Vulnfeed

Archives
Log in
Subscribe
July 27, 2026

[vulnfeed] 15 critical CVEs — 2026-07-27 16:00 UTC

vulnfeed Critical alert — 2026-07-27 18:00 UTC
15 new critical CVEs in the last 5 hours — 15 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-16812CRITICAL
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to acce
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may
CVSS 10.0
CVE-2026-63077CRITICAL
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the ag
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVSS 9.8
CVE-2026-66395CRITICAL
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin read
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:
CVSS 9.4
CVE-2026-66398CRITICAL
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows aut
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write a
CVSS 9.4
CVE-2026-61511CRITICAL
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote
CVSS 9.3
CVE-2026-59527CRITICAL
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVSS 9.3
CVE-2026-59533CRITICAL
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
CVSS 9.3
CVE-2026-59538CRITICAL
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
CVSS 9.3
CVE-2026-59549CRITICAL
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVSS 9.3
CVE-2026-59550CRITICAL
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
CVSS 9.3
CVE-2026-66394CRITICAL
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization th
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cl
CVSS 9.3
CVE-2026-66396CRITICAL
SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and
SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute in
CVSS 9.3
CVE-2026-65766CRITICAL
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper valid
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector
CVSS 9.2
CVE-2026-65876CRITICAL
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper valid
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vecto
CVSS 9.2
CVE-2026-55953CRITICAL
The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the
The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The clie
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-07-27 20:00 UTC Older → [vulnfeed] 6 critical CVEs — 2026-07-27 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.