Daily digest
Thursday 30 July 2026
A busier-than-usual day with 111 new CVEs (recent average about 79). Severity skewed high: 23 critical and 36 high, 53% of the total. 6 arrived with exploitation evidence or public exploit code already attached. google was the most-affected vendor with 22.
New this day, ranked by depth score
The 12 that matter most of the 111 published.
CVE-2026-59310Critical· 9.8CISA KEVPoCvCenter directory-traversal vulnerability
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVE-2026-66066CriticalPoCAction Pack is a framework for handling and responding to web requests
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload …
CVE-2026-68503Critical· 9.8PoCLazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc…
CVE-2026-66418Critical· 9.3PoCOpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, whi…
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, whi…
CVE-2026-47858High· 8.0PoCStarting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclips…
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclips…
CVE-2026-67429Critical· 10.0Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
CVE-2026-66803Critical· 10.0Azure Cosmos DB Remote Code Execution Vulnerability
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVE-2026-68502Critical· 9.8LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_c…
CVE-2026-44101Critical· 9.8Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
CVE-2026-17768Critical· 9.6Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page
Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromiu…
CVE-2026-17684Critical· 9.6Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…
CVE-2026-17681Critical· 9.6Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2025-21760In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_…epss50
Most-affected vendors
By CVEs published in the period.