Skip to content
Cyber Times

Independent threat intelligence for security leaders.

Go back

CISO Intelligence Update — Saturday, 29 August 2026

🛡️ Cyber Times — CISO Intelligence Update

Saturday, 29 August 2026 · Coverage: 28 Aug 2026 08:00 IST → 29 Aug 2026 08:00 IST

The high-confidence sweep produced 31 publishable records. This edition presents 7 source-linked updates across 1 security domains; 7 are marked for priority review.

🛡️ Vulnerabilities Worth Attention

CVE-2026-54745 — Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows

CRITICAL — NVD CVSS 10.0 (critical). Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 01:48 IST Sources: NVD

CVE-2026-82222 — Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection

CRITICAL — NVD CVSS 10.0 (critical). Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 28 Aug 2026 17:46 IST Sources: NVD

CVE-2026-19295 — IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with…

CRITICAL — NVD CVSS 9.9 (critical). IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from “authenticated flow user” to arbitrary OS-level command execution under the server process identity…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 03:46 IST Sources: NVD

CVE-2026-18527 — IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE…

CRITICAL — NVD CVSS 9.9 (critical). IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user’s authenticated profile gaining elevated privileges on the IBM i system.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 03:46 IST Sources: NVD

CVE-2026-55634 — Pimcore is an Open Source Data & Experience Management Platform

CRITICAL — NVD CVSS 9.9 (critical). Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 01:48 IST Sources: NVD

CVE-2026-55565 — Yamcs is a mission control framework

CRITICAL — NVD CVSS 9.9 (critical). Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by Expression.getCompiledExpression through SimpleCompiler.cook instead of applying ValueExpression.escapeJavaString. The pattern can originate from…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 01:48 IST Sources: NVD

CVE-2026-19286 — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A…

CRITICAL — NVD CVSS 9.8 (critical). IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 03:46 IST Sources: NVD

💡 Defensive Priority

Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.


Collection: 1,110 records inspected · 130 passed collection filters · 31 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.


Topics in this briefing

Share this post on:

Previous Post
CISO Intelligence Update — Sunday, 30 August 2026
Next Post
CISO Intelligence Update — Friday, 28 August 2026