Vulnfeed

Archives
Log in
Subscribe
July 15, 2026

[vulnfeed] 3 critical CVEs — 2026-07-15 12:00 UTC

vulnfeed Critical alert — 2026-07-15 14:17 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-56699CRITICAL
Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk r
Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smu
CVSS 10.0
CVE-2026-61451CRITICAL
The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_b
The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() fun
CVSS 9.4
CVE-2026-56400CRITICAL
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attacke
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 8 critical CVEs — 2026-07-15 16:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-07-15 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.