Vulnfeed

Archives
Log in
Subscribe
July 7, 2026

[vulnfeed] 6 critical CVEs — 2026-07-07 20:00 UTC

vulnfeed Critical alert — 2026-07-07 21:49 UTC
6 new critical CVEs in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-13019CRITICAL
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authenticatio
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access
CVSS 9.8
CVE-2026-53513CRITICAL
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
### Am I affected? Users are affected if all of the following are true: - Their application uses `@better-auth/sso` at a version `>= 0.1.0, < 1.6.11` on the stable line, or any `1.7.0-beta.x` on the
CVSS 9.6
CVE-2026-58473CRITICAL
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and callin
CVSS 9.3
CVE-2026-59800CRITICAL
9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/t
9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher,
CVSS 9.2
CVE-2026-59707CRITICAL
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoi
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized
CVSS 9.2
CVE-2026-53512CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
### Am I affected? Users are affected if all of the following are true: - Their application uses `better-auth` and has enabled at least one of: `oidcProvider()` (imported from `better-auth/plugins/o
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-07-08 00:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-07-07 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.