VulncastBriefing archive

Daily Brief - 2026-07-29

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-11391

medium · CVSS 6.3 · Tanium Patch

Tanium addressed a SQL injection vulnerability in Patch.

  • SQL Injection
  • endpoint management

CVE-2026-11756

critical · CVSS 10 · Dassault Systèmes 3DEXPERIENCE

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

  • Deserialization of Untrusted Data
  • Remote Code Execution
  • desktop application
  • enterprise software

CVE-2026-14512

critical · CVSS 9.8 · IBM WebSphere Application Server

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

  • Remote Code Execution
  • Insecure Deserialization
  • application server

CVE-2026-47483

high · CVSS 8.2 · NVIDIA DCGM Exporter

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

  • Denial of Service
  • Information Disclosure
  • monitoring tool
  • container

CVE-2026-66713

critical · CVSS 9.8 · Apache Software Foundation Apache Axis2

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered to the cluster  channel and deserialized in  org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are  recommended to upgrade to version 2.0.1, which fixes this issue by removing the  clustering feature entirely.

  • Insecure Deserialization
  • Remote Code Execution
  • java
  • application server