● Daily security briefing
Saturday, August 29, 2026
CERT and PSIRT advisories were quiet on August 29th with no new publications, leaving the day's activity dominated by 63 published CVEs including eight critical findings. The most severe issues span multiple domains: CVE-2026-82456 in argocd-mcp 0.8.0 exposes network services to unauthenticated access, CVE-2026-82460 affects Cloud Commander with directory traversal, CVE-2026-15369 and CVE-2026-14494 target WordPress plugins with privilege escalation and remote code execution respectively, while CVE-2026-82452, CVE-2026-82448, and CVE-2026-82454 disclose authentication bypasses in rust-iot-platform, Shinobi, and the Omnivore API. Additionally, CVE-2026-82447 describes a sandbox escape in Skyvern before version 1.0.45.
7 critical5 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-82456CVSS 10argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers wh
- criticalCVE-2026-82460CVSS 9.8Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attack
- criticalCVE-2026-15369CVSS 9.8The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin ac
- criticalCVE-2026-82452CVSS 9.8rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthe
- criticalCVE-2026-82448CVSS 9.8Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers
- criticalCVE-2026-14494CVSS 9.8The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to
- criticalCVE-2026-82454CVSS 9.1The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the
- highCVE-2026-82447CVSS 8.8Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandb
- highCVE-2026-82450CVSS 8.8BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions
- highCVE-2026-82466CVSS 8.7Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can ex
- highCVE-2026-82473CVSS 8.2KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgr
- highCVE-2026-82475CVSS 8.1iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can en