Cyber Security Alerts

  1. Home
  2. »
  3. Cyber Alerts

Blueteq Cyber Alerts

Latest High & Critical Vulnerabilities

Blueteq’s Cyber Alerts keep watch so you don’t have to. We continuously monitor newly published critical and high-risk vulnerabilities, analysing emerging threats as they appear. This page provides clear visibility of the issues that matter most, helping you stay protected.

CVE ID :CVE-2026-72859 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72837 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify,...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72836 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72833 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72830 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72831 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72829 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72827 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72828 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72826 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey....Read more
Date: 2026-08-14
CVE ID :CVE-2026-72824 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72822 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72819 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72810 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72811 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and...Read more
Date: 2026-08-14

Latest Vulnerabilities

CVE ID :CVE-2026-72859 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72837 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify,...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72836 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72833 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72830 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72831 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72829 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72827 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72828 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72826 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey....Read more
Date: 2026-08-14
CVE ID :CVE-2026-72824 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72822 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72819 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72810 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72811 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and...Read more
Date: 2026-08-14

Blueteq provides remote IT support to many organisations, so even if your business falls outside this mapped area for a free IT assessment, we’d still welcome you getting in touch. We’re always here to help.

Blueteq Ltd
Unit A5,
Endeavour Business Park, Penner Road,
Havant,
PO9 1QN

Free IT assessment map

Blueteq provides remote IT support to many organisations, so even if your business falls outside this mapped area for a free IT assessment, we’d still welcome you getting in touch. We’re always here to help.

Blueteq Ltd
Unit A5,
Endeavour Business Park, Penner Road,
Havant,
PO9 1QN