[vulnfeed] 3 critical CVEs — 2026-07-01 12:00 UTC
vulnfeed
Critical alert — 2026-07-01 15:17 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-57692CRITICAL
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation.
This issue
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation.
This issue affects PrivateContent: from n/a through 9.9.2.
CVSS 9.8
CVE-2026-14198CRITICAL
@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before
@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching middleware paths, while Fastify's underlying router preserves the encoding during
CVSS 9.1
CVE-2026-13603CRITICAL
The payment integration pretix-oppwa provides support
for the payment providers VR Payment, Hobex, and potent
The payment integration pretix-oppwa provides support
for the payment providers VR Payment, Hobex, and potentially others
based on Oppwa's technology. The integration of Oppwa, following their
offi
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: