[vulnfeed] 10 critical CVEs — 2026-07-29 20:00 UTC
vulnfeed
Critical alert — 2026-07-29 21:25 UTC
10 new critical CVEs
in the last 5 hours — 1 actively exploited (CISA KEV) · 9 CVSS ≥ 9.0
New vulnerabilities
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac
CVSS 5.3
CVE-2026-16326CRITICAL
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, whi
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests f
CVSS 10.0
CVE-2026-67429CRITICAL
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_wit
CVSS 10.0
CVE-2026-54680CRITICAL
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, t
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go w
CVSS 9.9
CVE-2026-14529CRITICAL
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP cont
CVSS 9.4
CVE-2026-18236CRITICAL
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An a
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute un
CVSS 9.3
CVE-2026-41939CRITICAL
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.F
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrat
CVSS 9.3
CVE-2026-67426CRITICAL
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyt
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /r
CVSS 9.3
CVE-2026-8338CRITICAL
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted
CVSS 9.2
CVE-2026-51992CRITICAL
SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbi
SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: