This week · ranked by CVSS

The latest high-severity CVEs

The ten most severe vulnerabilities disclosed in the past week. These are dangerous precisely because they’re fresh: many have no vendor patch yet, exploitation is often still unfolding, and defenders are working without an official fix.

That’s why remediation on a brand-new CVE runs roughly two to two-and-a-half times a settled one — a specialist has to build and verify an original mitigation, under time pressure, while the threat is still live. The prices below reflect that.

  1. Unclassified CRITICAL 10.0
    #1 CVE-2026-76008

    A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI P…

    Fix unknown Today
    Fix from $5,750 urgent 2026-08-19
  2. Unclassified CRITICAL 10.0
    #2 CVE-2026-70921

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected …

    Fix unknown Today
    Fix from $5,750 urgent 2026-08-18
  3. Unclassified CRITICAL 10.0
    #3 CVE-2026-70880

    Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported versio…

    Fix unknown Today
    Fix from $5,750 urgent 2026-08-18
  4. Unclassified CRITICAL 10.0
    #4 CVE-2026-61241

    Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affecte…

    Fix unknown Today
    Fix from $5,750 urgent 2026-08-18
  5. Unclassified CRITICAL 10.0
    #5 CVE-2026-75784

    A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx …

    Fix unknown 1 day old
    Fix from $5,750 urgent 2026-08-18
  6. Unclassified CRITICAL 10.0
    #6 CVE-2026-73343

    Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

    Fix unknown 1 day old
    Fix from $5,750 urgent 2026-08-18
  7. Unclassified CRITICAL 10.0
    #7 CVE-2026-75874

    Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

    Fix unknown 1 day old
    Fix from $5,750 urgent 2026-08-18
  8. Unclassified CRITICAL 10.0
    #8 CVE-2026-74253

    Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer befor…

    Fix unknown 1 day old
    Fix from $5,750 urgent 2026-08-17
  9. Unclassified CRITICAL 10.0
    #9 CVE-2026-74843

    A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttp…

    Fix unknown 2 days old
    Fix from $5,750 urgent 2026-08-17
  10. Unclassified CRITICAL 10.0
    #10 CVE-2026-19977

    A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Va…

    Fix unknown 2 days old
    Fix from $5,750 urgent 2026-08-17

Facing one of these in your stack right now?

Get it fixed fast