[vulnfeed] 2 critical CVEs — 2026-07-28 16:00 UTC
vulnfeed
Critical alert — 2026-07-28 17:49 UTC
2 new critical CVEs
in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-66713CRITICAL
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component
in Apache Software Fou
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component
in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat
(only when Tribes clustering i
CVSS 9.8
CVE-2026-67174CRITICAL
Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon
Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities.
The tryResolveHTMLElement function treated any resolved string as H
CVSS 9.2
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: