[vulnfeed] 5 critical CVEs — 2026-07-17 00:00 UTC
vulnfeed
Critical alert — 2026-07-17 03:44 UTC
5 new critical CVEs
in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-44181CRITICAL
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Sp
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the env
CVSS 10.0
CVE-2026-44182CRITICAL
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Sp
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server interpolates unt
CVSS 10.0
CVE-2026-14956CRITICAL
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms
CVSS 9.8
CVE-2026-62241CRITICAL
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-c
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/sca
CVSS 9.3
CVE-2026-62232CRITICAL
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the rege
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOT
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: