Vulnfeed

Archives
Log in
Subscribe
July 12, 2026

[vulnfeed] 2 critical CVEs — 2026-07-12 12:00 UTC

vulnfeed Critical alert — 2026-07-12 14:02 UTC
2 new critical CVEs in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-61876CRITICAL
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjac
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN conta
CVSS 9.4
CVE-2026-56271CRITICAL
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_tok
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 27 critical CVEs — 2026-07-13 08:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-07-11 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.