[vulnfeed] 9 critical CVEs — 2026-07-24 16:00 UTC
vulnfeed
Critical alert — 2026-07-24 17:57 UTC
9 new critical CVEs
in the last 5 hours — 9 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-56163CRITICAL
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized atta
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-57106CRITICAL
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
CVE-2026-58630CRITICAL
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a netw
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
GHSA-w28w-gp39-m4p6CRITICAL
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
## Summary
The TypeScript Nunjucks renderer evaluated untrusted `.prompty` template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and pr
CVSS 10.0
GHSA-rjg6-39jm-rgg4CRITICAL
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
### Am I affected?
You are affected if your application registers the `@better-auth/scim` plugin and lets authenticated users generate SCIM tokens. The default `canGenerateToken` policy was affected,
CVSS 9.9
CVE-2026-59940CRITICAL
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deser
## Summary
A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference table w
CVSS 9.8
GHSA-7gfh-x38p-prh3CRITICAL
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fi
### Summary
Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq ("Prototype Pollution in #set path assignment
CVSS 9.8
CVE-2026-12503CRITICAL
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to mak
CVSS 9.2
GHSA-r277-6w6q-xmqwCRITICAL
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
### Summary
`ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: