[vulnfeed] 18 critical CVEs — 2026-07-14 16:00 UTC
vulnfeed
Critical alert — 2026-07-14 17:38 UTC
18 new critical CVEs
in the last 5 hours — 18 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-10577CRITICAL
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-acce
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticate
CVSS 10.0
CVE-2026-62390CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache K
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.
CVSS 9.8
CVE-2026-62392CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ap
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.
This issue
CVSS 9.8
CVE-2026-42990CRITICAL
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a ne
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-49172CRITICAL
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a netwo
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-50522CRITICAL
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute co
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-54990CRITICAL
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a net
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-58644CRITICAL
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute co
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-48561CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allow
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
CVSS 9.6
CVE-2026-55008CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Ser
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVSS 9.6
CVE-2026-59891CRITICAL
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryC
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checkin
CVSS 9.6
CVE-2026-15265CRITICAL
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to wr
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote c
CVSS 9.4
CVE-2026-49798CRITICAL
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVSS 9.3
CVE-2025-12011CRITICAL
A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remot
A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fau
CVSS 9.2
CVE-2025-12012CRITICAL
A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a m
A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: