[vulnfeed] 35 critical CVEs — 2026-07-14 20:00 UTC
vulnfeed
Critical alert — 2026-07-14 21:28 UTC
35 new critical CVEs
in the last 5 hours — 4 actively exploited (CISA KEV) · 31 CVSS ≥ 9.0
New vulnerabilities
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorize
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
CVSS 5.3
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place int
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make re
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identifie
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could pot
CVE-2026-57092CRITICAL
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
CVE-2026-54052CRITICAL
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
## Impact
In multi-tenant HTTP deployments — where a single n8n-mcp server serves several tenants — the locally stored workflow version history (the automatic backups taken before workflow updates) w
CVSS 9.9
CVE-2026-42990CRITICAL
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a ne
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-49172CRITICAL
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a netwo
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-50522CRITICAL
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute co
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-54990CRITICAL
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a net
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-58644CRITICAL
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute co
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-50447CRITICAL
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-50518CRITICAL
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a netwo
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-55010CRITICAL
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute co
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-55944CRITICAL
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code ov
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
CVSS 9.8
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: