[vulnfeed] 17 critical CVEs — 2026-07-29 16:00 UTC
vulnfeed
Critical alert — 2026-07-29 17:45 UTC
17 new critical CVEs
in the last 5 hours — 17 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-65884CRITICAL
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows use
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with a
CVSS 10.0
CVE-2026-65887CRITICAL
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassw
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these us
CVSS 10.0
CVE-2026-65888CRITICAL
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method a
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
CVSS 10.0
CVE-2026-54735CRITICAL
Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to ver
Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters
CVSS 10.0
CVE-2026-54680CRITICAL
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, t
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go w
CVSS 9.9
CVE-2026-65885CRITICAL
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE
CVSS 9.4
CVE-2026-9177CRITICAL
A Server-Side Template Injection (SSTI) vulnerability was identified
in the mail template functionality of th
A Server-Side Template Injection (SSTI) vulnerability was identified
in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This
flaw
allows an attacker wi
CVSS 9.4
CVE-2026-0667CRITICAL
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code ex
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over
CVSS 9.3
CVE-2026-60112CRITICAL
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows an
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraf
CVSS 9.3
CVE-2026-60113CRITICAL
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authenticati
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthent
CVSS 9.3
CVE-2026-67191CRITICAL
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows re
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malform
CVSS 9.3
CVE-2026-65889CRITICAL
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp me
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
CVSS 9.2
CVE-2026-65890CRITICAL
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors all
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
CVSS 9.2
CVE-2026-65886CRITICAL
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer al
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
CVSS 9.2
CVE-2026-67192CRITICAL
Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows u
Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a G
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: