Vulnfeed

Archives
Log in
Subscribe
July 30, 2026

[vulnfeed] 7 critical CVEs — 2026-07-30 08:00 UTC

vulnfeed Critical alert — 2026-07-30 10:36 UTC
7 new critical CVEs in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-58046CRITICAL
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise
CVSS 9.9
CVE-2026-58066CRITICAL
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 ver
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Ass
CVSS 9.8
CVE-2026-44090CRITICAL
Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only pr
Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compro
CVSS 9.3
CVE-2026-44101CRITICAL
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconf
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data bei
CVSS 9.3
CVE-2026-44104CRITICAL
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum wi
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker
CVSS 9.3
CVE-2026-44108CRITICAL
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become ex
CVSS 9.3
CVE-2026-7849CRITICAL
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a com
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 5 critical CVEs — 2026-07-30 12:00 UTC Older → [vulnfeed] 4 critical CVEs — 2026-07-30 04:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.