[vulnfeed] 7 critical CVEs — 2026-07-31 16:00 UTC
vulnfeed
Critical alert — 2026-07-31 17:59 UTC
7 new critical CVEs
in the last 5 hours — 7 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-52855CRITICAL
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, placeholders in egg configuration-file templates allow a low-privilege
CVSS 9.9
CVE-2026-17561CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunication
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.
This issue affects Lo
CVSS 9.8
CVE-2026-54725CRITICAL
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-service
## Summary
The vault-secrets-webhook reads the `vault.security.banzaicloud.io/vault-addr` annotation from any ConfigMap or Secret being admitted and uses it as the Vault server address without any va
CVSS 9.6
CVE-2026-17351CRITICAL
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's exec
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statemen
CVSS 9.4
CVE-2026-17566CRITICAL
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQ
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop
CVSS 9.4
CVE-2026-58048CRITICAL
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
CVSS 9.4
CVE-2026-17349CRITICAL
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every co
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: