[vulnfeed] 2 critical CVEs — 2026-07-09 12:00 UTC
vulnfeed
Critical alert — 2026-07-09 15:39 UTC
2 new critical CVEs
in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-56291CRITICAL
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploa
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVSS 10.0
CVE-2026-56292CRITICAL
A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lea
A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: