[vulnfeed] 5 critical CVEs — 2026-07-30 12:00 UTC
vulnfeed
Critical alert — 2026-07-30 14:38 UTC
5 new critical CVEs
in the last 5 hours — 5 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-59309CRITICAL
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious ac
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gai
CVSS 9.8
CVE-2026-59310CRITICAL
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with netwo
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVSS 9.8
CVE-2026-47876CRITICAL
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious a
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual networ
CVSS 9.3
CVE-2026-54363CRITICAL
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attac
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as en
CVSS 9.3
CVE-2026-18363CRITICAL
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: