VulncastBriefing archive

Daily Brief - 2026-07-09

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-54061

critical · CVSS 9.1 · Dgraph Alpha

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the receiver calls `Prepare()` before processing the stream. This operation deletes and replaces the existing DB data. Version 25.3.5 patches the issue.

  • Improper Authentication
  • Improper Authorization
  • database
  • graphql

CVE-2026-56086

high · CVSS 8.8 · Dell PowerProtect Data Domain

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

  • Broken Access Control
  • data protection
  • storage appliance

CVE-2026-56843

critical · CVSS 9.9 · WebPros Plesk

Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user.

  • Authorization Bypass
  • Information Disclosure
  • Remote Code Execution
  • web application
  • api

CVE-2026-60002

high · CVSS 7.7 · OpenSSH

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

  • Use After Free
  • remote access
  • security protocol

CVE-2026-9695

critical · CVSS 9.8 · Dassault Systemes DELMIA Apriso

An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.

  • Improper Authentication
  • enterprise software