[vulnfeed] 4 critical CVEs — 2026-07-24 20:00 UTC
vulnfeed
Critical alert — 2026-07-24 21:33 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-62379CRITICAL
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
## Summary
A pre-authentication remote code execution vulnerability affects OpenAM. The
remote authentication endpoint (`/authservice`, PLL) accepts an XML element
that names an arbitrary Java class,
CVSS 9.8
CVE-2026-62835CRITICAL
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVSS 9.3
CVE-2026-48021CRITICAL
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain th
CVSS 9.1
GHSA-r277-6w6q-xmqwCRITICAL
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
### Summary
`ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: