High
The PostgreSQL fuzzystrmatch bug needs a database login
CVE-2026-15742 can run code as the PostgreSQL operating-system user. The vendor score is 8.8 and the vector requires a database account. Fixed builds shipped on 13 August 2026. A public PoC path exists. CISA has not listed it.
Published 2m ago
Critical
OpenOffice Java bug has no released fix
CVE-2026-59265 can run code when a person opens a crafted document in Apache OpenOffice 4.1.16 or earlier. There is no CVSS score, no KEV listing, and no finished 4.1.17 release.
Published 1h ago
Critical
The Gotenberg public PoC is not a confirmed RCE
CVE-2026-40281 has a public repository and a CVSS 10.0 score. The vendor advisory describes unauthenticated file move, overwrite, and link creation inside the container. Code execution is not the published impact.
Published 1h ago
Opening the public record
ThreatWire is live as a record, not a firehose. X carries the short dispatch. The site carries the detail, and only after it is edited.
Published 6h ago