[vulnfeed] 6 critical CVEs — 2026-07-07 20:00 UTC
vulnfeed
Critical alert — 2026-07-07 21:49 UTC
6 new critical CVEs
in the last 5 hours — 6 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-13019CRITICAL
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authenticatio
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access
CVSS 9.8
CVE-2026-53513CRITICAL
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
### Am I affected?
Users are affected if all of the following are true:
- Their application uses `@better-auth/sso` at a version `>= 0.1.0, < 1.6.11` on the stable line, or any `1.7.0-beta.x` on the
CVSS 9.6
CVE-2026-58473CRITICAL
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and callin
CVSS 9.3
CVE-2026-59800CRITICAL
9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/t
9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher,
CVSS 9.2
CVE-2026-59707CRITICAL
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoi
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized
CVSS 9.2
CVE-2026-53512CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
### Am I affected?
Users are affected if all of the following are true:
- Their application uses `better-auth` and has enabled at least one of: `oidcProvider()` (imported from `better-auth/plugins/o
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: