VulncastBriefing archive

Daily Brief - 2026-07-31

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-17699

high · CVSS 8.6 · Google Chrome

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

  • Use After Free
  • Sandbox Escape
  • web browser

CVE-2026-59309

critical · CVSS 9.8 · VMware vCenter

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

  • Authentication Bypass
  • virtualization platform
  • directory service

CVE-2026-66803

critical · CVSS 10 · Microsoft Azure Cosmos DB

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

  • Remote Code Execution
  • database
  • cloud platform

CVE-2026-7849

critical · CVSS 9.8 · Unknown

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.

  • Command Injection
  • unknown

CVE-2026-9322

high · CVSS 7.5 · IBM WebSphere Application Server

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

  • Denial of Service
  • java application server
  • web server