Daily digest
Tuesday 21 July 2026
A heavy day: 310 new CVEs, well above the recent average of about 157. Severity skewed high: 42 critical and 133 high, 56% of the total. 11 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. oracle was the most-affected vendor with 154.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-63030Critical· 9.8CISA KEVPoCWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…
CVE-2026-0770HighCISA KEV0dayPoCLangflow affected by Remote Code Execution via validate_code() exec()
Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2026-60137Medium· 5.9CISA KEVPoCWordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
New this day, ranked by depth score
The 12 that matter most of the 310 published.
CVE-2016-20096Critical· 9.8PoCLinknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login e…
CVE-2026-59891Critical· 9.6PoCCredential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
CVE-2026-65057Critical· 9.3PoCKeep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthchec…
CVE-2026-58424High· 8.9PoCGitea: Permanent Fork PR Workflow Approval Gate Bypass
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-65318High· 8.6PoCVerba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled UR…
CVE-2026-65317High· 8.6PoCVerba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by suppl…
CVE-2026-63764High· 8.6PoCLMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…
LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…
CVE-2026-65056High· 8.2PoCmcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only valida…
CVE-2026-60568Critical· 9.9Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…
CVE-2026-60565Critical· 9.9Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…
CVE-2026-60562Critical· 9.9Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…
CVE-2026-60561Critical· 9.9Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-63030WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…kev, exploited81
- CVE-2026-0770Langflow affected by Remote Code Execution via validate_code() exec()kev, exploited79
- CVE-2026-60137WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.kev, exploited59
Most-affected vendors
By CVEs published in the period.