[vulnfeed] 3 critical CVEs — 2026-06-29 16:00 UTC
vulnfeed
Critical alert — 2026-06-29 18:28 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-56290CRITICAL
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows upl
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVSS 10.0
CVE-2026-57331CRITICAL
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
CVSS 9.9
CVE-2026-41052CRITICAL
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
CVSS 9.4
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: