VulnSea

Weekly digest

Week 30, 2026 (20–26 Jul)

A busier-than-usual week with 867 new CVEs (recent average about 568). Severity skewed high: 100 critical and 374 high, 55% of the total. 23 arrived with exploitation evidence or public exploit code already attached. CISA added 5 CVEs to the Known Exploited Vulnerabilities catalog. 10 CVEs saw exploit probability (EPSS) jump by ten points or more. oracle was the most-affected vendor with 154.

867
New CVEs
100
Critical
5
KEV additions
21
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-63030Critical· 9.8CISA KEVPoC
2mo ago

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…

HadalEPSS 97%via NVD
CVE-2026-50522Critical· 9.8CISA KEVPoC
2mo ago

Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

HadalMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 85%via CVEORG
CVE-2026-16232Critical· 9.1CISA KEV0dayPoC
2mo ago

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…

Hadalcheckpoint · multi-domain_security_managementEPSS 72%via NVD
CVE-2026-0770HighCISA KEV0dayPoC
8mo ago

Langflow affected by Remote Code Execution via validate_code() exec()

Langflow affected by Remote Code Execution via validate_code() exec()

Abyssallangflow · langflowEPSS 64%via OSV
CVE-2026-60137Medium· 5.9CISA KEVPoC
2mo ago

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

MidnightEPSS 78%via NVD

Rising exploit probability

Largest EPSS increases inside the period (≥ 10 points).

  • CVE-2026-63030Critical· 9.8WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…8.9%98%
  • CVE-2026-56290Critical· 9.8The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.2.9%83%
  • CVE-2026-60137Medium· 5.9WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.4.0%78%
  • CVE-2026-56291Critical· 9.8The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.8.6%76%
  • CVE-2026-0770HighLangflow affected by Remote Code Execution via validate_code() exec()10%53%
  • CVE-2026-8037Critical· 9.6OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…43%85%
  • CVE-2026-25089Critical· 9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …36%70%
  • CVE-2026-20896Critical· 9.8Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.0.78%32%
  • CVE-2026-55255Critical· 9.9Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow0.56%29%
  • CVE-2026-48939Critical· 9.8A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.1.5%24%

New this week, ranked by depth score

The 12 that matter most of the 867 published.

CVE-2026-16232Critical· 9.1CISA KEV0dayPoC
2mo ago

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…

Hadalcheckpoint · multi-domain_security_managementEPSS 72%via NVD
CVE-2026-66012Critical· 10.0PoC
1mo ago

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, i…

Abyssalsiyuan-note · siyuanEPSS 0.55%via NVD
CVE-2026-15630Critical· 9.9PoC
2mo ago

CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

AbyssalCasdoor · CasdoorEPSS 0.34%via CVEORG
CVE-2026-65606Critical· 9.6PoC
2mo ago

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts t…

Abyssalsiyuan-note · siyuanEPSS 0.65%via NVD
CVE-2026-65605Critical· 9.6PoC
2mo ago

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied wh…

Abyssalsiyuan-note · siyuanEPSS 0.65%via NVD
CVE-2026-59891Critical· 9.6PoC
2mo ago

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Abyssalsigstore · @sigstore/ociEPSS 0.47%via GHSA
CVE-2026-61736Critical· 9.3PoC
2mo ago

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

Abyssallightrag-hku · lightrag-hkuEPSS 1.4%via GHSA
CVE-2026-58424High· 8.9PoC
2mo ago

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Midnightgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-65013High· 8.8PoC
2mo ago

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…

Midnightonlook · repoEPSS 0.37%via NVD
CVE-2026-63764High· 8.6PoC
2mo ago

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…

Midnightinternlm · lmdeployEPSS 0.39%via NVD
CVE-2026-63765High· 8.2PoC
2mo ago

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing au…

Midnightchatwoot · chatwootEPSS 0.70%via NVD
GHSA-w28w-gp39-m4p6Critical· 10.0
1mo ago

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Midnightprompty · @prompty/corevia GHSA

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-63030WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…98
  • CVE-2026-60137WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.73
  • CVE-2026-0770Langflow affected by Remote Code Execution via validate_code() exec()79
  • CVE-2026-56290The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.85
  • CVE-2026-8037OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…98
  • CVE-2026-39808A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…97
  • CVE-2026-25089A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …94
  • CVE-2026-45659Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.94

Most-affected vendors

By CVEs published in the period.