[vulnfeed] 13 critical CVEs — 2026-06-30 16:00 UTC
vulnfeed
Critical alert — 2026-06-30 18:17 UTC
13 new critical CVEs
in the last 5 hours — 13 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-48276CRITICAL
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the cur
CVSS 10.0
CVE-2026-48277CRITICAL
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability tha
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitatio
CVSS 10.0
CVE-2026-48281CRITICAL
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability tha
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitatio
CVSS 10.0
CVE-2026-48282CRITICAL
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Rest
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execut
CVSS 10.0
CVE-2026-48283CRITICAL
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the cur
CVSS 10.0
CVE-2026-48286CRITICAL
Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization
Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current
CVSS 10.0
CVE-2026-44946CRITICAL
A SAML authentication replay vulnerability in Rancher's Assertion
Consumer Service (ACS) handler did not enfo
A SAML authentication replay vulnerability in Rancher's Assertion
Consumer Service (ACS) handler did not enforce
one-time use of SAML assertion, potentially allowing person in the middle attacks aga
CVSS 9.5
CVE-2026-58116CRITICAL
LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI ac
LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or T
CVSS 9.3
CVE-2026-48313CRITICAL
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Rest
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system
CVSS 9.3
CVE-2026-48315CRITICAL
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability tha
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker
CVSS 9.3
CVE-2026-58172CRITICAL
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows d
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based access restrictions by sending WebSocket upgrade requ
CVSS 9.3
CVE-2026-58370CRITICAL
Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab
Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author name (commit.author.
CVSS 9.2
CVE-2026-6556CRITICAL
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expression
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: