[vulnfeed] 10 critical CVEs — 2026-07-30 16:00 UTC
vulnfeed
Critical alert — 2026-07-30 17:54 UTC
10 new critical CVEs
in the last 5 hours — 10 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-59309CRITICAL
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious ac
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gai
CVSS 9.8
CVE-2026-59310CRITICAL
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with netwo
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVSS 9.8
CVE-2026-15435CRITICAL
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote att
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted UR
CVSS 9.8
CVE-2026-28323CRITICAL
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
CVSS 9.8
CVE-2026-4978CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vis
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection.
This issue affects Traffic Analysis Sys
CVSS 9.8
CVE-2026-12940CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability
CVSS 9.8
CVE-2026-47876CRITICAL
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious a
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual networ
CVSS 9.3
CVE-2026-54363CRITICAL
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attac
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as en
CVSS 9.3
CVE-2026-11707CRITICAL
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cro
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
CVSS 9.3
CVE-2026-53431CRITICAL
Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained
Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: