[vulnfeed] 17 critical CVEs — 2026-06-30 20:00 UTC
vulnfeed
Critical alert — 2026-06-30 21:52 UTC
17 new critical CVEs
in the last 5 hours — 17 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-10134CRITICAL
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in t
CVSS 10.0
CVE-2026-7873CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral mo
CVSS 9.9
CVE-2026-50566CRITICAL
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod crea
### Summary
A follow-up bypass of the round-4 PodSpec hardening (GHSA-gx55-f84r-v3r7, GHSA-wmgg-3p4h-48x7, GHSA-v455-mv2v-5g92). Those advisories validate and sanitize the `PodSpec` (`spec.runtime.po
CVSS 9.9
CVE-2026-50564CRITICAL
Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
### Summary
Fission's `Environment` CRD exposes `spec.runtime.podSpec` and `spec.builder.podSpec`, which are merged into the Kubernetes pod specs for runtime and builder pods. The merge logic propaga
CVSS 9.9
CVE-2026-50563CRITICAL
Fission Container Executor Function PodSpec Injection Leading to Node Escape
### Summary
Fission's Container Executor path lets a tenant supply `Function.spec.podspec` directly; the executor merges it into the executor-built podspec and creates a Deployment whose pods run the
CVSS 9.9
CVE-2026-50545CRITICAL
Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
### Summary
A stronger framing of the same root cause as GHSA-gx55-f84r-v3r7: the `Environment.spec.runtime.podSpec` / `spec.builder.podSpec` passthrough lacked validation, and `MergePodSpec` propaga
CVSS 9.9
CVE-2026-10109CRITICAL
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to imprope
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.
CVSS 9.8
CVE-2026-7803CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow
IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
CVSS 9.8
CVE-2026-7871CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full appli
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
CVSS 9.8
CVE-2026-10140CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state
CVSS 9.6
CVE-2026-58172CRITICAL
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows d
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based access restrictions by sending WebSocket upgrade requ
CVSS 9.3
CVE-2026-58138CRITICAL
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that all
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow defini
CVSS 9.3
CVE-2026-11708CRITICAL
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the admin
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
CVSS 9.3
CVE-2026-11712CRITICAL
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the admin
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
CVSS 9.3
CVE-2026-58370CRITICAL
Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab
Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author name (commit.author.
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: