Daily digest
Wednesday 29 July 2026
A quiet day: only 48 new CVEs against a recent average of about 110. Of those, 3 critical and 20 high. 4 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. alextselegidis was the most-affected vendor with 6.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 12 that matter most of the 48 published.
CVE-2026-14266High· 7.80dayPoC7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this …
CVE-2026-59243Critical· 9.8PoCThe FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…
CVE-2026-20316Medium· 5.3CISA KEV0dayPoCA vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…
CVE-2026-64560High· 7.8PoCIn the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sy…
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sy…
CVE-2026-54735Critical· 10.0prebid-server's request forgery vulnerability allows for possible host environment data extraction
prebid-server's request forgery vulnerability allows for possible host environment data extraction
CVE-2026-54680Critical· 9.9Logging operator automates the deployment and configuration of Kubernetes logging pipelines
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record…
CVE-2026-11393High· 9.0AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
CVE-2026-54666High· 8.3swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
CVE-2026-54664High· 8.3swagger-typescript-api vulnerable to code injection via unescaped enum string values
swagger-typescript-api vulnerable to code injection via unescaped enum string values
CVE-2026-54662High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
CVE-2026-54661High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVE-2026-54727High· 8.2proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
Most-affected vendors
By CVEs published in the period.