PULSE
LIVE75signals / 24h
FEED
ransomdragonforce reclama a Primary Eye Care · US · Healthcareransomorova reclama a St Theresa Catholic Church · US · Otherransomorova reclama a Stoneybrook West Master Association, Inc · US · Otherransomorova reclama a Stonecrest POA · US · Otherransomqilin reclama a Bloom Financials · GB · Financial Servicesransomorova reclama a Magnolia Dental · US · Healthcareransomorova reclama a Country Oaks Veterinary Clinic · US · Healthcareransomorova reclama a David King Architect · US · Professional Servicesransomorova reclama a Woodside Ranch · US · Agriculture and Food Productionransombarracuda reclama a Ferrell \ Skyline Implants & Periodontics \ Dr. Scott Ferguson · Healthcareransombarracuda reclama a Micro-Comm Inc. · US · Technologyransombarracuda reclama a Namyang Industrial Co., Ltd. \ NAMYANG NEXMO · KR · Manufacturingransombarracuda reclama a RS Automation Co., Ltd. · CN · Manufacturingransomthreeam reclama a clubonecasino.com · US · Hospitalityransomdragonforce reclama a Primary Eye Care · US · Healthcareransomorova reclama a St Theresa Catholic Church · US · Otherransomorova reclama a Stoneybrook West Master Association, Inc · US · Otherransomorova reclama a Stonecrest POA · US · Otherransomqilin reclama a Bloom Financials · GB · Financial Servicesransomorova reclama a Magnolia Dental · US · Healthcareransomorova reclama a Country Oaks Veterinary Clinic · US · Healthcareransomorova reclama a David King Architect · US · Professional Servicesransomorova reclama a Woodside Ranch · US · Agriculture and Food Productionransombarracuda reclama a Ferrell \ Skyline Implants & Periodontics \ Dr. Scott Ferguson · Healthcareransombarracuda reclama a Micro-Comm Inc. · US · Technologyransombarracuda reclama a Namyang Industrial Co., Ltd. \ NAMYANG NEXMO · KR · Manufacturingransombarracuda reclama a RS Automation Co., Ltd. · CN · Manufacturingransomthreeam reclama a clubonecasino.com · US · Hospitality
← All CVEs
CVE WatchAug 6, 2026

CVE-2026-18996

A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.che

CVSS

6.3

Medium

EPSS

KEV

Exploit Today

0-100

Published: Aug 6, 2026 · Last modified: Aug 6, 2026 · CWE-266

EPSS · 30d

Not enough EPSS history yet.

Technical description

A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command Handler. Such manipulation leads to incorrect privilege assignment. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-189936.3 MED
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used.5h
CVE-2026-189766.3 MED
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report.8h
CVE-2026-200285.0 MED
A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.16h
CVE-2026-176268.8 HIG
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.5h
CVE-2026-100599.1 CRI
0A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.19h
CVE-2026-188172.2 LOW
0A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult. The presence of this vulnerability remains uncertain at this time. Upgrading to version 2.3.3 can resolve this issue. The affected component should be upgraded. The project maintainer explains: "While the problem exists, I'm not really sure if it's a vulnerability. (....) Even though the back gives a token for a deactivate user, none of the endpoints actually work. That said, we will fix it, but so far it seems more like a bug instead of a vulnerability."18h