Vulnfeed

Archives
Log in
Subscribe
July 20, 2026

[vulnfeed] 5 critical CVEs — 2026-07-20 12:00 UTC

vulnfeed Critical alert — 2026-07-20 14:36 UTC
5 new critical CVEs in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-64620CRITICAL
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfre
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the call
CVSS 9.3
CVE-2026-64621CRITICAL
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field o
CVSS 9.3
CVE-2026-64622CRITICAL
Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (
Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read routes, so even when an operator configure
CVSS 9.3
CVE-2026-57309CRITICAL
A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is abl
A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. Bec
CVSS 9.3
CVE-2026-63756CRITICAL
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint t
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticate
CVSS 9.2

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 8 critical CVEs — 2026-07-20 16:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-07-20 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.