[vulnfeed] 3 critical CVEs — 2026-07-28 20:00 UTC
vulnfeed
Critical alert — 2026-07-28 21:35 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-16498CRITICAL
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the st
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be use
CVSS 10.0
CVE-2026-50736CRITICAL
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the ap
CVSS 9.0
CVE-2026-50737CRITICAL
When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affect
When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because the apply worker runs at a privi
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: