Vulnfeed

Archives
Log in
Subscribe
July 25, 2026

[vulnfeed] 2 critical CVEs — 2026-07-25 12:00 UTC

vulnfeed Critical alert — 2026-07-25 14:07 UTC
2 new critical CVEs in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-66012CRITICAL
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enfo
CVSS 10.0
CVE-2026-66013CRITICAL
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known as
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 6 critical CVEs — 2026-07-27 12:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-07-24 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.