Daily digest
Tuesday 7 July 2026
92 new CVEs this day, in line with the recent average. Of those, 7 critical and 23 high. 9 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. better-auth was the most-affected vendor with 11.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-56290Critical· 9.8CISA KEVPoCThe Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVE-2026-55255Critical· 9.9CISA KEVPoCLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
New this day, ranked by depth score
The 12 that matter most of the 92 published.
CVE-2026-59705Critical· 9.8PoCmem0 - OpenMemory API Unauthenticated Access via Memory Endpoints
mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without authentication middlewa…
CVE-2026-59706Critical· 9.3PoCmem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url
mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like …
CVE-2026-59707High· 8.6PoCLocalAI - Server-Side Request Forgery via POST /models/apply
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to galle…
CVE-2026-57851High· 7.8PoCMSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by…
CVE-2026-33264Critical· 9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler /…
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain…
CVE-2026-56812High· 7.5PoCImproper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…
Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…
CVE-2026-53513Critical· 9.6@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
CVE-2026-27823CriticalEGroupware has a Remote Code Execution Vulnerability
EGroupware has a Remote Code Execution Vulnerability
CVE-2026-59704High· 7.1PoCCap - Missing Access Control in Video AI Metadata Endpoint
Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can supply arbitrary video IDs to read sensitiv…
CVE-2026-58473Critical· 9.1Cognee allows non-superusers to overwrite global LLM configuration
Cognee allows non-superusers to overwrite global LLM configuration
CVE-2026-53512Critical· 9.1Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVE-2026-14474High· 8.8A flaw was found in SSSD's LDAP sudo provider
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subt…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2022-30023Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.exploited74
- CVE-2021-25297Nagios XI version xi-5.7.5 is affected by OS command injectionepss85
Most-affected vendors
By CVEs published in the period.