Action1 5 Patch Tuesday 5 Vulnerability Digest August 2026 – Third-Party Updates

Vulnerability Digest August 2026 – Third-Party Updates

Published:
August 11, 2026
Last Updated:
August 11, 2026

By Jack Bicer

First 200 endpoints free, no feature limits.

No credit card required, full access to all features.

Vulnerability Digest August 2026 Updates – Third-Party Updates

This digest explains the most serious vulnerabilities in popular software that have been patched over the past month.

For even more information, join our next Patch Tuesday webinar and visit our Patch Tuesday Watch page.

Critical – Same Day DeploymentSAP NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud

SAP Security Update

“Critical vulnerabilities demand immediate action because a single unpatched system can become the weakest link across the enterprise.”

SAP has released security updates addressing three critical vulnerabilities affecting SAP NetWeaver Application Server ABAP, SAP Approuter, and SAP Commerce Cloud. These issues could allow attackers to compromise sensitive data, modify application content, or disrupt business operations if left unpatched. CVE-2026-44747 has a CVSS score of 9.9, which is Critical severity. CVE-2026-27690 has a CVSS score of 9.1, which is Critical severity. CVE-2026-44761 has a CVSS score of 9.1, which is Critical severity.

The update addresses a memory corruption issue in SAP NetWeaver Application Server ABAP that could enable unauthorized data access, modification, or system unavailability. It also resolves an HTTP Request Smuggling vulnerability in SAP Approuter that may expose user responses and impact service availability. In addition, the update removes the risk posed by publicly documented sample OAuth2 credentials in SAP Commerce Cloud that could otherwise allow unauthorized access to APIs and sensitive data. No verified real-world exploitation or public proof-of-concept has been confirmed for these vulnerabilities.

Critical – Same Day DeploymentAdobe Commerce and Experience Manager

“These critical weaknesses can turn trusted web platforms into a path for code execution and data exposure.”

Adobe has released updates addressing four critical vulnerabilities across Adobe Commerce and Adobe Experience Manager. CVE-2026-48356 allows dangerous file uploads that could lead to arbitrary code execution after user interaction. CVE-2026-48358 could allow arbitrary code execution without user interaction. CVE-2026-48356 has a CVSS score of 9.6, which is Critical severity. CVE-2026-48358 has a CVSS score of 9.1, which is Critical severity.

CVE-2026-48259 is a server-side request forgery vulnerability that could enable unauthorized server requests and code execution. CVE-2026-48359 is an XML external entity vulnerability that could expose sensitive files and lead to code execution. Both require low privileges but no user interaction. CVE-2026-48259 and CVE-2026-48359 each have a CVSS score of 9.6, which is Critical severity. No active exploitation is confirmed.

Critical – Same Day DeploymentBeyondTrust Remote Support

“Authentication is the front door—when it fails, everything behind it is at risk.”

BeyondTrust has released security updates for Remote Support and Privileged Remote Access to address four vulnerabilities affecting authentication, network communication, and web application components. The most critical issues, CVE-2026-40138 and CVE-2026-40139, are pre-authentication authentication bypass vulnerabilities that could allow an attacker to gain unauthorized access to affected appliances, including accounts with elevated privileges, when a specific authentication configuration is enabled. CVE-2026-40140 could allow an unauthenticated attacker to trigger a denial-of-service condition, while CVE-2026-40141 could enable an authenticated user with limited privileges to access resources beyond their intended authorization.

CVE-2026-40138 has a CVSS score of 9.2, which is Critical severity. CVE-2026-40139 has a CVSS score of 9.2, which is Critical severity. CVE-2026-40140 has a CVSS score of 8.7, which is High severity. CVE-2026-40141 has a CVSS score of 8.5, which is High severity. Based on the information provided, there is no verified exploitation associated with these vulnerabilities. Organizations using the affected products should apply the available updates to mitigate the authentication and access control risks.

Critical – Same Day DeploymentHTTP.sys Microsoft Windows 10 Version 1607

“A memory corruption weakness can turn network access into complete system compromise.”

Microsoft has patched CVE-2026-47291 in Windows 10 Version 1607. The vulnerability involves buffer and integer overflow conditions that could allow an attacker to corrupt memory and potentially execute arbitrary code on an affected system.

The CVSS score is 9.8, which is Critical severity. The potential for remote code execution makes this a high-impact risk for unpatched systems.

Critical – Same Day DeploymentZoom Workplace for Windows

“A single validation mistake can become a direct path to losing control of an account.”

Zoom Communications has released a security update for Zoom Workplace for Windows to address CVE-2026-53412, an improper input validation vulnerability (CWE-20). The issue affects the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. An unauthenticated attacker could exploit the vulnerability over the network to perform an account takeover. The CVSS score is 9.8, which is Critical severity.

The update strengthens input validation to prevent unauthorized account takeover through network-based attacks. There is no verified evidence of public proof-of-concept code or real-world exploitation associated with this vulnerability.

Critical – Same Day DeploymentTenable Agent

“Even trusted components can become dangerous when file boundaries are no longer enforced.”

Tenable has released a security update for Tenable Agent to address CVE-2026-15265, a path traversal vulnerability affecting Tenable Agent 11.2.0 and earlier supported versions. The vulnerability allows a privileged attacker to write arbitrary files outside the intended plugin directory, which could potentially lead to remote code execution. The CVSS score is 9.1, which is Critical severity.

The update strengthens file path validation and plugin handling to prevent unauthorized file writes outside the intended directory. There is no verified evidence of public proof-of-concept code or real-world exploitation associated with this vulnerability.

Zero-Day – Immediate DeploymentCursor

“A trusted development tool can become the attacker’s launcher when it executes the wrong binary.”

Cursor for Windows version 3.2.16 addresses a binary planting vulnerability that could allow arbitrary code execution in the context of the current user. The flaw allows a remote attacker to place a malicious git.exe file in a repository root. When a developer clones and opens the crafted repository, Cursor automatically resolves and executes the workspace-resident binary during IDE startup and on a recurring schedule without requiring additional user interaction. The vulnerability is associated with CWE-426 (Untrusted Search Path).

The CVSS score is 8.8, which is High severity. Based on the information provided, a public proof-of-concept (PoC) is available for this vulnerability.

Zero-Day – Immediate DeploymentRed Hat Enterprise Linux 10

“These flaws can break sandbox boundaries, crash exposed services, and corrupt critical system memory.”

Red Hat has released updates for five High-severity vulnerabilities affecting Red Hat Enterprise Linux 10. The fixes address a PipeWire sandbox escape, two remotely triggered libsoup denial-of-service flaws, an xdgmime heap buffer overflow, and a QEMU out-of-bounds write. Potential impacts include code execution outside a sandbox, service disruption, memory corruption, information disclosure, and privilege escalation.

CVE-2026-5674 has a CVSS score of 8.8, High severity. CVE-2026-15709 has a CVSS score of 7.5, High severity. CVE-2026-15711 has a CVSS score of 7.5, High severity. CVE-2026-16118 has a CVSS score of 7.1, High severity. CVE-2026-3842 has a CVSS score of 7.8, High severity. Public proof-of-concept code is identified for the two libsoup WebSocket denial-of-service vulnerabilities.

Zero-Day – Immediate DeploymentCheck Point Quantum Security Management & Security Gateway

“An authentication bypass in the management plane can turn a trusted security platform into an attacker’s strongest advantage.”

Check Point has released security updates addressing two Critical and one High severity vulnerabilities affecting Quantum Security Management, Multi-Domain Security Management, and Quantum Security Gateway. The fixes resolve authentication bypass and privilege escalation flaws that could allow attackers to gain administrative control, execute privileged commands, modify security policies, and compromise managed security infrastructure if exposed management servers are improperly configured.

CVE-2026-16232 has a CVSS score of 9.1, Critical severity. CVE-2026-62144 has a CVSS score of 9.1, Critical severity. CVE-2026-62145 has a CVSS score of 7.5, High severity. CVE-2026-16232 is being actively exploited in the wild. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with CVE-2026-62144 or CVE-2026-62145.

High with EoP or RCE – Expedited DeploymentMicrosoft Windows 10 Version 1607 (CVE-2026-54121) 8.8

 

“Closing one privilege gap today can prevent a much larger compromise tomorrow.”

 

This update addresses CVE-2026-54121 in Microsoft Windows 10 Version 1607. The vulnerability is associated with CWE-285, covering improper authorization that could allow elevation of privilege. The CVSS score is 8.8, which is High severity. No verified real-world exploitation or public proof-of-concept has been confirmed.

 

The patch reduces the risk of attackers gaining higher privileges on affected systems and strengthens the operating system’s security posture against unauthorized access through this vulnerability.

Critical – Same Day DeploymentOracle

 

“Twelve doors, one master key: when every lock reads 9.9 or higher, the enterprise isn’t choosing whether to patch, only how fast.”

 

Oracle has released fixes for twelve critical vulnerabilities spanning its product line, all requiring urgent attention. Nine carry the maximum CVSS score of 10.0, Critical severity: CVE-2026-47056 (Oracle Data Integrator), CVE-2026-60217 (Oracle Coherence), CVE-2026-60358 (Oracle Access Manager), CVE-2026-60360 (Oracle Unified Directory), CVE-2026-60365 (Oracle HTTP Server), CVE-2026-60366 (Oracle Platform Security for Java), CVE-2026-60379 and CVE-2026-60389 (Service Delivery Platform), and CVE-2026-60644 (Oracle WebCenter Content). Three more carry a CVSS score of 9.9, Critical severity: CVE-2026-61211 (Oracle Database Server), CVE-2026-60402 (TimesTen In-Memory Database), and CVE-2026-61146 (Oracle Commerce Guided Search / Oracle Commerce Experience Manager).

The breadth of affected products, from identity and directory services to databases and content management, means this update touches core enterprise infrastructure. Teams running any of these Oracle products should prioritize patching without delay.

Critical – Same Day DeploymentFirefox

 

“Every unpatched memory bug is a door left ajar — attackers only need one to walk through.”

 

Mozilla has patched three Critical memory safety flaws in Firefox. CVE-2026-16411 has a CVSS score of 9.8, Critical severity, and affects Firefox 152. CVE-2026-16412 has a CVSS score of 9.8, Critical severity, and affects Firefox ESR 140.12 and Firefox 152. CVE-2026-16360 has a CVSS score of 9.8, Critical severity, and affects Firefox ESR 115.37, Firefox ESR 140.12, and Firefox 152. All three stem from memory corruption bugs that could, with enough effort, be exploited to run arbitrary code.

The fixes ship in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. Update all affected Firefox and Thunderbird installations to the patched versions without delay.

Zero-Day – Immediate DeploymentMicrosoft Exchange Server 2016 Cumulative Update 23

“A single malicious email can become an entry point when systems remain unpatched.”

This patch addresses CVE-2026-42897, a cross-site scripting (CWE-79) vulnerability affecting Microsoft Exchange Server 2016 Cumulative Update 23. The CVSS score is 8.1, which is High severity. Verified active exploitation has been reported, making prompt deployment of the security update a priority. The vulnerability is not identified as Remote Code Execution (RCE) or Elevation of Privilege (EoP).

An attacker can exploit this vulnerability by sending a specially crafted email to a user. If the email is opened in Outlook Web Access (OWA) and the required user interaction occurs, arbitrary JavaScript can execute within the user’s browser session. Microsoft recommends installing the July 2026 Exchange Server Security Updates as soon as possible to protect against this vulnerability and the related CVE-2026-55008. Until the update is installed, the Exchange Emergency Mitigation Service (EEMS) provides automatic mitigation when enabled. After applying the July 2026 security updates, temporary mitigations deployed through EEMS or the EOMT script can be removed. Microsoft also advises against using Internet Explorer or Microsoft Edge in Internet Explorer Mode to access Outlook Web Access because those browsers do not support the required Content Security Policy (CSP) protections.

Zero-Day – Immediate DeploymentCisco Secure Firewall Management Center (FMC)

“Even low-privileged access can become a serious security risk when it’s built into the system.”

This patch addresses CVE-2026-20316, a CWE-259 (Use of Hard-coded Password) vulnerability affecting Cisco Secure Firewall Management Center (FMC). The CVSS score is 5.3, which is Medium severity. Verified active exploitation has been reported, resulting in an overall Red vulnerability rating despite the Medium CVSS score.

The vulnerability is caused by the presence of static credentials for a low-privileged account within the FMC web interface. An unauthenticated remote attacker can use these credentials to log in to an affected device and access sensitive information available to that account. While the attack surface is reduced when the FMC management interface is not exposed to the public internet, affected systems remain at risk. Cisco also notes that this vulnerability can be combined with other Cisco Secure FMC vulnerabilities to achieve privilege escalation, increasing its overall security impact. The vulnerability is not identified as Remote Code Execution (RCE) or Elevation of Privilege (EoP) on its own.

Critical – Same Day DeploymentVMware Cloud Foundation

“One unpatched virtualization platform can expose every workload it protects.”

This patch addresses multiple vulnerabilities affecting VMware Cloud Foundation components. CVE-2026-59309 has a CVSS score of 9.8, Critical severity, and allows an attacker with network access to vCenter to bypass authentication through the VMware Directory Service and gain unauthorized access. CVE-2026-47876 has a CVSS score of 9.3, Critical severity, and affects the VMXNET3 virtual network adapter in VMware ESX, allowing code execution on the host from a virtual machine with local administrative privileges. CVE-2026-41703 has a CVSS score of 7.6, High severity, and affects VMware ESX, Workstation, and Fusion through an out-of-bounds read that can result in information disclosure or, more commonly, a denial-of-service condition. CVE-2026-41709 has a CVSS score of 2.7, Low severity, and allows certain administrator actions to occur without sufficient logging.

The update resolves vulnerabilities that impact authentication, memory handling, and audit logging across VMware environments. While no verified real-world exploitation has been reported for these vulnerabilities, the presence of two Critical vulnerabilities—including an authentication bypass and a host code execution flaw—makes this a high-priority update. The host code execution vulnerability exhibits Remote Code Execution (RCE) and Elevation of Privilege (EoP) characteristics, while the out-of-bounds read vulnerability has RCE characteristics based on the supplied assessment.

Critical – Same Day DeploymentAdobe Campaign Classic

“When authorization breaks down, attackers don’t need an invitation.”

This patch addresses CVE-2026-48449, an Incorrect Authorization vulnerability (CWE-863) affecting Adobe Campaign Classic (ACC). The CVSS score is 10.0, which is Critical severity. No verified real-world exploitation has been reported.

The vulnerability could allow an attacker to achieve arbitrary code execution in the context of the current user by exploiting improper authorization controls. Exploitation does not require user interaction, increasing the potential impact on affected systems. Although the vulnerability is not identified as Remote Code Execution (RCE), it has Elevation of Privilege (EoP) characteristics because successful exploitation enables unauthorized execution within the user’s security context. Adobe has released an update to correct the authorization flaw and organizations should prioritize deployment due to the Critical severity.

Critical – Same Day DeploymentCisco Secure Firewall Management Center (FMC)

“A management interface should defend the network—not become its weakest point.”

Cisco has released a security update for Cisco Secure Firewall Management Center (FMC) to address a critical vulnerability in the web interface. The flaw stems from an improperly created system process during boot, allowing an unauthenticated remote attacker to bypass authentication and execute scripts that can obtain root access to the underlying operating system by sending crafted HTTP requests. The CVSS score is 10.0, which is Critical severity.

The update corrects the affected system process and prevents unauthenticated attackers from leveraging the web interface to gain root-level access. No verified public proof-of-concept code or real-world exploitation has been confirmed for this vulnerability.

Zero-Day – Immediate DeploymentSonicWall SMA1000 Security Update

“An actively exploited critical vulnerability turns patching from routine maintenance into an urgent business priority.”

SonicWall has released security updates for two vulnerabilities affecting SMA1000 appliances. One vulnerability is being actively exploited and could allow an unauthenticated attacker to abuse a Server-Side Request Forgery (SSRF) weakness to force the appliance to send requests to unintended destinations. The second vulnerability is a post-authentication code injection issue that could allow an authenticated administrator to execute arbitrary operating system commands under specific conditions.

CVE-2026-15409 has a CVSS score of 10.0, which is Critical severity. CVE-2026-15410 has a CVSS score of 7.2, which is High severity. Verified active exploitation has been reported for both vulnerabilities, making timely deployment of this update essential to reduce the risk of system compromise and unauthorized activity.

High with EoP or RCE – Expedited DeploymentSplunk Enterprise and Splunk Cloud Platform

“These weaknesses put stored credentials, indexed data, and application files within reach of attackers.”

Splunk patched three vulnerabilities affecting Splunk Enterprise and Splunk Cloud Platform. CVE-2026-20296 can let an attacker trick an authorized user into running SPL searches as splunk-system-user, exposing stored credentials and indexed data. CVE-2026-20296 has a CVSS score of 8.3, which is High severity.

CVE-2026-20297 allows a privileged user to write files outside the intended application directory during app installation. CVE-2026-20297 has a CVSS score of 7.2, which is High severity. CVE-2026-20298 allows a low-privileged user to view stored credential hashes through a REST endpoint. CVE-2026-20298 has a CVSS score of 5.3, which is Medium severity. Updated Splunk releases correct these weaknesses.

High with EoP or RCE – Expedited DeploymentF5 NGINX Plus

“A single crafted request can turn an application gateway into a business disruption.”

F5 has released updates to address a vulnerability affecting NGINX Plus and NGINX Open Source. CVE-2026-42533 is a heap buffer overflow vulnerability that can occur when specific map directive configurations use regular expression matching and reference regex capture variables under certain conditions. An unauthenticated attacker can exploit the issue by sending crafted HTTP requests, potentially causing a denial-of-service by crashing and restarting the NGINX worker process. In environments where Address Space Layout Randomization (ASLR) is disabled or can be bypassed, the vulnerability could also allow remote code execution. The CVSS score is 8.1, which is High severity.

The vulnerability affects the data plane only and does not expose the NGINX control plane. There are no verified reports of active exploitation or public proof-of-concept associated with this vulnerability. Organizations should update affected NGINX Plus or NGINX Open Source deployments to the fixed releases.

Zero-Day – Immediate DeploymentMozilla Firefox

“Public exploit code shortens the time between discovery and attack.”

Mozilla has released Firefox 152.0.6 to address two security vulnerabilities. CVE-2026-15718 has a CVSS score of 4.3, which is Medium severity. Public proof-of-concept exploit code is available for this vulnerability, although there are no verified reports of attacks in the wild. CVE-2026-15719 has a CVSS score of 5.4, which is Medium severity.

Both vulnerabilities are resolved in Firefox 152.0.6. Organizations should update affected Firefox installations to reduce the risk of exploitation and maintain a secure browsing environment.

Zero-Day – Immediate DeploymentAdobe ColdFusion 2025

“When critical vulnerabilities require no user interaction, every unpatched server becomes an immediate business risk.”

Adobe has released security updates for ColdFusion 2025 to address eight critical vulnerabilities. These include path traversal, code injection, improper input validation, incorrect authorization, missing authentication, and SQL injection issues that could allow attackers to read sensitive files, execute arbitrary code, or gain unauthorized access without requiring user interaction.

CVE-2026-48318 has a CVSS score of 9.9, which is Critical severity. CVE-2026-48322 and CVE-2026-48284 each have a CVSS score of 9.6, which is Critical severity. CVE-2026-48321 and CVE-2026-48325 each have a CVSS score of 9.3, which is Critical severity. CVE-2026-48319 and CVE-2026-48324 each have a CVSS score of 9.1, which is Critical severity. CVE-2026-48327 has a CVSS score of 9.0, which is Critical severity. There are no verified reports of active exploitation or public proof-of-concept associated with these vulnerabilities.

High with EoP or RCE – Expedited Deploymentn8n

“Identity checks are only as strong as the details they verify.”

n8n has released a security update to address CVE-2026-59208, an authentication vulnerability affecting instances configured with multiple trusted token-exchange issuers. The issue allowed external identities to be mapped to local accounts using only the JWT sub claim while ignoring the iss claim. An attacker with a valid token from one trusted issuer and a matching sub value from another issuer could authenticate as the victim. The issue is resolved in n8n versions 2.27.4 and 2.28.1.

The CVSS score is 7.6, which is High severity. Based on the information provided, there is no verified exploitation associated with this vulnerability. Although it is not a remote code execution issue, it can result in privilege escalation through improper authentication handling, making timely patching important for affected deployments.

Zero-Day – Immediate DeploymentLinux

“A race condition in the kernel can turn a routine operation into a serious memory safety risk.”

The Linux kernel has been patched for CVE-2026-46215, a race condition in the DRM handle-management process. Concurrent operations could leave a dangling handle that was later dereferenced, resulting in a use-after-free condition. The update prevents the old handle from being reused while PRIME operations are completed.

The CVSS score is 7.8, which is High severity. Public proof-of-concept code is available, increasing the risk that the vulnerability could be tested or adapted against unpatched systems.

Critical – Same Day DeploymentIBM WebSphere Application Server

“Administrative tools deserve the same level of protection as the applications they manage.”

IBM has released security updates for WebSphere Application Server 9.0 and 8.5 to address multiple vulnerabilities affecting the administrative console and its integrated help system. CVE-2026-11712 and CVE-2026-11708 are cross-site scripting (XSS) vulnerabilities (CWE-79) that could allow malicious script execution within the administrative console. CVE-2026-11595 is an information disclosure vulnerability (CWE-22) that could allow a remote attacker to obtain sensitive information from the integrated help system.

CVE-2026-11712 has a CVSS score of 9.3, which is Critical severity. CVE-2026-11708 has a CVSS score of 9.3, which is Critical severity. CVE-2026-11595 has a CVSS score of 4.3, which is Medium severity. Based on the information provided, there is no verified exploitation associated with these vulnerabilities. Organizations running affected WebSphere Application Server versions should apply the available updates to reduce the risk of administrative console compromise and information exposure.

High with EoP or RCE – Expedited DeploymentPalo Alto Networks Cloud NGFW

“A network service exposed to the wrong audience can quickly become an attacker’s entry point.”

Palo Alto Networks has released a security update for Cloud NGFW to address CVE-2026-0288, a buffer overflow vulnerability (CWE-787) in the User-ID Terminal Server Agent (TSA) component of PAN-OS. An unauthenticated attacker with network access could exploit the vulnerability by sending specially crafted network traffic, potentially causing a denial-of-service condition or achieving arbitrary code execution. The risk is significantly reduced when TSA connectivity is restricted to trusted internal IP addresses. Panorama is not affected by this vulnerability.

The CVSS score is 7.2, which is High severity. Based on the information provided, there is no verified exploitation associated with this vulnerability. Because the issue could potentially lead to remote code execution, organizations should prioritize applying the available security update and follow Palo Alto Networks’ recommended deployment practices.

High with EoP or RCE – Expedited DeploymentFoxit PDF Editor

“A single malicious PDF can turn a routine document into a security event if critical validation is missing.”

This update addresses multiple high-severity memory handling and input validation vulnerabilities in Foxit PDF Editor that could be triggered by opening specially crafted PDF files. The fixes strengthen object validation, memory management, pointer handling, and annotation processing to prevent application crashes and reduce the risk of exploitation through malicious documents.

CVE-2026-13126 has a CVSS score of 7.8, High severity. It addresses a use-after-free condition caused by JavaScript deleting PDF pages before invalid annotation objects were accessed. CVE-2026-57260 has a CVSS score of 7.8, High severity. It corrects improper pointer handling while parsing malformed Unity 3D objects embedded in PDF files. CVE-2026-57248 has a CVSS score of 7.8, High severity. It resolves insufficient object type and argument validation during JavaScript annotation processing that could corrupt internal structures and crash the application. CVE-2026-57246 has a CVSS score of 7.8, High severity. It fixes inadequate argument validation during signature verification that could lead to unsafe memory operations when processing abnormal strings.

No verified real-world exploitation or public proof-of-concept has been confirmed for these vulnerabilities.

Zero-Day – Immediate DeploymentBitwarden Server

“A single missing ownership check can put an entire account in someone else’s hands.”

Bitwarden has released Bitwarden Server 2026.6.0 to address CVE-2026-60104, an authorization vulnerability (CWE-639) affecting the Trusted Device Encryption authentication workflow. The issue allowed a low-privileged organization member to submit an authentication request using another user’s email address, potentially exposing the victim’s vault key and a victim-scoped access token. Successful exploitation could result in full account takeover.

The CVSS score is 8.7, which is High severity. Public proof-of-concept code is available, increasing the likelihood of exploitation against unpatched deployments. Organizations running Bitwarden Server versions prior to 2026.6.0 should upgrade to the latest release to prevent unauthorized access to user vaults.

Critical – Same Day DeploymentminiOrange OAuth Single Sign On – SSO (OAuth Client)

“When authentication can be bypassed, identity is no longer a security boundary.”

miniOrange has released a security update for OAuth Single Sign On – SSO (OAuth Client) to address CVE-2026-57807, an authentication bypass vulnerability (CWE-288). The vulnerability allows password recovery exploitation through an alternate authentication path or channel, potentially enabling unauthorized access to affected accounts. The issue affects OAuth Single Sign On – SSO (OAuth Client) versions through 38.5.8.

The CVSS score is 9.8, which is Critical severity. Based on the information provided, there is no verified exploitation associated with this vulnerability. Because the issue can lead to unauthorized account access through authentication bypass, organizations should prioritize applying the available update.

Critical – Same Day DeploymentRed Hat OpenShift AI (RHOAI)

“When internal services become reachable from the outside, sensitive data is only one request away.”

Red Hat has released security updates for Red Hat OpenShift AI (RHOAI) to address two Critical vulnerabilities in the guardrails-detectors component. Both issues stem from improper handling of user-supplied XML Schema Definition (XSD) input, enabling Server-Side Request Forgery (SSRF) attacks. A remote attacker could exploit these vulnerabilities to access internal network services, cloud metadata endpoints, or read sensitive local files, potentially exposing credentials, service account tokens, Kubernetes resources, and other confidential information.

CVE-2026-15143 has a CVSS score of 9.3, which is Critical severity. CVE-2026-15378 has a CVSS score of 9.3, which is Critical severity. Based on the information provided, there is no verified exploitation associated with these vulnerabilities. Organizations using affected RHOAI deployments should prioritize applying the available updates to protect sensitive infrastructure and internal resources.

Critical – Same Day DeploymentWebPros Plesk

“When authorization fails, one account can become the gateway to the entire server.”

WebPros has released security updates for Plesk to address two Critical authorization vulnerabilities affecting its XML-based management interfaces. CVE-2026-48614 allows an authenticated user to inject arbitrary configuration directives through the Plesk XML API, leading to arbitrary file writes as root and full privilege escalation on the underlying server. CVE-2026-56843 affects the XML-RPC API and allows a low-privileged customer to access domains they do not own, exposing other tenants’ FTP credentials stored in cleartext. The disclosed credentials could then be used to execute code under another tenant’s system account.

CVE-2026-48614 has a CVSS score of 9.9, which is Critical severity. CVE-2026-56843 has a CVSS score of 9.9, which is Critical severity. Based on the information provided, there is no verified exploitation associated with either vulnerability. Organizations using affected versions of Plesk should prioritize installing the latest updates to protect against privilege escalation and cross-tenant compromise.

Zero-Day – Immediate DeploymentWordPress

“When attackers can chain vulnerabilities together, a routine update becomes a business-critical priority.”

This WordPress security update addresses two related vulnerabilities affecting multiple WordPress releases. The update fixes an SQL injection issue in the author__not_in parameter of WP_Query and a REST API batch endpoint route confusion issue. When combined, these vulnerabilities could allow an attacker to perform SQL injection and potentially achieve remote code execution.

CVE-2026-60137 has a CVSS score of 5.9, Medium severity. It affects the handling of untrusted input passed to the author__not_in parameter by plugins or themes, potentially enabling SQL injection.

CVE-2026-63030 has a CVSS score of 9.8, Critical severity. It affects the REST API batch endpoint route handling and, when chained with CVE-2026-60137, could allow SQL injection leading to remote code execution. Public proof-of-concept (PoC) code is available for these vulnerabilities.

Critical – Same Day DeploymentGoogle Chrome

“A browser patch is more than a bug fix—it closes the door before attackers find a way through.”

This Google Chrome updates address 370 security vulnerabilities affecting Chrome on Windows, Linux, and Android. The fixes include several use-after-free vulnerabilities, heap buffer overflow, uninitialized memory use, and a same-origin policy bypass. Successful exploitation of the most severe issues could allow remote code execution, sandbox escape, privilege escalation, heap corruption, or disclosure of sensitive information through crafted web content.

CVE-2026-15773 has a CVSS score of 9.6, Critical severity. CVE-2026-13032 has a CVSS score of 9.6, Critical severity. CVE-2026-15767 has a CVSS score of 8.8, High severity. CVE-2026-15112 has a CVSS score of 8.8, High severity. CVE-2026-15129 has a CVSS score of 8.8, High severity. CVE-2026-13037 has a CVSS score of 7.8, High severity. CVE-2026-15764 has a CVSS score of 7.5, High severity. CVE-2026-15765 has a CVSS score of 7.5, High severity. CVE-2026-15766 has a CVSS score of 6.5, Medium severity. CVE-2026-15775 has a CVSS score of 6.5, Medium severity. CVE-2026-13030 has a CVSS score of 5.3, Medium severity.

Several of the high and critical vulnerabilities enable remote code execution or sandbox escape, while others could expose sensitive information or bypass browser security boundaries. No verified real-world exploitation or public proof-of-concept activity has been confirmed for these vulnerabilities.

High with EoP or RCE – Expedited DeploymentESET Inspect Connector

“Weak authentication inside trusted software can quietly hand attackers elevated control.”

A patch is available for CVE-2026-6423, a local privilege escalation vulnerability affecting ESET Inspect Connector. The vulnerability is caused by improper authentication in an IPC (Inter-Process Communication) channel, allowing a local attacker to elevate privileges on an affected system. The issue is associated with CWE-269 (Improper Privilege Management).

The CVSS score is 8.5, which is High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.

Critical – Same Day DeploymentSGLang

“An exposed service without authentication can turn a single network connection into a complete compromise.”

A patch is available for CVE-2026-14890, a critical vulnerability affecting SGLang. The vulnerability exists in the expert-parallel backup subsystem, which exposes a ZeroMQ PULL socket on a routable network interface without authentication or deserialization protections. An attacker can provide a malicious pickle file, resulting in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.

The CVSS score is 9.1, which is Critical severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.

Critical – Same Day DeploymentApache Tomcat

“Even strong security features fail when secure configuration isn’t clearly defined.”

A patch is available for CVE-2026-59084, a vulnerability affecting Apache Tomcat. The issue stems from insufficient technical documentation for securely configuring the EncryptInterceptor, which could leave deployments vulnerable if the feature is not configured correctly. The vulnerability is associated with CWE-1059 (Insufficient Technical Documentation).

The issue affects Apache Tomcat 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.13 through 9.0.119, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109. Users should upgrade to Apache Tomcat 11.0.24, 10.1.57, or 9.0.120, which address the issue.

The CVSS score is 9.1, which is Critical severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.

High with EoP or RCE – Expedited DeploymentAdobe Animate 2023

“A single malicious file could turn routine creative work into a system compromise.”

Adobe Animate 2023 contains six high-severity vulnerabilities that could result in arbitrary code execution in the current user’s context. The flaws include OS command injection, incorrect authorization, path traversal, and an untrusted search path. Most require a victim to open a malicious file, while CVE-2026-48349 does not require user interaction but depends on conditions beyond the attacker’s control.

CVE-2026-48345 has a CVSS score of 8.2, High severity. CVE-2026-48349 has a CVSS score of 8.1, High severity. CVE-2026-48350 has a CVSS score of 8.6, High severity. CVE-2026-48346 has a CVSS score of 7.9, High severity. CVE-2026-48347 has a CVSS score of 7.7, High severity. CVE-2026-48348 has a CVSS score of 7.7, High severity.

High with EoP or RCE – Expedited DeploymentAdobe Bridge

“One malicious file could turn a routine preview into arbitrary code execution.”

Adobe Bridge contains six high-severity vulnerabilities that could allow arbitrary code execution in the context of the current user. The flaws include out-of-bounds writes, a heap-based buffer overflow, untrusted pointer dereference, and integer overflow. Exploitation requires a victim to open a malicious file.

CVE-2026-48311 has a CVSS score of 7.8, High severity. CVE-2026-48339 has a CVSS score of 7.8, High severity. CVE-2026-48340 has a CVSS score of 7.8, High severity. CVE-2026-48341 has a CVSS score of 7.8, High severity. CVE-2026-48342 has a CVSS score of 7.8, High severity. CVE-2026-48343 has a CVSS score of 7.8, High severity.

Critical – Same Day DeploymentAdobe Commerce

“A handful of weaknesses across one platform can quickly become a complete compromise if left unpatched.”

Adobe Commerce addresses eight security vulnerabilities affecting file uploads, output encoding, authorization, cross-site scripting (XSS), and SQL injection. The most severe issues could lead to arbitrary code execution, while others allow security feature bypasses, unauthorized access, or malicious script injection that could compromise user accounts or sessions.

CVE-2026-48356 has a CVSS score of 9.6, Critical severity. CVE-2026-48358 has a CVSS score of 9.1, Critical severity. CVE-2026-47984 has a CVSS score of 8.2, High severity. CVE-2026-47988 has a CVSS score of 8.6, High severity. CVE-2026-47994 has a CVSS score of 8.7, High severity. CVE-2026-47995 has a CVSS score of 8.1, High severity. CVE-2026-47992 has a CVSS score of 7.2, High severity. CVE-2026-47996 has a CVSS score of 7.6, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

High with EoP or RCE – Expedited DeploymentAdobe Media Encoder

“Opening a single malicious media file should never put an entire workstation at risk.”

Adobe Media Encoder addresses four high-severity memory corruption vulnerabilities that could result in arbitrary code execution in the context of the current user. The vulnerabilities include a stack-based buffer overflow and multiple out-of-bounds write flaws. Successful exploitation requires a victim to open a malicious file.

CVE-2026-47971 has a CVSS score of 7.8, High severity. CVE-2026-47976 has a CVSS score of 7.8, High severity. CVE-2026-48366 has a CVSS score of 7.8, High severity. CVE-2026-48370 has a CVSS score of 7.8, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

High with EoP or RCE – Expedited DeploymentAfter Effects

“A malicious project file could turn creative work into a workstation compromise.”

Adobe After Effects contains two high-severity out-of-bounds write vulnerabilities that could result in arbitrary code execution in the context of the current user. Exploitation requires a victim to open a malicious file.

CVE-2026-48274 has a CVSS score of 7.8, High severity. CVE-2026-48367 has a CVSS score of 7.8, High severity.

High with EoP or RCE – Expedited DeploymentAdobe Audition

“A single malicious audio file should never become the gateway to code execution.”

Adobe Audition addresses five high-severity out-of-bounds write vulnerabilities that could result in arbitrary code execution in the context of the current user. All five vulnerabilities require a victim to open a malicious file, making user interaction a prerequisite for successful exploitation.

CVE-2026-47967 has a CVSS score of 7.8, High severity. CVE-2026-47968 has a CVSS score of 7.8, High severity. CVE-2026-48309 has a CVSS score of 7.8, High severity. CVE-2026-48365 has a CVSS score of 7.8, High severity. CVE-2026-48368 has a CVSS score of 7.8, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Critical – Same Day DeploymentAdobe ColdFusion

“When a web platform accumulates critical flaws across multiple attack paths, patching becomes a business priority—not a maintenance task.”

Adobe ColdFusion addresses thirteen vulnerabilities affecting ColdFusion 2025 and ColdFusion 2023.20 and earlier. The update resolves critical issues involving improper input validation, path traversal, code injection, SQL injection, missing authentication, and authorization weaknesses, along with high-severity vulnerabilities involving uncontrolled search paths, reflected cross-site scripting (XSS), and server-side request forgery (SSRF). Several of the critical vulnerabilities can be exploited without user interaction and could lead to arbitrary code execution, privilege escalation, unauthorized file access, or security feature bypass.

CVE-2026-48284 has a CVSS score of 9.6, Critical severity. CVE-2026-48318 has a CVSS score of 9.9, Critical severity. CVE-2026-48319 has a CVSS score of 9.1, Critical severity. CVE-2026-48321 has a CVSS score of 9.3, Critical severity. CVE-2026-48322 has a CVSS score of 9.6, Critical severity. CVE-2026-48324 has a CVSS score of 9.1, Critical severity. CVE-2026-48325 has a CVSS score of 9.3, Critical severity. CVE-2026-48327 has a CVSS score of 9.0, Critical severity. CVE-2026-48363 has a CVSS score of 8.2, High severity. CVE-2026-48364 has a CVSS score of 8.2, High severity. CVE-2026-48320 has a CVSS score of 8.5, High severity. CVE-2026-48328 has a CVSS score of 7.7, High severity. CVE-2026-48332 has a CVSS score of 7.7, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

High with EoP or RCE – Expedited DeploymentAdobe Creative Cloud Desktop

“Trusted desktop software can become an attack path when execution controls break down.”

Adobe Creative Cloud Desktop addresses two high-severity vulnerabilities that could result in arbitrary code execution in the context of the current user. The vulnerabilities include an uncontrolled search path element and a time-of-check time-of-use (TOCTOU) race condition. Neither vulnerability requires user interaction, although successful exploitation depends on conditions beyond the attacker’s control.

CVE-2026-48272 has a CVSS score of 7.8, High severity. CVE-2026-48344 has a CVSS score of 7.8, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Critical – Same Day DeploymentAdobe Illustrator Desktop 2026

“One malicious design file could turn a creative workflow into a code-execution event.”

Adobe Illustrator Desktop 2026 addresses five vulnerabilities that could result in arbitrary code execution in the context of the current user. The update covers improper input validation, an untrusted search path, and three out-of-bounds write flaws. Successful exploitation requires a victim to open a malicious file.

CVE-2026-48334 has a CVSS score of 9.3, Critical severity. CVE-2026-48275 has a CVSS score of 8.6, High severity. CVE-2026-48335 has a CVSS score of 7.8, High severity. CVE-2026-48336 has a CVSS score of 7.8, High severity. CVE-2026-48337 has a CVSS score of 7.8, High severity.

High with EoP or RCE – Expedited DeploymentAdobe Premiere Pro

“A crafted media file should never become a path to system compromise.”

Adobe Premiere Pro addresses three high-severity memory corruption vulnerabilities that could result in arbitrary code execution in the context of the current user. The update resolves a heap-based buffer overflow and two out-of-bounds write vulnerabilities. Successful exploitation requires a victim to open a malicious file.

CVE-2026-48269 has a CVSS score of 7.8, High severity. CVE-2026-48270 has a CVSS score of 7.8, High severity. CVE-2026-48369 has a CVSS score of 7.8, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Zero-Day – Immediate DeploymentArgo CD

“A trusted interface can become an attack vector when user-supplied links are left unchecked.”

Argo CD addresses CVE-2026-45738, a cross-site scripting (XSS) vulnerability affecting versions prior to 3.2.12, 3.3.10, and 3.4.2. The flaw allows users with application write access to define link.argocd.argoproj.io/* annotations that are rendered as hyperlink values without URL validation. An attacker can abuse this behavior to execute malicious JavaScript within a higher-privileged user’s authenticated Argo CD session. The vulnerability is associated with CWE-79 (Cross-Site Scripting).

The CVSS score is 7.3, which is High severity. Based on the information provided, a public proof-of-concept (PoC) is available for this vulnerability. The issue is resolved in Argo CD 3.2.12, 3.3.10, and 3.4.2.

Critical – Same Day DeploymentBetter Auth

“Authentication is only as strong as its weakest trust decision.”

Better Auth version 1.6.11 addresses six vulnerabilities affecting authentication, authorization, OAuth, SSO, device authorization, and organization invitation workflows. The update fixes a critical server-side request forgery (SSRF) vulnerability along with multiple high-severity flaws that could enable unauthorized account linking, privilege escalation, security control bypass, refresh token reuse through race conditions, and unauthorized management of SSO providers or organization invitations.

CVE-2026-53513 has a CVSS score of 9.6, Critical severity. CVE-2026-53516 has a CVSS score of 8.3, High severity. CVE-2026-53517 has a CVSS score of 8.1, High severity. CVE-2026-45337 has a CVSS score of 7.6, High severity. CVE-2026-53514 has a CVSS score of 7.7, High severity. CVE-2026-53515 has a CVSS score of 7.1, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

High with EoP or RCE – Expedited DeploymentCisco RoomOS Software

“Multiple weaknesses across access, memory, encryption, and error handling can expose critical collaboration systems.”

Cisco released a RoomOS software-hardening update addressing six internally discovered, high-severity vulnerabilities. The update strengthens access controls, memory handling, input validation, encryption, resource lifecycle management, and exceptional-condition handling. The most serious weaknesses could enable privilege escalation or arbitrary code execution.

CVE-2026-20150 has a CVSS score of 8.8, High severity. CVE-2026-20156 has a CVSS score of 8.1, High severity. CVE-2026-20153 has a CVSS score of 7.5, High severity. CVE-2026-20157 has a CVSS score of 7.5, High severity. CVE-2026-20158 has a CVSS score of 7.5, High severity. CVE-2026-20187 has a CVSS score of 7.5, High severity.

High with EoP or RCE – Expedited DeploymentF5 NGINX Plus

“A single crafted request should never be enough to destabilize a production web server.”

F5 has released updates for NGINX Plus to address two high-severity vulnerabilities affecting the NGINX data plane. The vulnerabilities involve a heap buffer overflow and uninitialized memory access that can be triggered by specially crafted HTTP requests under specific configuration conditions. Successful exploitation could result in denial of service, limited memory disclosure, or, in certain environments, arbitrary code execution.

CVE-2026-42533 has a CVSS score of 8.1, High severity. This heap buffer overflow can cause the NGINX worker process to restart and, on systems with Address Space Layout Randomization (ASLR) disabled or bypassed, could allow arbitrary code execution. CVE-2026-60005 has a CVSS score of 8.2, High severity. This vulnerability affects the ngx_http_slice_module and may allow limited memory disclosure or cause the NGINX worker process to restart when the module is enabled. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with either vulnerability.

High with EoP or RCE – Expedited DeploymentFortiAuthenticator

“A single crafted request should never expose sensitive information from a trusted authentication system.”

Fortinet has released an update for FortiAuthenticator to address CVE-2025-53379, a high-severity out-of-bounds read vulnerability affecting FortiAuthenticator 6.6.0 through 6.6.2 and all versions of the 6.5 release. The flaw could allow a remote, unauthenticated attacker to retrieve sensitive information by sending a specially crafted request. The vulnerability is associated with CWE-125 (Out-of-bounds Read).

The CVSS score is 7.0, which is High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.

High with EoP or RCE – Expedited DeploymentHCL DFXServer

“When authentication checks fail, unauthorized access becomes far easier than intended.”

HCL Software has released updates for DFXServer to address two high-severity authentication vulnerabilities. The first vulnerability is a broken authentication flaw that allows unauthenticated attackers to access specific API endpoints and perform unauthorized actions because the application fails to verify a user’s authentication status. The second vulnerability is an authentication bypass flaw that allows attackers to manipulate server authentication responses to gain unauthorized access without valid credentials.

CVE-2026-35147 has a CVSS score of 8.2, High severity. CVE-2026-35149 has a CVSS score of 8.2, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with either vulnerability.

High with EoP or RCE – Expedited DeploymentIBM Db2

“User-controlled connection settings should never become a path to code execution.”

IBM has released an update for Db2 to address CVE-2026-9762, a high-severity vulnerability affecting IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4. The vulnerability could allow remote code execution when a JDBC URL is under user control. The issue is associated with CWE-94 (Improper Control of Generation of Code).

The CVSS score is 7.8, which is High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.

Critical – Same Day DeploymentIBM Langflow OSS

“Security controls lose their value when authentication, validation, and execution boundaries fail together.”

IBM has released updates for Langflow OSS to address multiple Critical and High severity vulnerabilities affecting versions 1.0.0 through 1.10.1. The fixes address hard-coded credentials, authentication bypasses, remote code execution, privilege escalation, arbitrary file write, path traversal, server-side request forgery, insecure deserialization, unsafe code execution, and authorization weaknesses. Several vulnerabilities could allow attackers to gain administrative access, execute arbitrary code, manipulate workflows, overwrite files, or fully compromise affected Langflow deployments.

CVE-2026-13446 has a CVSS score of 9.8, Critical severity. CVE-2026-8476 has a CVSS score of 9.9, Critical severity. CVE-2026-8481 has a CVSS score of 9.9, Critical severity. CVE-2026-8505 has a CVSS score of 9.8, Critical severity. CVE-2026-8635 has a CVSS score of 9.9, Critical severity. CVE-2026-8859 has a CVSS score of 9.9, Critical severity. CVE-2026-9103 has a CVSS score of 9.8, Critical severity. CVE-2026-9135 has a CVSS score of 9.9, Critical severity. CVE-2026-9198 has a CVSS score of 9.8, Critical severity. CVE-2026-9202 has a CVSS score of 9.8, Critical severity. CVE-2026-13445 has a CVSS score of 8.1, High severity. CVE-2026-13448 has a CVSS score of 8.1, High severity. CVE-2026-14499 has a CVSS score of 8.8, High severity. CVE-2026-7667 has a CVSS score of 8.8, High severity. CVE-2026-7755 has a CVSS score of 8.8, High severity. CVE-2026-8056 has a CVSS score of 8.8, High severity. CVE-2026-7754 has a CVSS score of 7.7, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Critical – Same Day DeploymentMetabase

“Database connection privileges can become a direct path to server compromise and sensitive file exposure.”

Metabase has released updates addressing two vulnerabilities in its database connection functionality. A user permitted to configure database connections could exploit unsafe JDBC behavior to execute code or read arbitrary files from the Metabase server. The fixes restrict dangerous connection parameters and prevent attacker-controlled Snowflake infrastructure from writing files to the host.

CVE-2026-50148 has a CVSS score of 10.0, Critical severity. The vulnerability could enable remote code execution by replacing a Metabase database driver file that is later loaded by the application. CVE-2026-50147 has a CVSS score of 7.6, High severity. It could expose arbitrary server files through malicious MySQL or MariaDB JDBC parameters. Fixed releases include Metabase 1.54.24, 1.55.24, 1.56.25, 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, depending on the affected release branch.

High with EoP or RCE – Expedited DeploymentMicrosoft .NET 10.0

“A secure framework depends on every layer enforcing trust, validation, and resource protection.”

Microsoft has released security updates for .NET 10.0 that address twelve High severity vulnerabilities affecting authentication, authorization, resource management, memory safety, and input validation. Collectively, these fixes strengthen the framework against unauthorized access, privilege escalation, denial-of-service conditions, and memory-related security weaknesses that could impact applications built on affected .NET releases.

CVE-2026-47300 has a CVSS score of 8.8, High severity. CVE-2026-47303 has a CVSS score of 8.8, High severity. CVE-2026-50528 has a CVSS score of 8.2, High severity. CVE-2026-47302 has a CVSS score of 7.5, High severity. CVE-2026-50524 has a CVSS score of 7.5, High severity. CVE-2026-50525 has a CVSS score of 7.5, High severity. CVE-2026-50526 has a CVSS score of 7.0, High severity. CVE-2026-50527 has a CVSS score of 7.5, High severity. CVE-2026-50648 has a CVSS score of 7.5, High severity. CVE-2026-50651 has a CVSS score of 7.5, High severity. CVE-2026-56170 has a CVSS score of 7.5, High severity. CVE-2026-57108 has a CVSS score of 7.5, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

High with EoP or RCE – Expedited DeploymentMicrosoft .NET Framework 3.5

“Even mature application frameworks require continuous hardening to keep trust and execution boundaries intact.”

Microsoft has released security updates for .NET Framework 3.5 to address six High severity vulnerabilities affecting authentication validation, memory safety, and resource management. The updates strengthen the framework against memory corruption, denial-of-service conditions, and validation weaknesses that could be leveraged to compromise applications built on affected .NET Framework deployments.

CVE-2026-47304 has a CVSS score of 8.1, High severity. CVE-2026-50304 has a CVSS score of 7.5, High severity. CVE-2026-50355 has a CVSS score of 7.5, High severity. CVE-2026-50368 has a CVSS score of 7.5, High severity. CVE-2026-50411 has a CVSS score of 7.5, High severity. CVE-2026-50647 has a CVSS score of 7.5, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

High with EoP or RCE – Expedited DeploymentOpenClaw

“Small authorization gaps across many features can combine into significant operational risk.”

OpenClaw has released security updates addressing a broad set of High severity vulnerabilities affecting multiple releases prior to 2026.6.9. The update strengthens authorization enforcement, authentication validation, privilege management, environment filtering, network policy controls, and feature-specific security checks across components including plugin installation, browser integration, messaging platforms, device pairing, cron jobs, execution approval workflows, and sandboxed services. These fixes prevent lower-trust users from performing actions beyond their intended permissions and reduce opportunities for unauthorized access and policy bypass.

The affected vulnerabilities include CVSS scores ranging from 7.1 to 8.8, all rated High severity. Several vulnerabilities address authorization bypass and privilege escalation, while others resolve network policy bypass, server-side request forgery, environment filtering weaknesses, race conditions, symlink handling issues, and workspace plugin loading flaws. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Critical – Same Day DeploymentVMware Avi Load Balancer

“When authentication and execution controls fail together, attackers can move from access to full system compromise.”

VMware has released security updates for Avi Load Balancer to address one Critical and six High severity vulnerabilities affecting multiple supported release branches. The update resolves weaknesses involving authentication bypass, authorization bypass, remote code execution, directory traversal, and privilege escalation. If exploited, these flaws could allow attackers to access the Avi Control Plane, execute arbitrary code, elevate privileges, or access restricted resources.

CVE-2026-47865 has a CVSS score of 9.8, Critical severity. CVE-2026-47866 has a CVSS score of 8.3, High severity. CVE-2026-47867 has a CVSS score of 8.7, High severity. CVE-2026-47869 has a CVSS score of 8.7, High severity. CVE-2026-47871 has a CVSS score of 8.8, High severity. CVE-2026-47868 has a CVSS score of 7.8, High severity. CVE-2026-47870 has a CVSS score of 7.1, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Affected versions include 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, 22.1.1 through 22.1.7, and selected 32.1.1 deployments, with fixes available in 32.1.2, 31.2.2-2p3, and 30.2.7, depending on the release branch.

Zero-Day – Immediate DeploymentArista Networks VeloCloud Orchestrator On-Prem

“An internal feature exposed to the internet can quickly become an attacker’s fastest path to full compromise.”

This patch addresses CVE-2026-16812, a critical vulnerability affecting Arista Networks VeloCloud Orchestrator On-Prem. The flaw allows a remote attacker to access privileged internal functionality that was intended for internal use only. Successful exploitation can impact the VCO host and compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Hosted and Dedicated versions of VCO were patched before this advisory was released.

The CVSS score is 10.0, which is Critical severity. Active exploitation has been confirmed. The vulnerability also enables remote code execution (RCE), making this an urgent patching priority for organizations running on-premises VeloCloud Orchestrator deployments.

Critical – Same Day DeploymentJetBrains TeamCity

“When attackers can execute code without logging in, every exposed server becomes a priority.”

This patch addresses CVE-2026-63077, a critical vulnerability affecting JetBrains TeamCity before versions 2026.1.3 and 2025.11.7. The flaw allows unauthenticated remote code execution through the agent polling protocol, enabling a remote attacker to execute arbitrary code on a vulnerable TeamCity server without authentication.

The CVSS score is 9.8, which is Critical severity. No verified public exploitation or proof-of-concept activity has been confirmed. Due to the combination of unauthenticated access, remote code execution, and critical severity, organizations should prioritize upgrading affected TeamCity installations.

Critical – Same Day DeploymentDell PowerProtect Data Manager

“Security controls are only as strong as the validation behind them.”

This patch addresses multiple vulnerabilities in Dell PowerProtect Data Manager prior to version 20.2.0.0. The update resolves improper input validation flaws in the REST API and related components, as well as an incorrect security token generation issue in the Identity and Access Management (IAM) component. Successful exploitation could allow authenticated remote attackers to elevate privileges within the application.

CVE-2026-40712 has a CVSS score of 9.1, Critical severity. CVE-2026-46738 has a CVSS score of 9.1, Critical severity. CVE-2026-49499 has a CVSS score of 8.8, High severity. CVE-2026-40714 has a CVSS score of 7.2, High severity. No verified real-world exploitation or public proof-of-concept activity has been confirmed for these vulnerabilities.

Critical – Same Day DeploymentLinux Kernel

“Modern operating systems rely on thousands of components—securing each one keeps the entire platform resilient.”

This Linux kernel security update addresses 85 vulnerabilities across numerous kernel subsystems. The fixes strengthen core operating system security by resolving memory corruption, use-after-free, double-free, out-of-bounds memory access, race conditions, permission enforcement failures, authentication weaknesses, and input validation flaws. Collectively, these updates improve system stability while reducing the attack surface across networking, storage, virtualization, filesystems, and device drivers.

The update includes multiple Critical vulnerabilities with confirmed CVSS scores of 9.8 and 9.1, together with numerous High severity vulnerabilities ranging from 7.0 to 8.8. No verified real-world exploitation or public proof-of-concept activity is included for these vulnerabilities in the provided data.

CVE LIST:
CVE-2026-64188 CVE-2026-64189 CVE-2026-64191 CVE-2026-64206 CVE-2026-64208 CVE-2026-64210 CVE-2026-64216 CVE-2026-64217 CVE-2026-64218 CVE-2026-64219 CVE-2026-64221 CVE-2026-64222 CVE-2026-64223 CVE-2026-64226 CVE-2026-64232 CVE-2026-64235 CVE-2026-64243 CVE-2026-64247 CVE-2026-64251 CVE-2026-64255 CVE-2026-64257 CVE-2026-64259 CVE-2026-64260 CVE-2026-64261 CVE-2026-64265 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64276 CVE-2026-64277 CVE-2026-64279 CVE-2026-64280 CVE-2026-64281 CVE-2026-64284 CVE-2026-64286 CVE-2026-64287 CVE-2026-64293 CVE-2026-64296 CVE-2026-64298 CVE-2026-64299 CVE-2026-64300 CVE-2026-64303 CVE-2026-64304 CVE-2026-64311 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64317 CVE-2026-64318 CVE-2026-64319 CVE-2026-64320 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324 CVE-2026-64333 CVE-2026-64354 CVE-2026-64355 CVE-2026-64361 CVE-2026-64364 CVE-2026-64366 CVE-2026-64367 CVE-2026-64368 CVE-2026-64372 CVE-2026-64374 CVE-2026-64375 CVE-2026-64380 CVE-2026-64382 CVE-2026-64383 CVE-2026-64384 CVE-2026-64385 CVE-2026-64386 CVE-2026-64387 CVE-2026-64389 CVE-2026-64390 CVE-2026-64391 CVE-2026-64392 CVE-2026-64393 CVE-2026-64394 CVE-2026-64396 CVE-2026-64397 CVE-2026-64398 CVE-2026-64399 CVE-2026-64400 CVE-2026-64406 CVE-2026-64408 CVE-2026-64410 CVE-2026-64434 CVE-2026-64435 CVE-2026-64437 CVE-2026-64438 CVE-2026-64439 CVE-2026-64440 CVE-2026-64441 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64448 CVE-2026-64450 CVE-2026-64459 CVE-2026-64467 CVE-2026-64475 CVE-2026-64490 CVE-2026-64515 CVE-2026-64516 CVE-2026-64520 CVE-2026-64522 CVE-2026-64523, CVE-2026-53264

Vulnerability Coverage by Subsystem

SMB / KSMBD

  • Multiple Critical and High severity fixes address SMB client and KSMBD vulnerabilities.
  • Resolved issues include permission bypasses, authentication and credential handling flaws, replay handling bugs, use-after-free conditions, double-free vulnerabilities, path traversal, directory query synchronization, and improper access control.

Networking

  • Numerous fixes harden the networking stack, including Netfilter, RMNET, Mellanox (mlx5), Qualcomm networking, RXRPC, audit, and NetFS.
  • Vulnerabilities include race conditions, memory corruption, buffer validation failures, and use-after-free issues.

Bluetooth

  • Updates resolve High severity vulnerabilities in L2CAP and BNEP.
  • Fixes prevent deadlocks, connection lifetime issues, use-after-free conditions, and improper connection reference handling.

Storage and Filesystems

  • Security fixes span FUSE, ExFAT, UDF, ISOFS, HFS/HFS+, NFS, NVMe Target, Block Layer, and AIX partition parsing.
  • Improvements address bounds checking, memory safety, permission validation, metadata handling, and filesystem integrity.

Virtualization

  • KVM for both x86 and ARM64 receives multiple High severity fixes.
  • Updates improve Hyper-V handling, guest state validation, vCPU management, and memory safety.

RDMA

  • Critical fixes correct buffer validation, memory boundary enforcement, and protocol handling within RDMA and RTRS components.
  • These changes prevent out-of-bounds memory access and strengthen remote data transfer security.

Cryptography

  • Multiple fixes improve Kerberos, ECC, QAT, CAAM, pcrypt, and Loongson crypto components.
  • The update resolves memory corruption, buffer validation issues, callback handling errors, and sensitive key protection weaknesses.

BPF

  • Critical fixes strengthen BTF validation and XDP devmap processing.
  • Updates prevent integer overflow, memory corruption, and invalid packet handling.

USB / HID / Input

  • High severity vulnerabilities affecting HID, Wacom, Synaptics, USB serial, and input drivers are addressed.
  • Fixes prevent stack overflows, out-of-bounds access, buffer corruption, and invalid device state handling.

I2C / SPI / Device Drivers

  • Multiple driver updates resolve race conditions, DMA validation failures, use-after-free bugs, and improper resource cleanup across I2C, SPI, FPGA, CPU frequency, and other hardware components.

Memory Management and Core Kernel

  • Core kernel improvements address SLAB allocator behavior, scheduler logic, tracing, audit subsystem synchronization, and work queue lifetime management.
  • These fixes improve kernel stability and eliminate several memory safety defects.

High with EoP or RCE – Expedited DeploymentMongoDB Server

“Strong access controls only matter when every layer enforces them consistently.”

This MongoDB Server security update resolves four High severity vulnerabilities affecting query processing, BSON parsing, JavaScript execution, and aggregation pipeline handling. The fixes strengthen validation of client-supplied data, improve memory safety, enforce access controls, and prevent unintended access to sensitive resources. Together, these updates reduce the risk of unauthorized data access, information disclosure, memory corruption, and service instability.

CVE-2026-13059 has a CVSS score of 8.1, High severity, and resolves insufficient validation of client-supplied command parameters that could allow an authenticated low-privileged user to bypass role-based query-level access controls. CVE-2026-13072 has a CVSS score of 8.1, High severity, and corrects a memory corruption vulnerability during aggregation pipeline processing when compute mode is explicitly enabled. CVE-2026-13077 has a CVSS score of 7.1, High severity, and fixes an out-of-bounds heap read that could lead to server crashes or disclosure of adjacent memory. CVE-2026-13078 has a CVSS score of 7.7, High severity, and prevents authenticated users from reading arbitrary files through the server-side JavaScript engine.

Critical – Same Day DeploymentOracle

“One update can close hundreds of attack paths when it reaches every critical component.”

This security release addresses vulnerabilities across a broad range of open-source and commercial software components used throughout enterprise environments. The update includes multiple Critical, High, Medium, and Low severity vulnerabilities affecting web frameworks, databases, messaging platforms, networking libraries, cryptographic libraries, virtualization software, operating system components, logging frameworks, and developer tools. The fixes improve memory safety, input validation, authentication, authorization, bounds checking, cryptographic handling, and resource management while reducing the overall attack surface.

The release includes several Critical vulnerabilities with confirmed CVSS scores of 9.8, 9.4, and 9.1, together with numerous High severity vulnerabilities ranging from 7.0 to 8.9. Several entries include verified public proof-of-concept availability, while no active exploitation is identified in the provided data.

CVE LIST:

CVE-2024-28168 CVE-2024-29371 CVE-2024-37997 CVE-2024-47554 CVE-2024-7254 CVE-2025-13465 CVE-2025-27821 CVE-2025-48924 CVE-2025-5115 CVE-2025-54920 CVE-2025-67030 CVE-2025-67721 CVE-2025-67735 CVE-2025-68161 CVE-2025-7962 CVE-2025-8916 CVE-2026-1002 CVE-2026-10879 CVE-2026-1225 CVE-2026-21452 CVE-2026-22029 CVE-2026-2332 CVE-2026-23865 CVE-2026-24281 CVE-2026-25526 CVE-2026-25639 CVE-2026-27727 CVE-2026-28387 CVE-2026-33557 CVE-2026-33871 CVE-2026-34478 CVE-2026-34481 CVE-2026-35554 CVE-2026-41044 CVE-2026-4176 CVE-2026-43512 CVE-2026-46975 CVE-2026-47022 CVE-2026-47038 CVE-2026-47039 CVE-2026-47040 CVE-2026-47045 CVE-2026-47046 CVE-2026-47060 CVE-2026-47061 CVE-2026-4738 CVE-2026-54285 CVE-2026-54513 CVE-2026-54515 CVE-2026-54518 CVE-2026-60156 CVE-2026-60157 CVE-2026-60172 CVE-2026-60175 CVE-2026-60394 CVE-2026-60395 CVE-2026-60396 CVE-2026-60397 CVE-2026-60398 CVE-2026-60399 CVE-2026-60400 CVE-2026-60630 CVE-2026-61211 CVE-2026-7210 CVE-2026-7383

 

Vulnerability Coverage by Product / Subsystem

Operating Systems

  • Linux Kernel
  • Oracle Database Server
  • Oracle Net Services
  • GoldenGate Stream Analytics

Application Servers & Web Platforms

  • Apache Tomcat
  • Apache ActiveMQ
  • Apache Kafka
  • Apache Kafka Clients
  • Apache Spark
  • Eclipse Jetty
  • React Router
  • Apache ZooKeeper

Databases

  • Oracle Database Server
  • MongoDB Server

Networking & Communication

  • Netty
  • OpenSSL
  • Apache Hadoop HDFS Native Client
  • msgpack-java
  • Eclipse Vert.x
  • Jakarta Mail
  • axios

Logging & Monitoring

  • Apache Log4j Core
  • Apache Log4j JSON Template Layout
  • OpenTelemetry JavaScript

Serialization / Data Processing

  • Protocol Buffers
  • Jackson Databind
  • MessagePack Java
  • Apache XML Graphics FOP
  • Apache Commons IO
  • Apache Commons Lang
  • JinJava

Cryptography & Security Libraries

  • BC Java
  • OpenSSL
  • Logback-core
  • jose4j
  • mchange-commons-java

JavaScript / Web Libraries

  • Lodash
  • axios
  • React Router

Developer & Build Tools

  • Plexus Utils
  • Aircompressor
  • GDAL
  • Perl
  • FreeType

Messaging & Middleware

  • Apache Kafka
  • Apache ActiveMQ
  • Netty

Visualization & Engineering Software

  • Siemens JT Open
  • JT2Go
  • PLM XML SDK
  • Teamcenter Visualization

Key Security Themes

  • Remote code execution prevention
  • Authentication and authorization hardening
  • Memory corruption mitigation
  • Use-after-free and buffer overflow fixes
  • Bounds validation improvements
  • Deserialization security
  • XML and request parsing protections
  • Denial-of-service resilience
  • Information disclosure prevention
  • Race condition and concurrency fixes
  • Multiple Critical vulnerabilities were addressed across widely deployed enterprise software.
  • Memory safety, authentication, deserialization, and input validation represent the primary security improvements.
  • Several vulnerabilities have publicly available proof-of-concept code, increasing the urgency of patch deployment.
  • Applying these updates significantly reduces risk across enterprise application stacks and infrastructure.

Critical – Same Day Deploymentruflo

“An exposed management interface can turn a trusted automation tool into an attacker’s command center.”

This patch addresses CVE-2026-59726, affecting ruflo prior to version 3.16.3. The CVSS score is 10.0, which is Critical severity. The vulnerability stems from unauthenticated exposure of the MCP bridge endpoints in the default Docker Compose deployment, allowing remote attackers to invoke privileged tool functions without authentication. No verified real-world exploitation has been reported.

A successful attack could allow an unauthenticated attacker to execute terminal commands, obtain a shell within the bridge container, read provider API keys, and poison AgentDB learning-store patterns. The issue is associated with CWE-306 (Missing Authentication for Critical Function), CWE-78 (OS Command Injection), and CWE-942 (Permissive Cross-domain Policy with Untrusted Domains). The vulnerability has Remote Code Execution (RCE) and Elevation of Privilege (EoP) characteristics. This issue is resolved in ruflo version 3.16.3.

Critical – Same Day DeploymentSolarWinds Serv-U

“A chain of access control flaws can turn administrative privileges into full system compromise.”

This update addresses multiple vulnerabilities affecting SolarWinds Serv-U. CVE-2026-28302, CVE-2026-28304, CVE-2026-28305, CVE-2026-28306, CVE-2026-28307, CVE-2026-28308, CVE-2026-28309, CVE-2026-28310, CVE-2026-28312, CVE-2026-28313, CVE-2026-28314, CVE-2026-28316, CVE-2026-28317, and CVE-2026-28321 each have a CVSS score of 9.1, which is Critical severity. CVE-2026-28315 has a CVSS score of 6.2, which is Medium severity. No verified real-world exploitation has been reported for these vulnerabilities.

The vulnerabilities include insecure direct object reference (IDOR), broken access control, improper authorization, and privilege escalation flaws that can result in unauthorized account access, administrator privilege escalation, arbitrary file read and write, SMTP hijacking, account takeover, and, in several scenarios, execution of code as the root user. Many of the Critical vulnerabilities require an authenticated domain administrator or group administrator account, while some can elevate domain users or groups to system administrator privileges. The impact is generally lower on Windows deployments, but affected Linux and UNIX environments remain at greater risk. The update also resolves a stored cross-site scripting vulnerability that could lead to administrator session hijacking or information disclosure.

Note: CVE-2026-28311 is not included because no valid CVE record was available.

High with EoP or RCE – Expedited DeploymentN-able N-central

“An incomplete fix can leave the door just as open as the original flaw.”

This patch addresses CVE-2026-18577, an authentication bypass vulnerability (CWE-288) affecting N-able N-central through version 2026.3.1. The CVSS score is 8.2, which is High severity. No verified real-world exploitation has been reported.

The vulnerability results from an incomplete fix for CVE-2026-18556, allowing an attacker to bypass authentication and potentially take over user accounts on affected systems. While the vulnerability is not identified as Remote Code Execution (RCE), it has Elevation of Privilege (EoP) characteristics because successful exploitation can lead to unauthorized account access and control. Organizations running affected versions of N-central should apply the latest available update to fully remediate the issue.

Zero-Day – Immediate Deploymenthuggingface diffusers

“Security checks only work when every execution path enforces them.”

This update addresses multiple vulnerabilities in huggingface diffusers prior to version 0.38.0. CVE-2026-44827 has a CVSS score of 8.8, High severity. A verified public proof of concept (PoC) demonstrates that an attacker can achieve remote code execution by abusing the trust_remote_code safeguard during DiffusionPipeline.from_pretrained() through a malicious None.py file in a Hugging Face Hub repository. CVE-2026-45804 has a CVSS score of 7.5, High severity. A verified PoC shows that changes to cached pipeline content can bypass the trust_remote_code validation, allowing custom pipeline code to execute without requiring trust_remote_code=True. CVE-2026-44513 has a CVSS score of 8.8, High severity. It allows multiple trust_remote_code bypass scenarios that can lead to arbitrary remote code execution, although no verified public exploitation has been reported.

These vulnerabilities share a common root cause: security validation was performed during the download process instead of at the point where dynamic Python modules were loaded. As a result, attackers could craft malicious model repositories or exploit alternate loading paths to execute arbitrary code despite the intended trust_remote_code protection. Version 0.38.0 corrects these issues by closing the affected code paths. Two of the vulnerabilities have Remote Code Execution (RCE) characteristics, while one has Elevation of Privilege (EoP) characteristics.

High with EoP or RCE – Expedited DeploymentCitrix Secure Access Client for Windows

“Endpoint software deserves the same attention as the systems it protects.”

This update addresses two vulnerabilities affecting Citrix Secure Access Client for Windows. CVE-2026-53565 has a CVSS score of 8.5, High severity. It is an Improper Privilege Management vulnerability (CWE-269) that could allow an attacker to gain elevated privileges on affected systems. CVE-2026-53566 has a CVSS score of 6.8, Medium severity. It is an Out-of-Bounds Read vulnerability (CWE-125) that may allow unauthorized memory access. No verified real-world exploitation has been reported for either vulnerability.

The update resolves privilege management and memory handling issues affecting Citrix Secure Access Client for Windows before 26.6.1.20. It also addresses the privilege management vulnerability in Citrix Endpoint Analysis Client for Windows before 26.5.1.7. CVE-2026-53565 has Elevation of Privilege (EoP) characteristics, while CVE-2026-53566 has Remote Code Execution (RCE) characteristics based on the supplied assessment.

Critical – Same Day DeploymentDell PowerProtect Data Domain

“Critical infrastructure deserves immediate attention when authentication and file access controls fail.”

This update addresses two Critical vulnerabilities affecting Dell PowerProtect Data Domain. CVE-2026-53481 has a CVSS score of 9.8, Critical severity. It is a Path Traversal vulnerability (CWE-22) that allows an unauthenticated remote attacker to gain unauthorized access by exploiting improper restriction of file paths. CVE-2026-53483 also has a CVSS score of 9.8, Critical severity. It is an Improper Authentication vulnerability (CWE-287) that could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access. No verified real-world exploitation has been reported for either vulnerability.

Both vulnerabilities affect Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 versions 8.6.1.0 through 8.6.1.10, LTS2025 versions 8.3.1.0 through 8.3.1.30, and LTS2024 versions 7.13.1.0 through 7.13.1.70. Successful exploitation could allow an attacker to take complete control of an affected system. While neither vulnerability is identified as Remote Code Execution (RCE), both have Elevation of Privilege (EoP) characteristics because they enable unauthorized system access. Dell recommends upgrading affected systems as soon as possible.

Zero-Day – Immediate DeploymentSGLang

“AI infrastructure is only as secure as the safeguards protecting its models and APIs.”

This update addresses multiple vulnerabilities affecting SGLang. CVE-2026-15969 has a CVSS score of 9.8, Critical severity, and allows unauthenticated remote code execution through crafted pickle payloads that bypass SafeUnpickler protections. CVE-2026-15971 has a CVSS score of 9.8, Critical severity, with a verified public proof of concept (PoC) demonstrating remote code execution when the optional dumper subsystem is enabled. CVE-2026-15974 has a CVSS score of 6.5, Medium severity, with a verified PoC for server-side request forgery (SSRF) and local file disclosure through unsanitized image_url input. CVE-2026-15976 has a CVSS score of 9.8, Critical severity, with a verified PoC showing remote code execution during model weight loading from a Hugging Face repository. CVE-2026-15977 has a CVSS score of 7.5, High severity, with a verified PoC demonstrating exposure of API keys and SSL keyfile information through the /server_info endpoint. CVE-2026-15978 has a CVSS score of 7.5, High severity, with a verified PoC showing that attackers can exfiltrate model weights when API keys are not configured.

The update resolves vulnerabilities affecting model loading, deserialization, API endpoint security, credential protection, and distributed model handling. Successful exploitation could lead to remote code execution, credential disclosure, server-side request forgery, local file access, and theft of proprietary AI model weights. Several of the vulnerabilities require specific features or configurations to be enabled, but together they represent a significant risk to AI inference environments. Organizations should update to the latest supported version of SGLang as soon as possible.

High or Medium – Important DeploymentApple iOS and iPadOS

“A single malformed file should never be enough to put a device at risk.”

This update addresses multiple vulnerabilities affecting Apple iOS and iPadOS. CVE-2026-64763, CVE-2026-64764, CVE-2026-64765, CVE-2026-64766, and CVE-2026-43776 each have a CVSS score of 7.8, which is High severity. CVE-2026-43818 has a CVSS score of 8.8, which is also High severity. No verified real-world exploitation has been reported for these vulnerabilities.

The vulnerabilities include out-of-bounds writes, integer overflows, and a buffer overflow that can be triggered by processing a maliciously crafted file or image. Successful exploitation may result in unexpected application termination or arbitrary code execution. Apple addressed these issues through improved bounds checking, improved input validation, and removal of vulnerable code. The fixes are included in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8 (where applicable), macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

High with EoP or RCE – Expedited DeploymentGitea Open Source Git Server

“A missing permission check can expose information that was never meant to leave the repository.”

This patch addresses CVE-2026-27771, a Broken Authorization vulnerability (CWE-862) affecting Gitea Open Source Git Server versions up to and including 1.26.1. The CVSS score is 8.2, which is High severity. No verified real-world exploitation has been reported.

The vulnerability is caused by insufficient permission checks for Composer package source links, which can expose private or internal package source information to unauthorized users. Successful exploitation could reveal sensitive repository metadata and internal package details that should remain restricted. While the vulnerability is not identified as Remote Code Execution (RCE), it has Elevation of Privilege (EoP) characteristics because it allows unauthorized access to protected information. Organizations running affected Gitea versions should upgrade to a fixed release to restore proper access controls.

High with EoP or RCE – Expedited DeploymentAdobe Photoshop Installer

“Even a trusted installer can become an attack vector when it searches the wrong place.”

This patch addresses CVE-2026-48388, an Uncontrolled Search Path Element vulnerability (CWE-427) affecting the Adobe Photoshop Installer. The CVSS score is 8.6, which is High severity. No verified real-world exploitation has been reported.

The vulnerability could allow an attacker to achieve arbitrary code execution in the context of the current user by placing a malicious library in a directory searched by the installer. Exploitation requires user interaction, as the victim must run the affected installer. While the vulnerability is not identified as Remote Code Execution (RCE), it has Elevation of Privilege (EoP) characteristics because it enables unauthorized code execution within the user’s security context. Adobe has addressed the issue by correcting the installer behavior to prevent loading malicious libraries from uncontrolled search paths.

High with EoP or RCE – Expedited DeploymentAdobe Premiere Pro

“A single malicious media file can turn creative work into a security risk.”

This patch addresses CVE-2026-34641, an Out-of-Bounds Write vulnerability (CWE-787) affecting Adobe Premiere Pro. The CVSS score is 7.8, which is High severity. No verified real-world exploitation has been reported.

The vulnerability could allow arbitrary code execution in the context of the current user if a victim opens a specially crafted malicious file in Adobe Premiere Pro. Because exploitation requires user interaction, an attacker must convince a user to open the malicious file. Based on the supplied assessment, the vulnerability has Remote Code Execution (RCE) and Elevation of Privilege (EoP) characteristics. Adobe has released a security update to address the memory handling flaw and organizations should deploy the update promptly.

High with EoP or RCE – Expedited DeploymentAutodesk AutoCAD

“One malicious design file can turn a trusted engineering tool into an attack path.”

This patch addresses CVE-2026-16463, a Heap-Based Buffer Overflow vulnerability (CWE-122) affecting Autodesk AutoCAD. The CVSS score is 7.8, which is High severity. No verified real-world exploitation has been reported.

The vulnerability can be triggered when AutoCAD parses a specially crafted DXF file. Successful exploitation could cause the application to crash, expose sensitive data, or execute arbitrary code in the context of the current process. Exploitation requires a user to open the malicious file. Based on the supplied assessment, the vulnerability has Remote Code Execution (RCE) characteristics but does not have Elevation of Privilege (EoP) characteristics. Autodesk has released a security update to address the memory handling flaw and organizations should apply the update to affected systems.

Critical – Same Day DeploymentIBM App Connect Enterprise

“When file access and command execution flaws exist together, attackers gain multiple paths to compromise.”

This update addresses multiple vulnerabilities affecting IBM App Connect Enterprise. CVE-2026-15435 has a CVSS score of 9.8, Critical severity. It is a path traversal vulnerability that allows a remote attacker to send a specially crafted URL containing “/../” sequences to write arbitrary files on the system. CVE-2026-14522 has a CVSS score of 8.8, High severity. It allows remote arbitrary command execution due to improper neutralization of CRLF characters. CVE-2026-12947 has a CVSS score of 7.5, High severity. It exposes potentially sensitive information stored in log files that may be accessible to a local user. CVE-2026-14519 has a CVSS score of 7.5, High severity. It is a path traversal vulnerability that allows a remote attacker to read arbitrary files. No verified real-world exploitation has been reported for these vulnerabilities.

The vulnerabilities affect IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27. Together, they expose systems to unauthorized file read and write operations, remote command execution, and disclosure of sensitive information. Based on the supplied assessment, CVE-2026-14522 has Remote Code Execution (RCE) characteristics, while CVE-2026-15435 and CVE-2026-14519 have Elevation of Privilege (EoP) characteristics. Organizations should prioritize applying the latest IBM security updates to affected deployments.

High with EoP or RCE – Expedited DeploymentIBM Db2

“A single memory handling flaw in a privileged helper can undermine the security of an entire database environment.”

This patch addresses CVE-2026-10535, a Stack-Based Buffer Overflow vulnerability (CWE-121) affecting IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4. The CVSS score is 8.4, which is High severity. No verified real-world exploitation has been reported.

The vulnerability exists in the setgid helper db2flacc, where improper memory handling can result in a buffer overflow. Successful exploitation could allow arbitrary code execution within the affected environment. Based on the supplied assessment, the vulnerability has Remote Code Execution (RCE) characteristics but does not have Elevation of Privilege (EoP) characteristics. IBM has released security updates to address the flaw, and organizations running affected Db2 versions should apply the update promptly.

Critical – Same Day DeploymentIBM Tivoli System Automation Application Manager

“Even an administrative login page becomes a security risk when untrusted content is allowed to execute.”

This patch addresses CVE-2026-11707, a Cross-Site Scripting (XSS) vulnerability (CWE-79) affecting IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server. The CVSS score is 9.3, which is Critical severity. No verified real-world exploitation has been reported.

The vulnerability exists in the administrative console login page, where improper handling of user-supplied input could allow malicious scripts to execute in a user’s browser. Successful exploitation could compromise the confidentiality and integrity of an administrator’s session, potentially leading to unauthorized actions within the administrative console. The vulnerability is not identified as Remote Code Execution (RCE) or Elevation of Privilege (EoP). IBM has released a security update to correct the input validation issue, and organizations should prioritize deployment due to the Critical severity.

High with EoP or RCE – Expedited DeploymentRed Hat Ansible Automation Platform 2

“When authentication can be bypassed, automation may execute commands the attacker never had permission to trigger.”

This update addresses two vulnerabilities affecting Red Hat Ansible Automation Platform 2, specifically the Event-Driven Ansible (EDA) components. CVE-2026-18141 has a CVSS score of 8.2, which is High severity. It allows an unauthenticated remote attacker to bypass mutual TLS (mTLS) authentication by manipulating the event stream URL and forging the HTTP Subject header, potentially injecting arbitrary events into Event-Driven Ansible workflows. CVE-2026-12383 has a CVSS score of 7.5, which is High severity. It stems from overly permissive access controls and reliance on an untrusted Subject HTTP header for authentication, allowing attackers to inject arbitrary events into mTLS-protected event streams. No verified real-world exploitation has been reported for either vulnerability.

The vulnerabilities affect the authentication and authorization mechanisms used by Event-Driven Ansible. Successful exploitation could allow attackers to trigger automated workflows without proper authentication, potentially causing unauthorized actions across managed environments. CVE-2026-18141 has Elevation of Privilege (EoP) characteristics based on the supplied assessment, while CVE-2026-12383 does not have Remote Code Execution (RCE) or Elevation of Privilege (EoP) characteristics. Organizations should apply the latest Red Hat security updates to restore proper authentication validation and secure event processing.

High with EoP or RCE – Expedited DeploymentRed Hat Enterprise Linux 10

“A collection of High severity flaws across core system components can create multiple paths to compromise if left unpatched.”

This update addresses multiple vulnerabilities affecting Red Hat Enterprise Linux 10. CVE-2026-16526 and CVE-2026-58222 each have a CVSS score of 8.8, which is High severity. CVE-2026-16524, CVE-2026-17523, CVE-2026-18107, and CVE-2026-18220 each have a CVSS score of 7.8, High severity. CVE-2026-16313 has a CVSS score of 7.6, High severity. CVE-2026-16529 has a CVSS score of 7.5, High severity, and CVE-2026-16527 has a CVSS score of 7.3, High severity. No verified real-world exploitation has been reported for any of these vulnerabilities.

The update resolves vulnerabilities across several components, including Performance Co-Pilot (PCP), the Linux kernel, CRIU, GNU binutils, Samba Active Directory Domain Controller, and sg3_utils. The issues include command injection, insecure internal connections, access control bypass, integer overflow, kernel privilege escalation, checkpoint and restore privilege escalation, memory corruption, LDAP filter injection, and improper handling of device data. Successful exploitation could lead to arbitrary command execution, disclosure of sensitive information, denial of service, privilege escalation, unauthorized access to Active Directory data, or system compromise under specific conditions. Based on the supplied assessment, CVE-2026-16524, CVE-2026-16529, and CVE-2026-18220 have Remote Code Execution (RCE) characteristics, while CVE-2026-18107 and CVE-2026-18220 have Elevation of Privilege (EoP) characteristics.

Zero-Day – Immediate DeploymentPaperclip

“A default deployment can become a direct path to complete server compromise.”

Paperclip versions before 2026.416.0 contain an import authorization bypass that allows an unauthenticated attacker to execute code on a network-accessible instance running in authenticated mode. The automated attack requires no credentials or user interaction and can compromise confidentiality, integrity, and availability. The CVSS score is 10.0, which is Critical severity.

Version 2026.416.0 patches the vulnerable authorization path. Public proof-of-concept exploit code is available.

Critical – Same Day DeploymentCisco Catalyst SD-WAN Controller

“Proactive security reviews are most valuable when they eliminate critical weaknesses before attackers can exploit them.”

Cisco has released software hardening updates for the Cisco Catalyst SD-WAN Controller to address multiple internally discovered vulnerabilities identified during a comprehensive security review. The updates resolve issues involving improper input validation, improper access control, improper link resolution before file access, and cleartext storage of sensitive information, improving the overall resilience of the platform.

CVE-2026-20303 has a CVSS score of 9.9, Critical severity. CVE-2026-20304 has a CVSS score of 9.9, Critical severity. CVE-2026-20310 has a CVSS score of 9.1, Critical severity. CVE-2026-20312 has a CVSS score of 8.8, High severity. CVE-2026-20313 has a CVSS score of 7.7, High severity. No verified public proof-of-concept code or real-world exploitation has been confirmed for these vulnerabilities.

Critical – Same Day DeploymentCisco IOS XE Software

“The strongest defenses are built by fixing hidden weaknesses before they become visible attacks.”

Cisco has released software hardening updates for Cisco IOS XE Software following a comprehensive internal security review. The updates address multiple internally discovered vulnerabilities involving improper neutralization of special elements and improper access control, strengthening the security of affected systems.

CVE-2026-20272 has a CVSS score of 9.8, Critical severity. CVE-2026-20267 has a CVSS score of 9.0, Critical severity. No verified public proof-of-concept code or real-world exploitation has been confirmed for these vulnerabilities.

Critical – Same Day DeploymentGoogle ADK

“Trust in agent actions depends on verifying every approval, not just receiving one.”

Google has released a security update for the Agent Development Kit (ADK) to address a critical vulnerability in the tool confirmation process. The flaw allows continuation forgery in tool confirmations, enabling an attacker who can manipulate or inject events into the session history to execute unauthorized tools. The issue stems from insufficient validation of tool registration, confirmation requirements, and confirmation arguments. The CVSS score is 9.3, which is Critical severity.

The update strengthens validation of tool confirmation workflows by ensuring that confirmation requests are properly associated with the executing agent and the original tool invocation. No verified public proof-of-concept code or real-world exploitation has been confirmed for this vulnerability.

High or Medium – Important DeploymentmacOS

“Screen Sharing access should never bypass valid credentials.”

Apple fixed an authentication flaw in macOS Screen Sharing that could allow an attacker on the network to authenticate without valid credentials. The issue is addressed through improved state management in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1. The CVSS score is 7.1, which is High severity.

Critical – Same Day DeploymentGemini CLI

“A malicious configuration file could turn a trusted CI workflow into host-level code execution.”

Google Cloud fixed a critical command injection vulnerability affecting Gemini CLI versions before 0.39.1 and the run-gemini-cli GitHub Action before 0.1.22. A maliciously crafted .gemini/.env file could allow an unprivileged attacker to achieve pre-sandbox host-level code execution on headless CI systems. The CVSS score is 10.0, which is Critical severity.

The patch strengthens the container-launch process against malicious configuration input before sandbox protections take effect.

Webinar Recording: July 2026 Vulnerability Digest from Action1

See What You Can Do with Action1

 

Join our weekly LIVE demo “Patch Management That Just Works with Action1” to learn more

about Action1 features and use cases for your IT needs.

 

spiceworks logo
getapp logo review
software advice review
trustradius
g2 review
g2 review