[vulnfeed] 11 critical CVEs — 2026-07-15 20:00 UTC
vulnfeed
Critical alert — 2026-07-15 21:27 UTC
11 new critical CVEs
in the last 5 hours — 11 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-53513CRITICAL
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/s
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-con
CVSS 9.6
CVE-2026-62948CRITICAL
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 clien
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_writ
CVSS 9.6
CVE-2026-46684CRITICAL
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token h
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), wh
CVSS 9.5
CVE-2026-52842CRITICAL
Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ acr
Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page or
CVSS 9.3
CVE-2026-52843CRITICAL
Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHtt
Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credenti
CVSS 9.3
CVE-2026-50562CRITICAL
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and e
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs
CVSS 9.3
CVE-2026-46421CRITICAL
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and ca
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, c
CVSS 9.3
CVE-2026-49445CRITICAL
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Ciliu
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-a
CVSS 9.2
CVE-2026-53512CRITICAL
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcPro
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates
CVSS 9.1
CVE-2026-62378CRITICAL
RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, th
RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx
CVSS 9.0
CVE-2026-45534CRITICAL
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasourc
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getPropert
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: