Daily digest
Thursday 23 July 2026
A quiet day: only 45 new CVEs against a recent average of about 113. Severity skewed high: 8 critical and 22 high, 67% of the total. 7 arrived with exploitation evidence or public exploit code already attached. pypdf was the most-affected vendor with 4.
New this day, ranked by depth score
The 12 that matter most of the 45 published.
CVE-2026-15630Critical· 9.9PoCA non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
CVE-2026-65606Critical· 9.6PoCSiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts t…
CVE-2026-65605Critical· 9.6PoCSiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied wh…
CVE-2026-63765High· 8.2PoCChatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing au…
CVE-2026-64600High· 7.8PoCIn the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…
In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…
CVE-2026-54120Critical· 9.9Microsoft Surface Remote Code Execution Vulnerability
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-44210Critical· 9.9kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection (CVE-2026-44210)
A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, whic…
CVE-2026-65919High· 7.5PoCMeshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation
Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. A…
CVE-2026-56165Critical· 9.8Microsoft Account Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
GHSA-8fpg-xm3f-6cx3CriticalAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
GHSA-7rqj-j65f-68whCriticalAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
CVE-2026-65918High· 7.1PoCPyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy
PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or trunc…
Most-affected vendors
By CVEs published in the period.