[vulnfeed] 4 critical CVEs — 2026-06-29 20:00 UTC
vulnfeed
Critical alert — 2026-06-29 21:49 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-57498CRITICAL
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Serve
CVSS 9.6
CVE-2026-11720CRITICAL
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox.
When constructi
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox.
When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into th
CVSS 9.3
CVE-2026-56782CRITICAL
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoint
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_k
CVSS 9.3
CVE-2026-37637CRITICAL
An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.
An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: