[vulnfeed] 3 critical CVEs — 2026-07-28 12:00 UTC
vulnfeed
Critical alert — 2026-07-28 14:56 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-65880CRITICAL
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field ty
CVSS 10.0
CVE-2026-11841CRITICAL
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEng
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem direct
CVSS 9.4
CVE-2026-16462CRITICAL
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: