Vulnfeed

Archives
Log in
Subscribe
July 16, 2026

[vulnfeed] 14 critical CVEs — 2026-07-16 16:00 UTC

vulnfeed Critical alert — 2026-07-16 17:43 UTC
14 new critical CVEs in the last 5 hours — 14 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-45568CRITICAL
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK Pro
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to url
CVSS 9.9
CVE-2026-45695CRITICAL
Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side
Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP
CVSS 9.8
CVE-2026-46562CRITICAL
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorith
CVSS 9.8
CVE-2026-54733CRITICAL
The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory inte
The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration
CVSS 9.3
CVE-2026-59864CRITICAL
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin ge
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from
CVSS 9.3
CVE-2026-59865CRITICAL
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.langu
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version value
CVSS 9.3
CVE-2026-59866CRITICAL
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientCla
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both gene
CVSS 9.3
CVE-2026-63087CRITICAL
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers t
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install
CVSS 9.3
CVE-2026-63304CRITICAL
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php wher
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside si
CVSS 9.2
CVE-2026-63305CRITICAL
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notif
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Atta
CVSS 9.2
CVE-2026-63306CRITICAL
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy an
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private
CVSS 9.2
CVE-2026-44632CRITICAL
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in t
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactor
CVSS 9.1
CVE-2026-46621CRITICAL
Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithm
Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through t
CVSS 9.1
CVE-2026-11386CRITICAL
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advanta
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 11 critical CVEs — 2026-07-16 20:00 UTC Older → [vulnfeed] 7 critical CVEs — 2026-07-16 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.