[vulnfeed] 15 critical CVEs — 2026-07-06 20:00 UTC
vulnfeed
Critical alert — 2026-07-06 21:52 UTC
15 new critical CVEs
in the last 5 hours — 15 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-48316CRITICAL
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability tha
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitatio
CVSS 10.0
CVE-2026-57572CRITICAL
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepte
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch argument
CVSS 10.0
CVE-2026-54769CRITICAL
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
### Advisory Details
**Title**: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
**Description**:
### Summary
Langroid is vulnerable to a critical Sandbox
CVSS 10.0
GHSA-vjc7-jrh9-9j86CRITICAL
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
---
title: Unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
product: 9Router
version: <= 0.4.41
severity: critical
cve_request: true
---
## Summary
Multiple critical
CVSS 10.0
CVE-2026-48614CRITICAL
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege esc
CVSS 9.9
CVE-2026-34038CRITICAL
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application depl
CVSS 9.9
CVE-2026-55500CRITICAL
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Crede
## Summary
The `/api/settings/database` endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without a
CVSS 9.9
CVE-2026-9181CRITICAL
ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this is
ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow access to sen
CVSS 9.8
CVE-2026-57571CRITICAL
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a down
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined
CVSS 9.6
CVE-2026-54496CRITICAL
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained b
### Summary
A soundness vulnerability in the variable-base scalar multiplication gadget of `halo2_gadgets` allowed a malicious prover to produce a valid proof for an Orchard Action with an *under-con
CVSS 9.3
CVE-2026-40138CRITICAL
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Suppo
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a ne
CVSS 9.2
CVE-2026-40139CRITICAL
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Suppo
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote att
CVSS 9.2
CVE-2026-42341CRITICAL
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When
CVSS 9.2
CVE-2026-49445CRITICAL
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket acce
### Impact
When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to
CVSS 9.2
CVE-2026-53486CRITICAL
Decompress: Archive extraction can create files and links outside of the target directory
### Impact
When extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the parsed entries, so it affects every for
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: