← Back to the live CVE advisory feed

CVE-2026-55580: Product identification pending

Severity
8.6 (HIGH)
Affected versions
Before 0.6.0
Fixed version
0.6.0.
Patch status
Patched
Published
2026-08-25T16:16:55.317
Modified
2026-08-25T17:17:32.743

Why it matters

This matters because the affected product may allow code execution. Prioritize systems that are internet-facing or have privileged access to other infrastructure.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployment without a security policy. SecurityValidator.validateCommand in security.go then short-circuits and allows every command supplied to the shell_exec MCP tool, so an LLM connected over stdio can execute unrestricted OS commands as the mcp-shell process user. The README from-source installation and MCP client configuration omit MCP_SHELL_SEC_CONFIG_FILE, making the insecure state the documented default. This issue is fixed in version 0.6.0.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: AUG 26, 2026 12:00 AM UTC
771 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-77998
SAML SSO for Joomla extension for Joomla
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-76193
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-76195
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-76197
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-65083
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-65093
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-13214
Product identification pending
Reporter: VULNERABILITIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-78477
Jawn
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-78568
Total Donations
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-78570
Total Donations
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-49845
Product identification pending PATCH
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-16286
Product identification pending PATCH
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-55546
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-45018
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-77136
Extension "powermail"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
9.5
CRITICAL
VIEW RECORD
CVE-2026-78683
Product identification pending PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-57909
WatchGuard Agent
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.4
CRITICAL
VIEW RECORD
CVE-2026-56705
adminer PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-56710
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-72699
grav PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-72702
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-78676
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-63586
Product identification pending
Reporter: INFO
9.3
CRITICAL
VIEW RECORD
CVE-2026-77138
Extension "HTML5 Video Player vs. Powermail"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
9.3
CRITICAL
VIEW RECORD
CVE-2026-57910
WatchGuard Agent
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.3
CRITICAL
VIEW RECORD
CVE-2026-79657
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2022-51000
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2024-58377
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2024-58378
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2025-71407
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79675
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79774
winter PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79782
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79787
alluxio
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-80104
DB-GPT
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79911
N600R
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-78379
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
9.2
CRITICAL
VIEW RECORD
CVE-2026-80138
clipbucket-v5
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-79664
Product identification pending PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-55536
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-55640
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-62862
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-19892
InfusedWoo Pro
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-16601
CM Map Locations – Visualize and share your locations in a few clicks
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-59769
FA-50
Reporter: VULTURES
8.8
HIGH
VIEW RECORD
CVE-2026-63587
Product identification pending
Reporter: INFO
8.8
HIGH
VIEW RECORD
CVE-2026-77141
Extension "Club Directory"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
8.8
HIGH
VIEW RECORD
CVE-2026-77142
Extension "Industry Directory"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
8.8
HIGH
VIEW RECORD
CVE-2026-77143
Extension "Forum"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
8.8
HIGH
VIEW RECORD
CVE-2026-49050
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-19949
All-in-One WP Migration and Backup
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-79662
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-55541
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2022-50999
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-79674
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-24170
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-55585
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55637
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-65091
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-56709
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-72700
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-75574
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-76839
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-76846
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-78677
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-78681
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-78682
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-67578
FA-50
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-77140
Extension "Telephone Directory"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
8.7
HIGH
VIEW RECORD
CVE-2026-12600
Innodata Labs
Reporter: CVE-COORDINATION
8.7
HIGH
VIEW RECORD
CVE-2026-59335
UAA PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-79658
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-79665
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-57863
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2021-47996
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2022-50998
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2023-54354
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2025-71346
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2025-71406
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-79769
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-79770
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-80049
airbyte-platform
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-77357
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-62865
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-63403
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-56703
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-72696
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-78675
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-78685
Product identification pending
Reporter: TWCERT
8.6
HIGH
VIEW RECORD
CVE-2026-12878
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-55534
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-55539
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-55580
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-79784
vocos
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-55557
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-75496
Product identification pending PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
8.6
HIGH
VIEW RECORD
CVE-2026-75497
QloApps PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
8.6
HIGH
VIEW RECORD
CVE-2026-75498
QloApps PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
8.6
HIGH
VIEW RECORD
CVE-2026-78680
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-66109
SKYSEA Client View
Reporter: VULTURES
8.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.