[vulnfeed] 9 critical CVEs — 2026-07-24 00:00 UTC
vulnfeed
Critical alert — 2026-07-24 03:51 UTC
9 new critical CVEs
in the last 5 hours — 9 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-42933CRITICAL
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which co
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.
CVSS 10.0
CVE-2026-56191CRITICAL
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVSS 10.0
CVE-2026-58275CRITICAL
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-62825CRITICAL
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a networ
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-50517CRITICAL
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVSS 9.9
CVE-2026-54120CRITICAL
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVSS 9.9
CVE-2026-56165CRITICAL
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVSS 9.8
CVE-2026-28698CRITICAL
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthor
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.
CVSS 9.2
CVE-2026-56160CRITICAL
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges ov
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: