Vulnfeed

Archives
Log in
Subscribe
June 29, 2026

[vulnfeed] 3 critical CVEs — 2026-06-29 16:00 UTC

vulnfeed Critical alert — 2026-06-29 18:28 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-56290CRITICAL
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows upl
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVSS 10.0
CVE-2026-57331CRITICAL
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
CVSS 9.9
CVE-2026-41052CRITICAL
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
CVSS 9.4

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 4 critical CVEs — 2026-06-29 20:00 UTC Older → vulnfeed weekly: 10645 CVEs · 675 critical — 2026-06-21
Powered by Buttondown, the easiest way to start and grow your newsletter.