VulnSea

Weekly digest

Week 29, 2026 (13–19 Jul)

A heavy week: 1,159 new CVEs, well above the recent average of about 450. Severity skewed high: 72 critical and 598 high, 58% of the total. 44 arrived with exploitation evidence or public exploit code already attached. CISA added 7 CVEs to the Known Exploited Vulnerabilities catalog. 3 CVEs saw exploit probability (EPSS) jump by ten points or more. Microsoft was the most-affected vendor with 576.

1159
New CVEs
72
Critical
7
KEV additions
4
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-39808Critical· 9.8CISA KEVPoC
5mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

Hadalfortinet · fortisandboxEPSS 93%via NVD
CVE-2026-25089Critical· 9.8CISA KEVPoC
3mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

Hadalfortinet · fortisandboxEPSS 76%via NVD
CVE-2026-58644Critical· 9.8CISA KEVPoC
2mo ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Hadalmicrosoft · sharepoint_serverEPSS 61%via NVD
CVE-2026-46817Critical· 9.8CISA KEVPoC
3mo ago

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

Hadaloracle · e-business_suiteEPSS 13%via NVD
CVE-2026-56155High· 7.8CISA KEV0dayPoC
2mo ago

Active Directory Federation Services Elevation of Privilege Vulnerability

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

AbyssalMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2023-4346High· 7.5CISA KEV
3y ago

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the device…

Abyssalknx · connection_authorizationEPSS 1.3%via NVD
CVE-2026-56164Medium· 5.3CISA KEV0dayPoC
2mo ago

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 27%via CVEORG

Rising exploit probability

Largest EPSS increases inside the period (≥ 10 points).

  • CVE-2026-39808Critical· 9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…49%84%
  • CVE-2026-8037Critical· 9.6OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…30%43%
  • CVE-2026-25089Critical· 9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …23%36%

New this week, ranked by depth score

The 12 that matter most of the 1159 published.

CVE-2026-63030Critical· 9.8CISA KEVPoC
2mo ago

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…

HadalEPSS 97%via NVD
CVE-2026-50522Critical· 9.8CISA KEVPoC
2mo ago

Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

HadalMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 85%via CVEORG
CVE-2026-9198Critical· 9.8CISA KEVPoC
2mo ago

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…

HadalEPSS 61%via NVD
CVE-2026-58644Critical· 9.8CISA KEVPoC
2mo ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Hadalmicrosoft · sharepoint_serverEPSS 61%via NVD
CVE-2026-55040Critical· 9.1CISA KEVPoC
2mo ago

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

HadalMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 51%via CVEORG
CVE-2026-9586Critical· 9.8CISA KEVPoC
2mo ago

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …

Hadalsangoma · switchvoxEPSS 12%via NVD
CVE-2026-60137Medium· 5.9CISA KEVPoC
2mo ago

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

MidnightEPSS 78%via NVD
MAL-2026-10779Critical⚠ Exploited
2mo ago

Malicious code in mlflow-ui (PyPI)

Malicious code in mlflow-ui (PyPI)

Abyssalmlflow-ui · mlflow-uivia OSV
CVE-2026-56155High· 7.8CISA KEV0dayPoC
2mo ago

Active Directory Federation Services Elevation of Privilege Vulnerability

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

AbyssalMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-55579Critical· 9.8PoC
2mo ago

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Abyssalpheditor · pheditor/pheditorEPSS 0.60%via GHSA
CVE-2026-15013Critical· 9.8PoC
2mo ago

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_s…

AbyssalEPSS 1.5%via NVD
CVE-2026-60121Critical· 9.8PoC
2mo ago

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

Abyssalvitec · flamingoEPSS 2.3%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-8037OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…98
  • CVE-2026-39808A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…97
  • CVE-2026-25089A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …94
  • CVE-2026-56291The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.82

Most-affected vendors

By CVEs published in the period.