PULSE
LIVE46signals / 24h
FEED
ransomdirewolf reclama a BigSpark · AI · Not Foundransomanubis reclama a Cleaver-Brooks · US · Manufacturingransomdeadlock reclama a LT Group / Fortune Tobacco Corp · PH · Manufacturingransomgenesis reclama a Consolidated Medical Practices of Memphis · US · Healthcareransomgenesis reclama a Interim HealthCare (Oklahoma and Tulsa) · US · Healthcareransomdirewolf reclama a Chat Jurídico · BR · Professional Servicesransomdirewolf reclama a Merge · US · Technologyransomqilin reclama a HIGEN MOTOR(critical data) · KR · Manufacturingransomdirewolf reclama a Swyft Inc. · US · Technologyransomdirewolf reclama a AliveCor, Inc. · US · Healthcareransomdirewolf reclama a Statista GmbH · DE · Professional Servicesransomdirewolf reclama a Quironsalud · ES · Healthcareransomdirewolf reclama a Health Carousel · PH · Healthcareransomdirewolf reclama a Fondo · Financial Servicesransomdirewolf reclama a BigSpark · AI · Not Foundransomanubis reclama a Cleaver-Brooks · US · Manufacturingransomdeadlock reclama a LT Group / Fortune Tobacco Corp · PH · Manufacturingransomgenesis reclama a Consolidated Medical Practices of Memphis · US · Healthcareransomgenesis reclama a Interim HealthCare (Oklahoma and Tulsa) · US · Healthcareransomdirewolf reclama a Chat Jurídico · BR · Professional Servicesransomdirewolf reclama a Merge · US · Technologyransomqilin reclama a HIGEN MOTOR(critical data) · KR · Manufacturingransomdirewolf reclama a Swyft Inc. · US · Technologyransomdirewolf reclama a AliveCor, Inc. · US · Healthcareransomdirewolf reclama a Statista GmbH · DE · Professional Servicesransomdirewolf reclama a Quironsalud · ES · Healthcareransomdirewolf reclama a Health Carousel · PH · Healthcareransomdirewolf reclama a Fondo · Financial Services
← All CVEs
CVE WatchAug 10, 2026

CVE-2026-72728

Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed t

CVSS

6.3

Medium

EPSS

KEV

Exploit Today

0-100

Published: Aug 10, 2026 · Last modified: Aug 10, 2026 · CWE-20

EPSS · 30d

Not enough EPSS history yet.

Technical description

Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-728679.9 CRI
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct compose.update request to store a malicious customGitBranch, branch, gitlabBranch, bitbucketBranch, or giteaBranch. A low-privileged authenticated user can trigger compose.deploy, which passes the stored branch to shell-based Git clone commands in packages/server/src/utils/providers/git.ts, github.ts, gitlab.ts, bitbucket.ts, and gitea.ts, resulting in arbitrary host command execution. This issue is fixed in version 0.29.13.5h
CVE-2026-42537
0Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.13h
CVE-2026-40920
0Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.13h
CVE-2026-21083
0Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.6h
CVE-2026-21072
0Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.6h
CVE-2026-21071
0Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.6h