VulncastBriefing archive

Daily Brief - 2026-07-22

· 4 vulnerabilities · 5 min listen

▶ Listen to this briefing

CVE-2026-16411

critical · CVSS 9.8 · Mozilla Firefox

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153.

  • Memory Corruption
  • Remote Code Execution
  • web browser

CVE-2026-28304

critical · CVSS 9.1 · SolarWinds Serv-U

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

  • Remote Code Execution
  • file transfer software

CVE-2026-61211

critical · CVSS 9.9 · Oracle RDBMS

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

  • Remote Code Execution
  • Unauthorized Access
  • database server
  • oracle net

CVE-2026-8933

high · CVSS 7.8 · Canonical snap-confine

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.

  • Privilege Escalation
  • containerization
  • linux kernel