Daily digest
Wednesday 22 July 2026
98 new CVEs this day, in line with the recent average. Of those, 1 critical and 39 high. 4 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. n8n was the most-affected vendor with 53.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-50522Critical· 9.8CISA KEVPoCMicrosoft SharePoint Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-16232Critical· 9.1CISA KEV0dayPoCAn authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…
New this day, ranked by depth score
The 12 that matter most of the 98 published.
CVE-2026-16232Critical· 9.1CISA KEV0dayPoCAn authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…
CVE-2026-65013High· 8.8PoCOnlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…
CVE-2026-65591HighPoCn8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
CVE-2026-64641HighNext.js: Denial of Service in App Router using Server Actions
Next.js: Denial of Service in App Router using Server Actions
CVE-2026-59208Highn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
GHSA-xwx6-jjhv-84p8Highn8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
GHSA-xmc9-4f2h-jf9cHighn8n: Edit Image Node Format Injection Allows Arbitrary File Write
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
GHSA-wq64-hcrf-8m56HighDuplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
GHSA-w46p-w7w2-fr9gHighDuplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
GHSA-vhcw-f978-xjjgHighDuplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
GHSA-rcv6-pvrj-4xcgHighn8n: Authenticated code execution in the n8n Git node
n8n: Authenticated code execution in the n8n Git node
GHSA-pppj-hq3g-57pjHighJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-63030WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…epss98
- CVE-2026-56290The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.epss85
- CVE-2026-0770Langflow affected by Remote Code Execution via validate_code() exec()epss79
- CVE-2026-60137WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.epss73
Most-affected vendors
By CVEs published in the period.