Back to trending CVEs

Week of August 10, 2026

Trending* CVEs over the last 7 days (from August 3, 2026 to August 10, 2026)

1
CVE-2026-18577N-able / N-Central
NewKEV
SYRN Score95
CVSS8.2
Activity63
Published08/02/2026
StatusHighly Active

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

2
CVE-2026-63077Jetbrains / Teamcity
KEV
SYRN Score97
CVSS9.8
Activity50
Published07/27/2026
StatusHighly Active

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

3
CVE-2026-64561Linux / Linux Kernel
New
SYRN Score51
CVSS8.8
Activity47
Published08/04/2026
StatusHighly Active

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.

4
CVE-2026-58048Webpros / Cpanel
SYRN Score93
CVSS9.4
Activity36
Published07/31/2026
StatusHighly Active

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

5
CVE-2026-64638Wordpress / Wordpress
New
SYRN Score95
CVSS8.9
Activity29
Published08/07/2026
StatusHighly Active

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

6
CVE-2026-18556N-able / N-Central
KEV
SYRN Score94
CVSS8.2
Activity26
Published08/01/2026
StatusHighly Active

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

7
CVE-2026-9198Langflow / Langflow
KEV
SYRN Score96
CVSS9.8
Activity23
Published07/17/2026
StatusActive

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

8
CVE-2026-66066Rails / Rails
SYRN Score94
CVSS9.5
Activity20
Published07/30/2026
StatusActive

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

9
CVE-2025-55182Vercel / Next.Js
KEVRansomware
SYRN Score100
CVSS10.0
Activity17
Published12/03/2025
StatusActive

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

10
CVE-2026-8037Progress / Connection Manager For Objectscale
KEV
SYRN Score98
CVSS9.6
Activity17
Published06/04/2026
StatusActive

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

* Trending is based on the number of sightings collected from SYRN's threat intelligence sources over the given period.

Monitor these vulnerabilities and get alerted when new threats target your stack.

Get Started Free