Vulnfeed

Archives
Log in
Subscribe
July 8, 2026

[vulnfeed] 2 critical CVEs — 2026-07-08 20:00 UTC

vulnfeed Critical alert — 2026-07-08 21:37 UTC
2 new critical CVEs in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-52831CRITICAL
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RC
## Summary Nuclio controller builds a `curl` invocation string for each cron trigger and stores it as the `args` of a Kubernetes CronJob container (`/bin/sh`, `-c`, `<command>`). Two fields in the tr
CVSS 10.0
CVE-2026-53649CRITICAL
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
# Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0) **Severity:** Critical **CVSS v3.1:** 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) **Affected versions:** Joro ≤ v1.1.0, proxy m
CVSS 9.6

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-07-09 04:00 UTC Older → [vulnfeed] 7 critical CVEs — 2026-07-08 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.