Vulnfeed

Archives
Log in
Subscribe
July 28, 2026

[vulnfeed] 3 critical CVEs — 2026-07-28 12:00 UTC

vulnfeed Critical alert — 2026-07-28 14:56 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-65880CRITICAL
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field ty
CVSS 10.0
CVE-2026-11841CRITICAL
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEng
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem direct
CVSS 9.4
CVE-2026-16462CRITICAL
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-07-28 16:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-07-28 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.