Vulnfeed

Archives
Log in
Subscribe
July 7, 2026

[vulnfeed] 4 critical CVEs — 2026-07-07 04:00 UTC

vulnfeed Critical alert — 2026-07-07 07:59 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-34037CRITICAL
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the sour
CVSS 9.9
CVE-2026-34047CRITICAL
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorizat
CVSS 9.9
CVE-2026-34048CRITICAL
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not en
CVSS 9.9
CVE-2026-14345CRITICAL
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulner
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postDa
CVSS 9.8

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-07-07 12:00 UTC Older → [vulnfeed] 15 critical CVEs — 2026-07-06 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.