[vulnfeed] 12 critical CVEs — 2026-08-01 16:00 UTC
vulnfeed
Critical alert — 2026-08-01 17:28 UTC
12 new critical CVEs
in the last 5 hours — 12 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-67305CRITICAL
FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual ch
FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-pr
CVSS 9.4
CVE-2026-67330CRITICAL
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 throu
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject pro
CVSS 9.4
CVE-2026-67336CRITICAL
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit
CVSS 9.4
CVE-2026-66402CRITICAL
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weak
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names().
CVSS 9.3
CVE-2026-67289CRITICAL
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the serve
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client'
CVSS 9.3
CVE-2026-67292CRITICAL
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libf
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte respons
CVSS 9.3
CVE-2026-67293CRITICAL
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulne
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treat
CVSS 9.3
CVE-2026-67294CRITICAL
FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during
FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_
CVSS 9.3
CVE-2026-67324CRITICAL
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pa
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes atta
CVSS 9.3
CVE-2026-67340CRITICAL
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Ja
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authen
CVSS 9.3
CVE-2026-67341CRITICAL
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION stat
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript co
CVSS 9.3
CVE-2026-67342CRITICAL
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissio
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: