Back to trending CVEs

Week of August 24, 2026

Trending* CVEs over the last 7 days (from August 17, 2026 to August 24, 2026)

1
CVE-2026-19478Gitlab / Gitlab
New
SYRN Score96
CVSS9.4
Activity97
Published08/17/2026
StatusHighly Active

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

2
CVE-2023-32243Wpdeveloper / Essential Addons For Elementor
SYRN Score97
CVSS9.8
Activity81
Published05/12/2023
StatusHighly Active

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

3
CVE-2026-69836Microsoft / Microsoft Entra Id
NewKEV
SYRN Score96
CVSS10.0
Activity61
Published08/20/2026
StatusHighly Active

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

4
CVE-2026-19490Netscaler / Adc
New
SYRN Score91
CVSS9.3
Activity44
Published08/19/2026
StatusHighly Active

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

5
CVE-2026-73570Synacor / Zimbra Collaboration Suite
KEV
SYRN Score95
CVSS8.9
Activity44
Published08/13/2026
StatusHighly Active

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

6
CVE-2026-64849Lfprojects / Mlflow
NewKEV
SYRN Score97
CVSS9.3
Activity37
Published08/17/2026
StatusHighly Active

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

7
CVE-2023-28121Automattic / Woocommerce
SYRN Score97
CVSS9.8
Activity36
Published04/12/2023
StatusHighly Active

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

8
CVE-2026-65400Apple / Macos
KEV
SYRN Score95
CVSS7.1
Activity31
Published08/06/2026
StatusHighly Active

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

9
CVE-2026-59310Vmware / Cloud Foundation
KEV
SYRN Score97
CVSS9.8
Activity31
Published07/30/2026
StatusHighly Active

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

10
CVE-2026-33824Microsoft / Microsoft Windows
KEV
SYRN Score97
CVSS9.8
Activity31
Published04/14/2026
StatusHighly Active

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

* Trending is based on the number of sightings collected from SYRN's threat intelligence sources over the given period.

Monitor these vulnerabilities and get alerted when new threats target your stack.

Get Started Free