Vulnfeed

Archives
Log in
Subscribe
July 24, 2026

[vulnfeed] 4 critical CVEs — 2026-07-24 20:00 UTC

vulnfeed Critical alert — 2026-07-24 21:33 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-62379CRITICAL
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote authentication endpoint (`/authservice`, PLL) accepts an XML element that names an arbitrary Java class,
CVSS 9.8
CVE-2026-62835CRITICAL
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVSS 9.3
CVE-2026-48021CRITICAL
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain th
CVSS 9.1
GHSA-r277-6w6q-xmqwCRITICAL
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
### Summary `ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-07-25 12:00 UTC Older → [vulnfeed] 9 critical CVEs — 2026-07-24 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.