Vulnfeed

Archives
Log in
Subscribe
July 16, 2026

[vulnfeed] 7 critical CVEs — 2026-07-16 12:00 UTC

vulnfeed Critical alert — 2026-07-16 14:30 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2023-49899CRITICAL
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifyi
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
CVSS 9.8
CVE-2023-49900CRITICAL
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
CVSS 9.8
CVE-2026-22752CRITICAL
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.
CVSS 9.6
CVE-2026-63304CRITICAL
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php wher
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside si
CVSS 9.2
CVE-2026-63305CRITICAL
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notif
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Atta
CVSS 9.2
CVE-2026-63306CRITICAL
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy an
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private
CVSS 9.2
CVE-2026-11386CRITICAL
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advanta
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 14 critical CVEs — 2026-07-16 16:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-07-16 08:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.