GRACEITS • DEFENSIVE SECURITY INTELLIGENCE

Today's high-risk
vulnerability watch.

CVSS 8.0+ vulnerabilities prioritized with CISA KEV and Red Hat context, plus practical remediation guidance for infrastructure and platform teams.

Tracked high risk2377CVSS 8.0+
Critical957CVSS 9.0+
Known exploited18CISA KEV + CVSS 8+
Last syncAug 22, 2026 1:10 PM EDTserver-side cache
PRIORITIZED FEED

Critical & high vulnerabilities

9.8
CVE-2026-65400
CRITICAL KNOWN EXPLOITED

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

Published Aug 6, 2026 6:18 PM EDT Updated Aug 19, 2026 12:17 AM EDT
View impact & remediation →
9.8
CVE-2026-59310
CRITICAL KNOWN EXPLOITED

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Published Jul 30, 2026 9:16 AM EDT Updated Aug 19, 2026 12:17 AM EDT
View impact & remediation →
9.8
CVE-2026-33824
CRITICAL KNOWN EXPLOITED

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Published Apr 14, 2026 2:17 PM EDT Updated Aug 19, 2026 12:16 AM EDT
View impact & remediation →
9.8
CVE-2026-9198
CRITICAL KNOWN EXPLOITED

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

Published Jul 17, 2026 2:17 PM EDT Updated Aug 17, 2026 4:16 PM EDT
View impact & remediation →
9.6
CVE-2022-26486
CRITICAL KNOWN EXPLOITED

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Andro…

Published Dec 22, 2022 3:15 PM EST Updated Aug 19, 2026 11:29 AM EDT
View impact & remediation →
9.5
CVE-2026-72530
CRITICAL KNOWN EXPLOITED

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrar…

Published Aug 19, 2026 1:21 PM EDT Updated Aug 21, 2026 12:18 AM EDT
View impact & remediation →
9.4
CVE-2025-62593
CRITICAL KNOWN EXPLOITED

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-ba…

Published Nov 26, 2025 6:15 PM EST Updated Aug 18, 2026 12:16 AM EDT
View impact & remediation →
9.3
CVE-2026-72529
CRITICAL KNOWN EXPLOITED

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Published Aug 19, 2026 1:21 PM EDT Updated Aug 21, 2026 12:18 AM EDT
View impact & remediation →
9.3
CVE-2026-64849
CRITICAL KNOWN EXPLOITED RH important

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py …

Published Aug 17, 2026 6:17 PM EDT Updated Aug 20, 2026 3:16 PM EDT
View impact & remediation →
9.1
CVE-2026-55040
CRITICAL KNOWN EXPLOITED

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Published Jul 14, 2026 2:18 PM EDT Updated Aug 19, 2026 12:17 AM EDT
View impact & remediation →
8.9
CVE-2026-73570
HIGH KNOWN EXPLOITED

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processin…

Published Aug 13, 2026 12:19 PM EDT Updated Aug 22, 2026 12:18 AM EDT
View impact & remediation →
8.8
CVE-2022-26485
HIGH KNOWN EXPLOITED

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thund…

Published Dec 22, 2022 3:15 PM EST Updated Aug 19, 2026 11:29 AM EDT
View impact & remediation →
GRACEITS VULNERABILITY REMEDIATION

From vulnerability finding to verified closure.

GraceITS supports remediation at scale across RHEL 7/8/9/10, Windows, Java, Oracle and application platforms using Qualys, Tanium and Ansible-driven automation.

DiscoverPrioritizeRemediateRescanClose