The latest high-severity CVEs
The ten most severe vulnerabilities disclosed in the past week. These are dangerous precisely because they’re fresh: many have no vendor patch yet, exploitation is often still unfolding, and defenders are working without an official fix.
That’s why remediation on a brand-new CVE runs roughly two to two-and-a-half times a settled one — a specialist has to build and verify an original mitigation, under time pressure, while the threat is still live. The prices below reflect that.
-
Unclassified CRITICAL 10.0#1 CVE-2026-76008
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI P…
Fix unknown TodayFix from $5,750 urgent 2026-08-19 -
Unclassified CRITICAL 10.0#2 CVE-2026-70921
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected …
Fix unknown TodayFix from $5,750 urgent 2026-08-18 -
Unclassified CRITICAL 10.0#3 CVE-2026-70880
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported versio…
Fix unknown TodayFix from $5,750 urgent 2026-08-18 -
Unclassified CRITICAL 10.0#4 CVE-2026-61241
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affecte…
Fix unknown TodayFix from $5,750 urgent 2026-08-18 -
Unclassified CRITICAL 10.0#5 CVE-2026-75784
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx …
Fix unknown 1 day oldFix from $5,750 urgent 2026-08-18 -
Unclassified CRITICAL 10.0#6 CVE-2026-73343
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Fix unknown 1 day oldFix from $5,750 urgent 2026-08-18 -
Unclassified CRITICAL 10.0#7 CVE-2026-75874
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Fix unknown 1 day oldFix from $5,750 urgent 2026-08-18 -
Unclassified CRITICAL 10.0#8 CVE-2026-74253
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer befor…
Fix unknown 1 day oldFix from $5,750 urgent 2026-08-17 -
Unclassified CRITICAL 10.0#9 CVE-2026-74843
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttp…
Fix unknown 2 days oldFix from $5,750 urgent 2026-08-17 -
Unclassified CRITICAL 10.0#10 CVE-2026-19977
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Va…
Fix unknown 2 days oldFix from $5,750 urgent 2026-08-17
Facing one of these in your stack right now?
Get it fixed fast