VulnSea

Daily digest

Thursday 16 July 2026

A quiet day: only 63 new CVEs against a recent average of about 165. Severity skewed high: 11 critical and 22 high, 52% of the total. 4 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. Microsoft was the most-affected vendor with 4.

63
New CVEs
11
Critical
3
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-25089Critical· 9.8CISA KEVPoC
3mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

▾ Hadalfortinet · fortisandboxEPSS 76%via NVD
CVE-2026-39808Critical· 9.8CISA KEVPoC
5mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

▾ Hadalfortinet · fortisandboxEPSS 47%via NVD
CVE-2026-58644Critical· 9.8CISA KEVPoC
2mo ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

▾ Hadalmicrosoft · sharepoint_serverEPSS 16%via NVD

New this day, ranked by depth score

The 12 that matter most of the 63 published.

CVE-2026-55579Critical· 9.8PoC
2mo ago

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

▾ Abyssalpheditor · pheditor/pheditorEPSS 0.79%via GHSA
CVE-2026-15013Critical· 9.8PoC
2mo ago

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_s…

▾ AbyssalEPSS 1.5%via NVD
CVE-2026-46512Critical· 9.9
2mo ago

Frogman provides headless PBX control through MCP and HTTP API

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/DialplanApply.php wrote Dialplan/Templates…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-46562Critical· 9.8
2mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed…

▾ Midnightspaceapplications · yamcsEPSS 0.98%via NVD
CVE-2023-49899Critical· 9.8
2mo ago

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

▾ MidnightEPSS 0.31%via NVD
CVE-2026-22752Critical· 9.6
2mo ago

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1…

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1…

▾ Midnightbroadcom · spring_authorization_serverEPSS 0.48%via NVD
CVE-2026-15925Critical
2mo ago

Snowflake Connector for Python improperly verifies TLS hostnames

Snowflake Connector for Python improperly verifies TLS hostnames

▾ Midnightsnowflake-connector-python · snowflake-connector-pythonEPSS 0.29%via OSV
CVE-2026-63089Critical· 9.3
2mo ago

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a…

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-46621Critical· 9.1
2mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without e…

▾ Midnightspaceapplications · yamcsEPSS 1.1%via NVD
CVE-2026-45568Critical· 9.1
2mo ago

zrok is software for sharing web services, files, and network resources

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the reque…

▾ Midnightnetfoundry · zrokEPSS 0.54%via NVD
CVE-2026-10050Critical· 9.1
2mo ago

jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision (CVE-2026-10050)

A flaw was found in Eclipse Jetty, a widely used web server and servlet container. This vulnerability affects its HTTP Digest authentication mechanism, which is used to verify user identities. The issue arises because Jetty's hash computat…

▾ MidnightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.63%via CSAF
CVE-2026-55578High· 8.8
2mo ago

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

▾ Twilightpheditor · pheditor/pheditorEPSS 0.67%via GHSA

Most-affected vendors

By CVEs published in the period.