⌁ CyberSecurityBoardThreat Intel · CVEs · Products

Tag: critical

Critical CVEs

CVE-2026-82452 — Critical vulnerability brief

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated…

critical Critical CVE CVE-2026-82452
August 29, 2026
Critical CVEs

CVE-2026-82277 — Critical vulnerability brief

Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on…

critical Critical CVE CVE-2026-82277
August 28, 2026
Critical CVEs

CVE-2026-82266 — Critical vulnerability brief

Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach…

critical Critical CVE CVE-2026-82266
August 28, 2026
Critical CVEs

CVE-2026-81735 — Critical vulnerability brief

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the…

critical Critical CVE CVE-2026-81735
August 27, 2026