PULSE
LIVE65signals / 24h
FEED
ransombarracuda reclama a Micro-Comm Inc. · US · Technologyransombarracuda reclama a Namyang Industrial Co., Ltd. \ NAMYANG NEXMO · KR · Manufacturingransombarracuda reclama a RS Automation Co., Ltd. · CN · Manufacturingransomthreeam reclama a clubonecasino.com · US · Hospitalityransomincransom reclama a vprj.org · US · Not Foundransompanzer reclama a Surakarta University · ID · Educationransompanzer reclama a Festina Group · CH · Retail & E-Commerceransomclop reclama a nuv******* · Not Foundransomclop reclama a ipm******* · Not Foundransomclop reclama a ecc******* · Not Foundransomclop reclama a st******* · Not Foundransomclop reclama a qc******* · Not Foundransomclop reclama a flu******* · Not Foundransomclop reclama a mid******* · Not Foundransombarracuda reclama a Micro-Comm Inc. · US · Technologyransombarracuda reclama a Namyang Industrial Co., Ltd. \ NAMYANG NEXMO · KR · Manufacturingransombarracuda reclama a RS Automation Co., Ltd. · CN · Manufacturingransomthreeam reclama a clubonecasino.com · US · Hospitalityransomincransom reclama a vprj.org · US · Not Foundransompanzer reclama a Surakarta University · ID · Educationransompanzer reclama a Festina Group · CH · Retail & E-Commerceransomclop reclama a nuv******* · Not Foundransomclop reclama a ipm******* · Not Foundransomclop reclama a ecc******* · Not Foundransomclop reclama a st******* · Not Foundransomclop reclama a qc******* · Not Foundransomclop reclama a flu******* · Not Foundransomclop reclama a mid******* · Not Found
← All CVEs
CVE WatchAug 6, 2026

CVE-2026-18993

A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file her

CVSS

6.3

Medium

EPSS

KEV

Exploit Today

0-100

Published: Aug 6, 2026 · Last modified: Aug 6, 2026 · CWE-266 · CWE-284

EPSS · 30d

Not enough EPSS history yet.

Technical description

A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-189966.3 MED
A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command Handler. Such manipulation leads to incorrect privilege assignment. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.4h
CVE-2026-189954.3 MED
A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.4h
CVE-2026-189766.3 MED
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report.7h
CVE-2026-189745.3 MED
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.8h
CVE-2026-189697.3 HIG
A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.9h
CVE-2026-706125.4 MED
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame sandbox state was also not made available to the app permission handlers, affecting apps that render untrusted content in sandboxed iframes and grant the openExternal permission by default when no setPermissionRequestHandler is installed. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.13h