Vulnfeed

Archives
Log in
Subscribe
July 28, 2026

[vulnfeed] 4 critical CVEs — 2026-07-28 08:00 UTC

vulnfeed Critical alert — 2026-07-28 10:56 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-11756CRITICAL
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthen
CVSS 10.0
CVE-2026-15014CRITICAL
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to,
CVSS 9.8
CVE-2026-11841CRITICAL
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEng
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem direct
CVSS 9.4
CVE-2026-16462CRITICAL
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-07-28 12:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-07-27 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.