Vulnfeed

Archives
Log in
Subscribe
July 14, 2026

[vulnfeed] 35 critical CVEs — 2026-07-14 20:00 UTC

vulnfeed Critical alert — 2026-07-14 21:28 UTC
35 new critical CVEs in the last 5 hours — 4 actively exploited (CISA KEV) · 31 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-56155HIGH KEV
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorize
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
CVSS 7.8
CVE-2026-56164MEDIUM KEV
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
CVSS 5.3
CVE-2026-15409UNKNOWN KEV
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place int
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make re
CVE-2026-15410UNKNOWN KEV
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identifie
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could pot
CVE-2026-57092CRITICAL
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
CVE-2026-54052CRITICAL
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
## Impact In multi-tenant HTTP deployments — where a single n8n-mcp server serves several tenants — the locally stored workflow version history (the automatic backups taken before workflow updates) w
CVSS 9.9
CVE-2026-42990CRITICAL
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a ne
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-49172CRITICAL
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a netwo
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-50522CRITICAL
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute co
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-54990CRITICAL
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a net
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-58644CRITICAL
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute co
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-50447CRITICAL
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-50518CRITICAL
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a netwo
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-55010CRITICAL
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute co
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-55944CRITICAL
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code ov
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
CVSS 9.8

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-07-15 00:00 UTC Older → [vulnfeed] 18 critical CVEs — 2026-07-14 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.