Vulnfeed

Archives
Log in
Subscribe
July 23, 2026

[vulnfeed] 4 critical CVEs — 2026-07-23 08:00 UTC

vulnfeed Critical alert — 2026-07-23 10:37 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-14282CRITICAL
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more p
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includi
CVSS 9.8
CVE-2026-15011CRITICAL
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'pa
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic functi
CVSS 9.8
CVE-2026-15015CRITICAL
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying tha
CVSS 9.8
CVE-2026-16723CRITICAL
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is ex
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required,
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 24 critical CVEs — 2026-07-23 12:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-07-23 00:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.