<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
  <title>Exploit-DB.ai — Latest CVE intelligence</title>
  <link>https://exploit-db.ai/cve</link>
  <description>AI-scored CVE &amp; exploit intelligence. Data: NVD. Analysis: local $0 model.</description>
  <lastBuildDate>Tue, 11 Aug 2026 07:06:46 GMT</lastBuildDate>
  <item>
    <title>CVE-2026-13477 — MEDIUM 4.7</title>
    <link>https://exploit-db.ai/cve/CVE-2026-13477</link>
    <guid isPermaLink="false">CVE-2026-13477</guid>
    <pubDate>Wed, 05 Aug 2026 21:16:49 GMT</pubDate>
    <description>IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.</description>
  </item>
  <item>
    <title>CVE-2026-12762 — MEDIUM 5.3</title>
    <link>https://exploit-db.ai/cve/CVE-2026-12762</link>
    <guid isPermaLink="false">CVE-2026-12762</guid>
    <pubDate>Wed, 05 Aug 2026 21:16:49 GMT</pubDate>
    <description>IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.</description>
  </item>
  <item>
    <title>CVE-2026-12730 — LOW 3.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-12730</link>
    <guid isPermaLink="false">CVE-2026-12730</guid>
    <pubDate>Wed, 05 Aug 2026 21:16:49 GMT</pubDate>
    <description>IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate poten</description>
  </item>
  <item>
    <title>CVE-2026-10025 — HIGH 8.2</title>
    <link>https://exploit-db.ai/cve/CVE-2026-10025</link>
    <guid isPermaLink="false">CVE-2026-10025</guid>
    <pubDate>Wed, 05 Aug 2026 21:16:49 GMT</pubDate>
    <description>The flaw is an XML External Entity (XXE) injection vulnerability in IBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 to 7.5.0 UP 15 Interim Fix 005, allowing attackers to inject malicious XML content and potentially access sensitive information.</description>
  </item>
  <item>
    <title>CVE-2026-54876 — HIGH 7.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-54876</link>
    <guid isPermaLink="false">CVE-2026-54876</guid>
    <pubDate>Wed, 05 Aug 2026 20:16:53 GMT</pubDate>
    <description>The flaw allows a malicious TLS server to cause a memory leak in a client that checks OCSP responses, potentially leading to Denial of Service.</description>
  </item>
  <item>
    <title>CVE-2026-17613 — HIGH 7.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-17613</link>
    <guid isPermaLink="false">CVE-2026-17613</guid>
    <pubDate>Wed, 05 Aug 2026 20:16:40 GMT</pubDate>
    <description>The flaw allows any authenticated user to overwrite files and subscribe to WebSocket events, enabling data exfiltration and poisoning.</description>
  </item>
  <item>
    <title>CVE-2026-16102 — HIGH 8.1</title>
    <link>https://exploit-db.ai/cve/CVE-2026-16102</link>
    <guid isPermaLink="false">CVE-2026-16102</guid>
    <pubDate>Wed, 05 Aug 2026 20:16:37 GMT</pubDate>
    <description>The flaw in Keycloak&apos;s Dynamic Client Registration component allows attackers to write values to sensitive claim locations, potentially forging administrative roles and gaining full control over the realm.</description>
  </item>
  <item>
    <title>CVE-2026-16100 — MEDIUM 6.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-16100</link>
    <guid isPermaLink="false">CVE-2026-16100</guid>
    <pubDate>Wed, 05 Aug 2026 20:16:37 GMT</pubDate>
    <description>A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated use</description>
  </item>
  <item>
    <title>CVE-2026-16071 — MEDIUM 5.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-16071</link>
    <guid isPermaLink="false">CVE-2026-16071</guid>
    <pubDate>Wed, 05 Aug 2026 20:16:37 GMT</pubDate>
    <description>A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups </description>
  </item>
  <item>
    <title>CVE-2026-15573 — HIGH 8.1</title>
    <link>https://exploit-db.ai/cve/CVE-2026-15573</link>
    <guid isPermaLink="false">CVE-2026-15573</guid>
    <pubDate>Wed, 05 Aug 2026 20:16:36 GMT</pubDate>
    <description>The flaw in Keycloak&apos;s PathMatcher allows attackers to bypass security policies by manipulating URLs, granting unauthorized access.</description>
  </item>
  <item>
    <title>CVE-2026-12410 — HIGH 7.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-12410</link>
    <guid isPermaLink="false">CVE-2026-12410</guid>
    <pubDate>Wed, 05 Aug 2026 20:16:35 GMT</pubDate>
    <description>This vulnerability allows a low-privileged user to escalate privileges by creating symlinks during CCleaner uninstallation, potentially gaining SYSTEM access. It matters because it can lead to unauthorized system control.</description>
  </item>
  <item>
    <title>CVE-2026-7529 — HIGH 7.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-7529</link>
    <guid isPermaLink="false">CVE-2026-7529</guid>
    <pubDate>Wed, 05 Aug 2026 19:17:15 GMT</pubDate>
    <description>The flaw allows unauthenticated attackers to modify and disclose data through REST API endpoints due to lack of proper permission checks.</description>
  </item>
  <item>
    <title>CVE-2026-7456 — MEDIUM 6.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-7456</link>
    <guid isPermaLink="false">CVE-2026-7456</guid>
    <pubDate>Wed, 05 Aug 2026 19:17:14 GMT</pubDate>
    <description>The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to dele</description>
  </item>
  <item>
    <title>CVE-2026-67623 — HIGH 8.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-67623</link>
    <guid isPermaLink="false">CVE-2026-67623</guid>
    <pubDate>Wed, 05 Aug 2026 19:17:10 GMT</pubDate>
    <description>Mistral Vibe before 2.23.3 allows attackers to execute arbitrary commands via a malicious .git/config file, posing a significant security risk.</description>
  </item>
  <item>
    <title>CVE-2026-17506 — HIGH 7.2</title>
    <link>https://exploit-db.ai/cve/CVE-2026-17506</link>
    <guid isPermaLink="false">CVE-2026-17506</guid>
    <pubDate>Wed, 05 Aug 2026 19:17:04 GMT</pubDate>
    <description>The flaw allows unauthenticated attackers to inject arbitrary scripts via the 404 not_found_url parameter, leading to cross-site scripting (XSS). This matters because it can be exploited to steal user data or manipulate web pages.</description>
  </item>
  <item>
    <title>CVE-2026-16443 — HIGH 7.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-16443</link>
    <guid isPermaLink="false">CVE-2026-16443</guid>
    <pubDate>Wed, 05 Aug 2026 19:17:03 GMT</pubDate>
    <description>The flaw in Keycloak&apos;s SAML metadata import functionality allows unauthenticated attackers to forge SAML responses and gain unauthorized access by exploiting missing usage attributes for keys.</description>
  </item>
  <item>
    <title>CVE-2026-15979 — HIGH 8.1</title>
    <link>https://exploit-db.ai/cve/CVE-2026-15979</link>
    <guid isPermaLink="false">CVE-2026-15979</guid>
    <pubDate>Wed, 05 Aug 2026 19:17:03 GMT</pubDate>
    <description>The flaw allows authenticated attackers with author-level access to delete arbitrary files via path traversal, potentially leading to remote code execution.</description>
  </item>
  <item>
    <title>CVE-2025-70962 — HIGH 7.5</title>
    <link>https://exploit-db.ai/cve/CVE-2025-70962</link>
    <guid isPermaLink="false">CVE-2025-70962</guid>
    <pubDate>Wed, 05 Aug 2026 19:16:58 GMT</pubDate>
    <description>The flaw allows network attackers to access hardcoded credentials in RTSP authentication, enabling unauthorized viewing of camera footage.</description>
  </item>
  <item>
    <title>CVE-2026-71294 — HIGH 7.6</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71294</link>
    <guid isPermaLink="false">CVE-2026-71294</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:54 GMT</pubDate>
    <description>The flaw allows deserialization of untrusted data, leading to potential code execution or data manipulation by authenticated users.</description>
  </item>
  <item>
    <title>CVE-2026-71293 — MEDIUM 6.2</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71293</link>
    <guid isPermaLink="false">CVE-2026-71293</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:54 GMT</pubDate>
    <description>Statamic CMS&apos;s user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case for the handle that returns the user&apos;s raw two-factor recovery codes with no access restriction.</description>
  </item>
  <item>
    <title>CVE-2026-71292 — HIGH 7.2</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71292</link>
    <guid isPermaLink="false">CVE-2026-71292</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:53 GMT</pubDate>
    <description>The flaw allows for SQL injection by misusing request parameters in Subrion CMS, enabling attackers to execute arbitrary SQL commands.</description>
  </item>
  <item>
    <title>CVE-2026-71291 — HIGH 8.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71291</link>
    <guid isPermaLink="false">CVE-2026-71291</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:53 GMT</pubDate>
    <description>The flaw allows untrusted content to be executed as Twig templates without sandboxing, enabling Remote Code Execution (RCE).</description>
  </item>
  <item>
    <title>CVE-2026-71289 — CRITICAL 9.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71289</link>
    <guid isPermaLink="false">CVE-2026-71289</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:53 GMT</pubDate>
    <description>The flaw allows direct access to the amp-manager REST API without going through the CAM gateway, enabling unauthorized access and potential full system compromise.</description>
  </item>
  <item>
    <title>CVE-2026-71288 — HIGH 8.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71288</link>
    <guid isPermaLink="false">CVE-2026-71288</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:53 GMT</pubDate>
    <description>The flaw allows SQL injection by directly concatenating unvalidated input into an SQL ORDER BY clause without proper allowlisting or validation, leading to potential data manipulation and theft.</description>
  </item>
  <item>
    <title>CVE-2026-71287 — HIGH 8.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71287</link>
    <guid isPermaLink="false">CVE-2026-71287</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:53 GMT</pubDate>
    <description>The flaw allows SQL injection by not properly sanitizing ORDER BY column names, enabling attackers to execute arbitrary SQL commands.</description>
  </item>
  <item>
    <title>CVE-2026-71286 — MEDIUM 6.1</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71286</link>
    <guid isPermaLink="false">CVE-2026-71286</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:53 GMT</pubDate>
    <description>The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer&apos;s compileTemplate (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input.</description>
  </item>
  <item>
    <title>CVE-2026-71285 — HIGH 8.1</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71285</link>
    <guid isPermaLink="false">CVE-2026-71285</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:53 GMT</pubDate>
    <description>The flaw allows unauthenticated visitors to execute arbitrary JavaScript due to improper handling of user input in Matomo analytics integration, leading to potential session theft and full page takeover.</description>
  </item>
  <item>
    <title>CVE-2026-71284 — HIGH 7.2</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71284</link>
    <guid isPermaLink="false">CVE-2026-71284</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:53 GMT</pubDate>
    <description>The flaw allows an admin to execute arbitrary OS commands by crafting a backup archive, leading to Remote Code Execution (RCE).</description>
  </item>
  <item>
    <title>CVE-2026-71283 — MEDIUM 4.9</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71283</link>
    <guid isPermaLink="false">CVE-2026-71283</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:52 GMT</pubDate>
    <description>Fledge&apos;s backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. Requires the admin role (@has_permission(&quot;admin&quot;)).</description>
  </item>
  <item>
    <title>CVE-2026-71282 — MEDIUM 6.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71282</link>
    <guid isPermaLink="false">CVE-2026-71282</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:52 GMT</pubDate>
    <description>ChirpStack&apos;s SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpolates the user-supplied tag KEY directly into a raw SQL fragment via Rust&apos;s format! macro , while only the tag VALUE is safely parameter-bound via Diesel&apos;s .bind.</description>
  </item>
  <item>
    <title>CVE-2026-71281 — HIGH 8.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71281</link>
    <guid isPermaLink="false">CVE-2026-71281</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:52 GMT</pubDate>
    <description>The flaw allows attackers to execute arbitrary code by providing malicious cache/covariance files, as the torch.load function is called without weights_only=True, bypassing safety checks.</description>
  </item>
  <item>
    <title>CVE-2026-71280 — HIGH 8.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71280</link>
    <guid isPermaLink="false">CVE-2026-71280</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:52 GMT</pubDate>
    <description>The flaw allows an attacker to potentially manipulate or exploit a caller-supplied bookmark URL due to lack of validation checks, leading to potential security risks.</description>
  </item>
  <item>
    <title>CVE-2026-71279 — HIGH 8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71279</link>
    <guid isPermaLink="false">CVE-2026-71279</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:52 GMT</pubDate>
    <description>The flaw allows an attacker to execute arbitrary code by manipulating a file path parameter, leading to remote code execution.</description>
  </item>
  <item>
    <title>CVE-2026-71278 — CRITICAL 9.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71278</link>
    <guid isPermaLink="false">CVE-2026-71278</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:52 GMT</pubDate>
    <description>The flaw allows creating a &apos;calc rule&apos; without authentication, enabling unauthorized access and potential manipulation of critical data.</description>
  </item>
  <item>
    <title>CVE-2026-71277 — CRITICAL 9.1</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71277</link>
    <guid isPermaLink="false">CVE-2026-71277</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:52 GMT</pubDate>
    <description>The flaw allows an attacker to bypass authentication by sending any non-empty Authorization header, granting unauthorized access to protected endpoints.</description>
  </item>
  <item>
    <title>CVE-2026-71276 — HIGH 7.1</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71276</link>
    <guid isPermaLink="false">CVE-2026-71276</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:52 GMT</pubDate>
    <description>The flaw allows SQL injection by authenticated users due to direct interpolation of unvalidated HTTP query string values into raw SQL queries.</description>
  </item>
  <item>
    <title>CVE-2026-71275 — MEDIUM 5.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71275</link>
    <guid isPermaLink="false">CVE-2026-71275</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:51 GMT</pubDate>
    <description>OpenBK7231T&apos;s http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(request, &quot;&lt;h3&gt;OTA requested for %s!&lt;/h3&gt;&quot;, tmpA) with no HTML encoding, allowing a crafted URL such as /ota_exec?host=&lt;script&gt;alert(1)&lt;/script&gt; to execute Ja</description>
  </item>
  <item>
    <title>CVE-2026-71274 — HIGH 8.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71274</link>
    <guid isPermaLink="false">CVE-2026-71274</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:51 GMT</pubDate>
    <description>The flaw allows injection of malicious HTML content due to lack of sanitization and encoding, enabling cross-site scripting (XSS) attacks.</description>
  </item>
  <item>
    <title>CVE-2026-71273 — MEDIUM 6.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71273</link>
    <guid isPermaLink="false">CVE-2026-71273</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:51 GMT</pubDate>
    <description>OpenBK7231T&apos;s /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the parameter is absent from the request, an else-branch silently clears the device&apos;s web admin password to an empty string.</description>
  </item>
  <item>
    <title>CVE-2026-71272 — HIGH 8.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71272</link>
    <guid isPermaLink="false">CVE-2026-71272</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:51 GMT</pubDate>
    <description>The flaw allows attackers to manipulate hostname resolution and potentially execute code by exploiting DNS rebinding or similar techniques.</description>
  </item>
  <item>
    <title>CVE-2026-71271 — HIGH 8.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71271</link>
    <guid isPermaLink="false">CVE-2026-71271</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:51 GMT</pubDate>
    <description>The flaw lies in Memos&apos; webhook URL validation where it fails to check for the unspecified IP address (0.0.0.0/8), potentially allowing unauthorized access. This matters because it can lead to security breaches if exploited.</description>
  </item>
  <item>
    <title>CVE-2026-71270 — HIGH 8.6</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71270</link>
    <guid isPermaLink="false">CVE-2026-71270</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:51 GMT</pubDate>
    <description>The flaw allows an attacker to exploit SSRF in Stirling-PDF by targeting unsecured conversion endpoints, leading to potential data exposure.</description>
  </item>
  <item>
    <title>CVE-2026-71269 — HIGH 7.2</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71269</link>
    <guid isPermaLink="false">CVE-2026-71269</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:51 GMT</pubDate>
    <description>The flaw allows an attacker to traverse directories and potentially execute arbitrary code by manipulating path parameters in Node-RED&apos;s local-filesystem library storage module.</description>
  </item>
  <item>
    <title>CVE-2026-71268 — CRITICAL 9.9</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71268</link>
    <guid isPermaLink="false">CVE-2026-71268</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:51 GMT</pubDate>
    <description>The flaw allows attackers to execute arbitrary code by manipulating file paths in uploaded Structured Text files, due to lack of proper validation.</description>
  </item>
  <item>
    <title>CVE-2026-71267 — CRITICAL 9.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71267</link>
    <guid isPermaLink="false">CVE-2026-71267</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:50 GMT</pubDate>
    <description>The flaw allows an attacker to overwrite critical data on the stack by supplying a long entry name, potentially leading to remote code execution.</description>
  </item>
  <item>
    <title>CVE-2026-71266 — HIGH 7.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71266</link>
    <guid isPermaLink="false">CVE-2026-71266</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:50 GMT</pubDate>
    <description>The flaw involves a fixed-size stack buffer in tinyobjloader-c&apos;s parsing function, allowing potential overflow if input exceeds 4096 bytes.</description>
  </item>
  <item>
    <title>CVE-2026-71265 — HIGH 7.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71265</link>
    <guid isPermaLink="false">CVE-2026-71265</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:50 GMT</pubDate>
    <description>The flaw involves an insecure use of strcpy without length checking, leading to potential stack buffer overflow when processing MOCHAD_RFSEC messages in Domoticz.</description>
  </item>
  <item>
    <title>CVE-2026-71264 — HIGH 8.2</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71264</link>
    <guid isPermaLink="false">CVE-2026-71264</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:50 GMT</pubDate>
    <description>The flaw allows unauthenticated access to the device&apos;s configuration details via the GET /json/cfg endpoint, exposing sensitive information such as network settings and LED configurations.</description>
  </item>
  <item>
    <title>CVE-2026-71263 — CRITICAL 9.1</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71263</link>
    <guid isPermaLink="false">CVE-2026-71263</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:50 GMT</pubDate>
    <description>The flaw involves an off-by-one error in the bounds check for LINUXTCP port of FreeModbus, leading to potential buffer overflow. This matters because it can allow attackers to exploit the vulnerability to execute malicious code or cause system crashes.</description>
  </item>
  <item>
    <title>CVE-2026-71262 — CRITICAL 9.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-71262</link>
    <guid isPermaLink="false">CVE-2026-71262</guid>
    <pubDate>Wed, 05 Aug 2026 18:24:50 GMT</pubDate>
    <description>The IoTSharp BlobStorageController.cs lacks proper authorization, allowing unauthenticated attackers to access sensitive storage operations such as upload, download, list, modify, and delete.</description>
  </item>
</channel></rss>
