[vulnfeed] 4 critical CVEs — 2026-07-06 12:00 UTC
vulnfeed
Critical alert — 2026-07-06 12:21 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-14807CRITICAL
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remo
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and passwo
CVSS 9.3
CVE-2026-14808CRITICAL
Prog
Management System developed by PROG MIS has a Exposure of Sensitive
Information vulnerability, allowi
Prog
Management System developed by PROG MIS has a Exposure of Sensitive
Information vulnerability, allowing unauthenticated remote attackers to view
a specific page and obtain the database acco
CVSS 9.3
CVE-2026-12686CRITICAL
An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unautho
An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted within the same subdomain environment. The applicat
CVSS 9.3
CVE-2026-6900CRITICAL
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL.
This issue affects APR
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL.
This issue affects APROL: before R 4.4-01P5.
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: