Rosetta Daily · Aug 15, 2026
Scanned 259 raw items in the 36-hour window (32 enabled sources, 6 active this cycle); 18 selected.
Critical Vulnerabilities
MindsDB Minds Platform ≤26.1.0 — unauthenticated RCE CVE-2026-73678, CVSS 10.0 CRITICAL. An unauthenticated attacker can configure their own LLM API key via PUT /api/v1/settings/, then submit a crafted prompt to POST /api/v1/responses/ that drives the Anton agent's scratchpad tool to call exec() on attacker-influenced Python source without sandboxing — full command execution as the user running the desktop app, exposing SSH keys, stored credentials and environment secrets. A textbook prompt-injection-to-RCE chain. NVD
Haiwell IoT Cloud HMI Gateway — unauthenticated command injection CVE-2026-19188, CVSS 10.0 CRITICAL. The cmdPing Socket.io event under the Net Check feature at /setting fails to sanitize input before passing it to the OS shell, letting an attacker inject and execute arbitrary commands as root. Affects an industrial/IoT gateway product — high blast radius. NVD
Grav CMS / Grav API plugin — 9-CVE authorization bypass cluster (CVSS 8.6–9.3) Versions before 1.0.13 gate several controllers (Groups, Accounts, Preferences, Invitations, Dashboard, Users) on a bare isSuperAdmin() check that never consults the API key's declared scope cap — a minimal-scope key minted on a super-admin account can disable 2FA, rewrite group ACLs, or mint a new super-admin key, leading to full site takeover; separate Twig-injection and ZIP-upload paths reach direct RCE. Fixed in plugin 1.0.13 / Grav core 2.0.13. NVD
IBM Db2 Mirror for i 7.4/7.5/7.6 — 7-CVE cluster (CVSS 8.2–9.9) Arbitrary CL command execution, arbitrary code execution via external file-path control, authentication bypass, path-traversal file writes, DoS via command injection, arbitrary file reads, and system-configuration information disclosure. NVD
Tenable Security Center — 5-CVE cluster (CVSS 8.5–9.4) Unauthenticated command injection with service-account privileges; authenticated non-admin RCE via report generation; cross-group user management by a "Security Manager"-role user; config-write command injection; and a local privilege-escalation chain. Notably, this is the security-monitoring vendor's own product. NVD
SiYuan notes app — two high-severity flaws CVE-2026-72811 (SQL injection, CVSS 9.9): the backlink/mention search concatenates stored metadata and client keywords into a SQL statement while escaping only double quotes, letting anonymous or RoleReader users read/write across the whole database. CVE-2026-72810 (publish-boundary bypass, CVSS 9.2): unauthenticated WebSocket broadcast sessions leak real-time edits, including password-protected and forbidden documents. Both fixed in v3.7.4. NVD
Metacat (DataONE data repository) — unauthenticated SQL injection CVE-2026-48528, CVSS 9.8. The nodeId parameter on /cn/v1/object and /cn/v2/object is unsanitized; attackers can exfiltrate the entire underlying database via error-message reflection, exposing research catalog data, access logs, and researcher ORCID/IP identifiers. Fixed in 3.4.1. NVD
Laravel Socialite Facebook provider — authentication bypass CVE-2026-73683, CVSS 9.2. getUserByOIDCToken() never validates the OIDC nonce claim, so a captured, unexpired id_token for the same Facebook App ID can be replayed to impersonate a victim's account. NVD
erlang_quic — client never authenticated the server CVE-2026-49457, CVSS 9.1. Before 1.4.4, the QUIC/HTTP3 client skipped CertificateVerify signature checks, chain validation, and hostname comparison during the TLS 1.3 handshake, making verify a no-op and enabling a full MITM. NVD
WordPress plugin ecosystem — batch of high-severity flaws 6Storage Rentals ≤2.27.0: unauthenticated auth bypass, login as any user via email alone (CVE-2026-15303, CVSS 9.8). Wishlist Member ≤3.34.1: unauthenticated account takeover, including admins, via a flawed registration-merge check (CVE-2026-12949, CVSS 9.8). RapiSafe for Contact Form 7 ≤1.0.4: arbitrary file deletion that can delete wp-config.php to trigger RCE (CVE-2026-14484, CVSS 9.1). NVD
Vendor Advisories
Microsoft Edge (Chromium) heap overflow RCE plus five inherited use-after-free bugs CVE-2026-72970 (CVSS 8.3, network-side RCE) alongside five Chromium-origin use-after-free CVEs landing in Edge via V8, Blink, HTML, Extensions, and TabStrip — all fixed through the Chromium version bump. Separately, PowerShell RCE (CVE-2026-50523) and NTFS RCE (CVE-2026-50313) updates shipped in the same cycle. MSRC
Actively Exploited / Watch Closely
⚠️ Max-severity SAP Commerce Cloud RCE flaw already targeted, three days after patch Threat intel firm Defused observed active exploitation attempts. No CVE was given in public reporting — teams running the product should verify patch status now. Bleeping Computer
⚠️ macOS Screen Sharing auth-bypass exploited to deploy a Monero miner The Netherlands' NCSC warned that public exploit code for this authentication-bypass flaw is now driving in-the-wild cryptomining deployments. Bleeping Computer
Microsoft Defender "ShieldBreak" elevation of privilege CVE-2026-69414, severity not yet rated. Microsoft confirmed a publicly named EoP issue in the Malware Protection Engine; no fix is available yet — worth tracking for a patch and any exploitation reports. MSRC
Industry News
RingCentral breach exposes 1.6 million accounts The ShinyHunters extortion group stole personal data after breaching RingCentral in July; scale confirmed via Have I Been Pwned. Bleeping Computer
Shell investigating potential incident after Clop data-theft claims Clop claims to have stolen 89GB of data; Shell confirmed an active investigation. Bleeping Computer
Arrests over €30M bank fraud exploiting a service-provider flaw Four arrested in Brazil, three more charged in Europe, for exploiting a vulnerability at a service provider to withdraw funds from Commerzbank customer accounts. Bleeping Computer
New Evooo1Bot Linux botnet turns routers into traffic relay nodes A Mirai-based modular malware targeting internet-facing gateway devices, converting them into SOCKS5 relay nodes. Bleeping Computer
Former data analyst sentenced to prison for extortion A former Brightly Software contractor got two years for a $2.5 million data-theft extortion scheme against his employer. Bleeping Computer