VulncastBriefing archive

Daily Brief - 2026-07-15

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-48325

critical · CVSS 9.3 · Adobe ColdFusion

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

  • Missing Authentication
  • Remote Code Execution
  • web application server
  • scripting engine

CVE-2026-56451

critical · CVSS 10 · Siemens Opcenter X

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

  • Authentication Bypass
  • Impersonation
  • web application
  • authentication framework

CVE-2026-58644

critical · CVSS 9.8 · Microsoft SharePoint

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  • Deserialization of Untrusted Data
  • Remote Code Execution
  • content management system
  • web application

CVE-2026-59083

critical · CVSS 9.1 · Apache Tomcat

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

  • Security Constraint Bypass
  • web server
  • application server

CVE-2026-62422

critical · CVSS 10 · JetBrains YouTrack

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

  • Authentication Bypass
  • web application
  • issue tracking