[vulnfeed] 2 critical CVEs — 2026-07-25 12:00 UTC
vulnfeed
Critical alert — 2026-07-25 14:07 UTC
2 new critical CVEs
in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-66012CRITICAL
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enfo
CVSS 10.0
CVE-2026-66013CRITICAL
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known as
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: