Vulnfeed

Archives
Log in
Subscribe
July 2, 2026

[vulnfeed] 15 critical CVEs — 2026-07-02 16:00 UTC

vulnfeed Critical alert — 2026-07-02 18:09 UTC
15 new critical CVEs in the last 5 hours — 15 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-50746CRITICAL
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in U
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
CVSS 10.0
CVE-2026-56004CRITICAL
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could b
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service
CVSS 10.0
CVE-2026-50747CRITICAL
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL In
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host
CVSS 9.9
CVE-2026-50748CRITICAL
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vul
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host de
CVSS 9.9
CVE-2026-54402CRITICAL
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vul
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
CVSS 9.9
CVE-2026-55115CRITICAL
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (S
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
CVSS 9.9
CVE-2026-44935CRITICAL
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one
CVSS 9.9
CVE-2026-5524CRITICAL
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execu
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension
CVSS 9.8
CVE-2026-4767CRITICAL
Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authenti
Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
CVSS 9.8
CVE-2026-50027CRITICAL
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/
## Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete ### Summary All HTTP routes under `/api/documents/*` in `mcp-memory-service` are served without an
CVSS 9.8
CVE-2022-50973CRITICAL
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUp
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting
CVSS 9.3
CVE-2024-14037CRITICAL
Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achi
Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpo
CVSS 9.3
CVE-2026-58455CRITICAL
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote at
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authen
CVSS 9.2
CVE-2026-54400CRITICAL
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vuln
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
CVSS 9.1
CVE-2026-55116CRITICAL
A malicious actor with access to the network and under certain network configurations could exploit an Imprope
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthori
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-07-02 20:00 UTC Older → [vulnfeed] 24 critical CVEs — 2026-07-01 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.