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

  • Path Traversal
  • linux container
  • system software

CVE-2026-73269

critical · CVSS 9.9 · Red Hat Cluster Curator Controller

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.

  • Privilege Escalation
  • kubernetes
  • orchestration

CVE-2026-73296

critical · CVSS 9.4 · Microsoft UFO

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.

  • Broken Access Control
  • automation
  • python
  • mobile device management

CVE-2026-17184

critical · CVSS 9.8 · IBM Db2 Mirror for i

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

  • Remote Code Execution
  • database
  • server software

CVE-2026-19682

critical · CVSS 9.9 · Tenable Security Center

A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.

  • Command Injection
  • web application