VulnSea

Daily digest

Friday 24 July 2026

A heavy day: 205 new CVEs, well above the recent average of about 109. Severity skewed high: 26 critical and 79 high, 51% of the total. 2 arrived with exploitation evidence or public exploit code already attached. Magick was the most-affected vendor with 28.

205
New CVEs
26
Critical
0
KEV additions
20
Records changed

New this day, ranked by depth score

The 12 that matter most of the 205 published.

GHSA-w28w-gp39-m4p6Critical· 10.0
2mo ago

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Midnightprompty · @prompty/corevia GHSA
GHSA-f25v-x6vr-962gCritical· 10.0
2mo ago

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Midnightpheditor · pheditor/pheditorvia GHSA
CVE-2026-62825Critical· 10.0
2mo ago

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Midnightmicrosoft · azure_key_vaultEPSS 0.71%via NVD
CVE-2026-58630Critical· 10.0
2mo ago

Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure App Service for LinuxEPSS 0.46%via CVEORG
CVE-2026-58275Critical· 10.0
2mo ago

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Midnightmicrosoft · azure_dnsEPSS 0.71%via NVD
CVE-2026-57106Critical· 10.0
2mo ago

Data Quality Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft Purview Data GovernanceEPSS 0.48%via CVEORG
CVE-2026-56191Critical· 10.0
2mo ago

Microsoft Exchange Online Tampering Vulnerability

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.76%via CVEORG
CVE-2026-56163Critical· 10.0
2mo ago

Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure Kubernetes ServiceEPSS 0.49%via CVEORG
CVE-2026-50517Critical· 9.9
2mo ago

Microsoft M365 Copilot Remote Code Execution Vulnerability

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

MidnightMicrosoft · Microsoft 365 CopilotEPSS 1.3%via CVEORG
GHSA-rjg6-39jm-rgg4Critical· 9.9
2mo ago

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

Midnightbetter-auth · @better-auth/scimvia GHSA
GHSA-7gfh-x38p-prh3Critical· 9.8
2mo ago

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

Midnightvelocityjs · velocityjsvia GHSA
CVE-2026-64232Critical· 9.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "…

In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "…

MidnightEPSS 0.46%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-63030WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…98
  • CVE-2026-8037OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…98
  • CVE-2026-39808A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…97
  • CVE-2026-25089A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …94
  • CVE-2026-45659Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.94
  • CVE-2026-34486Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …86
  • CVE-2026-56290The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.85
  • CVE-2025-67038An issue was discovered in Lantronix EDS5000 2.1.0.0R383

Most-affected vendors

By CVEs published in the period.