CyberSecurityBoardThreat Intel · CVEs · Products

Category: Critical CVEs

Critical and exploited CVEs, vulnerability intelligence and remediation guidance.

Critical CVEs

WordPress Pre-Auth XSS Vulnerability CVE-2026-64638

CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting vulnerability in WordPress's login screen. It allows unauthenticated attackers to execute arbitrary JavaScript in…

CVE-2026-64638 Pre-Auth RCE WordPress
August 7, 2026
Critical CVEs

CVE-2026-64564: Linux SCTP Use-After-Free

A use-after-free vulnerability in Linux's SCTP networking code, present since 2008, allows local users to gain root and potentially escape containers. Patched…

container escape CVE-2026-64564 privilege escalation SCTP
August 7, 2026