Vulnfeed

Archives
Log in
Subscribe
July 16, 2026

[vulnfeed] 11 critical CVEs — 2026-07-16 20:00 UTC

vulnfeed Critical alert — 2026-07-16 21:29 UTC
11 new critical CVEs in the last 5 hours — 11 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-45336CRITICAL
HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracki
HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used
CVSS 10.0
CVE-2026-45568CRITICAL
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK Pro
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to url
CVSS 9.9
CVE-2026-46512CRITICAL
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted tem
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/Dialp
CVSS 9.9
CVE-2026-46562CRITICAL
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorith
CVSS 9.8
CVE-2026-63087CRITICAL
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers t
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install
CVSS 9.3
CVE-2026-46515CRITICAL
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficien
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup
CVSS 9.3
CVE-2026-44632CRITICAL
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in t
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactor
CVSS 9.1
CVE-2026-46621CRITICAL
Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithm
Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through t
CVSS 9.1
CVE-2026-15422CRITICAL
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating th
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classifica
CVSS 9.1
CVE-2026-53713CRITICAL
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret D
### Impact The `to_absolute_normalized_path` function (security.lua:28-43) does not collapse redundant path separators (// → /). On Linux, `//etc/passwd` is equivalent to `/etc/passwd` (POSIX path se
CVSS 9.1
CVE-2026-63089CRITICAL
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuar
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 5 critical CVEs — 2026-07-17 00:00 UTC Older → [vulnfeed] 14 critical CVEs — 2026-07-16 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.