Vulnfeed

Archives
Log in
Subscribe
July 1, 2026

[vulnfeed] 2 critical CVEs — 2026-07-01 08:00 UTC

vulnfeed Critical alert — 2026-07-01 11:36 UTC
2 new critical CVEs in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-11387CRITICAL
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and incl
CVSS 9.8
CVE-2026-10539CRITICAL
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under c
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorize
CVSS 9.5

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-07-01 12:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-07-01 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.