Vulnfeed

Archives
Log in
Subscribe
July 21, 2026

[vulnfeed] 23 critical CVEs — 2026-07-21 16:00 UTC

vulnfeed Critical alert — 2026-07-21 17:50 UTC
23 new critical CVEs in the last 5 hours — 23 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-47392CRITICAL
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37,
CVSS 9.9
CVE-2026-47391CRITICAL
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example e
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` to
CVSS 9.8
CVE-2026-47393CRITICAL
PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a
PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API s
CVSS 9.8
CVE-2026-47396CRITICAL
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-fa
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured.
CVSS 9.8
CVE-2026-47410CRITICAL
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 h
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcode
CVSS 9.8
CVE-2026-47407CRITICAL
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, t
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and pro
CVSS 9.4
CVE-2026-65048CRITICAL
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() ac
CVSS 9.3
CVE-2026-64824CRITICAL
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability in the backup-restore function tha
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a cr
CVSS 9.3
CVE-2026-28302CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to pri
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrat
CVSS 9.1
CVE-2026-28304CRITICAL
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arb
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
CVSS 9.1
CVE-2026-28305CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to rem
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write acce
CVSS 9.1
CVE-2026-28306CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to el
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deploymen
CVSS 9.1
CVE-2026-28307CRITICAL
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be el
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
CVSS 9.1
CVE-2026-28308CRITICAL
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to rem
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Window
CVSS 9.1
CVE-2026-28309CRITICAL
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to c
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 14 critical CVEs — 2026-07-21 20:00 UTC Older → [vulnfeed] 2 critical CVEs — 2026-07-21 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.