[vulnfeed] 15 critical CVEs — 2026-07-09 16:00 UTC
vulnfeed
Critical alert — 2026-07-09 18:15 UTC
15 new critical CVEs
in the last 5 hours — 15 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-15308CRITICAL
The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated untermi
The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated unterminated markup declarations when
processing uncontrolled data.
CVSS 10.0
CVE-2026-12116CRITICAL
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP d
CVSS 9.8
CVE-2025-27462CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corresp
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
The Windows PV drivers expose various facilities to userspace. Sever
CVSS 9.4
CVE-2025-27463CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corresp
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several
CVSS 9.4
CVE-2025-27464CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corresp
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several
CVSS 9.4
CVE-2025-58146CRITICAL
There are multiple issues.
1. Updates to the XAPI database sanitise input strings, but try
generating th
There are multiple issues.
1. Updates to the XAPI database sanitise input strings, but try
generating the notification using the unsanitised input. This
causes the database's event thread t
CVSS 9.4
CVE-2025-58151CRITICAL
varstored is a component of the Xapi toolstack handling UEFI Variables
for a VM. It has a communication path
varstored is a component of the Xapi toolstack handling UEFI Variables
for a VM. It has a communication path with OVMF inside the VM involving
mapping a buffer prepared by OVMF.
Within varstored, th
CVSS 9.4
CVE-2026-23556CRITICAL
When oxenstored is tearing a domain down, the node data is cleaned up
but the usage counts are leaked.
When t
When oxenstored is tearing a domain down, the node data is cleaned up
but the usage counts are leaked.
When the domain ID is eventually reused, the new domain can create fewer
nodes before beeing dee
CVSS 9.4
CVE-2026-23559CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corresp
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different roles, using Role
B
CVSS 9.4
CVE-2026-23560CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corresp
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different roles, using Role
Bas
CVSS 9.4
CVE-2026-23561CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corresp
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different roles, using Role
Bas
CVSS 9.4
CVE-2026-23562CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corresp
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different roles, using Role
Bas
CVSS 9.4
CVE-2026-42486CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities corresp
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different roles, using Role
Bas
CVSS 9.4
CVE-2026-56292CRITICAL
A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lea
A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.
CVSS 9.2
CVE-2026-14261CRITICAL
A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reins
A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a rem
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: