[vulnfeed] 8 critical CVEs — 2026-07-15 16:00 UTC
vulnfeed
Critical alert — 2026-07-15 17:43 UTC
8 new critical CVEs
in the last 5 hours — 8 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-50148CRITICAL
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add
CVSS 10.0
CVE-2026-44986CRITICAL
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profi
CVSS 9.9
CVE-2026-61736CRITICAL
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing
CVSS 9.3
CVE-2026-61740CRITICAL
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed wi
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed beca
CVSS 9.3
CVE-2026-52842CRITICAL
Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ acr
Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page or
CVSS 9.3
CVE-2026-52843CRITICAL
Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHtt
Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credenti
CVSS 9.3
CVE-2026-42533CRITICAL
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a stri
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map outp
CVSS 9.2
CVE-2026-62378CRITICAL
RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, th
RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: