Daily digest
Wednesday 15 July 2026
A quiet day: only 71 new CVEs against a recent average of about 167. Of those, 4 critical and 28 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. mantisbt was the most-affected vendor with 8.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-46817Critical· 9.8CISA KEVPoCVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…
CVE-2023-4346High· 7.5CISA KEVKNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device
KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the device…
New this day, ranked by depth score
The 12 that matter most of the 71 published.
CVE-2026-59258High· 8.3PoCimmich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions
immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can dem…
CVE-2026-13585High· 8.2PoCAllocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …
CVE-2026-52891Critical· 9.9Wekan is open source kanban built with Meteor
Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avatars.js and models/…
CVE-2026-54466Criticalwebsocket-driver: Message corruption via abuse of protocol length headers
websocket-driver: Message corruption via abuse of protocol length headers
CVE-2026-52881CriticalMantisBT: Reflected XSS in admin/install.php via unescaped printf
MantisBT: Reflected XSS in admin/install.php via unescaped printf
CVE-2026-52847CriticalMantisBT: Reflected XSS in admin/install.php
MantisBT: Reflected XSS in admin/install.php
CVE-2026-59255High· 7.1PoCBloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema
BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens…
GHSA-62gx-5q78-wrvxHigh· 8.8obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete
obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete
CVE-2026-54498High· 8.7ViewComponent: around_render HTML-Safety Bypass
ViewComponent: around_render HTML-Safety Bypass
CVE-2026-20150High· 8.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…
CVE-2026-15029High· 8.4Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL req…
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL req…
CVE-2026-20156High· 8.1As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…
Most-affected vendors
By CVEs published in the period.