Weekly digest
Week 30, 2026 (20–26 Jul)
A busier-than-usual week with 867 new CVEs (recent average about 568). Severity skewed high: 100 critical and 374 high, 55% of the total. 23 arrived with exploitation evidence or public exploit code already attached. CISA added 5 CVEs to the Known Exploited Vulnerabilities catalog. 10 CVEs saw exploit probability (EPSS) jump by ten points or more. oracle was the most-affected vendor with 154.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-63030Critical· 9.8CISA KEVPoCWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…
CVE-2026-50522Critical· 9.8CISA KEVPoCMicrosoft SharePoint Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-16232Critical· 9.1CISA KEV0dayPoCAn authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…
CVE-2026-0770HighCISA KEV0dayPoCLangflow affected by Remote Code Execution via validate_code() exec()
Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2026-60137Medium· 5.9CISA KEVPoCWordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Rising exploit probability
Largest EPSS increases inside the period (≥ 10 points).
- CVE-2026-63030Critical· 9.8WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…8.9% → 98%
- CVE-2026-56290Critical· 9.8The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.2.9% → 83%
- CVE-2026-60137Medium· 5.9WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.4.0% → 78%
- CVE-2026-56291Critical· 9.8The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.8.6% → 76%
- CVE-2026-0770HighLangflow affected by Remote Code Execution via validate_code() exec()10% → 53%
- CVE-2026-8037Critical· 9.6OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…43% → 85%
- CVE-2026-25089Critical· 9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …36% → 70%
- CVE-2026-20896Critical· 9.8Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.0.78% → 32%
- CVE-2026-55255Critical· 9.9Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow0.56% → 29%
- CVE-2026-48939Critical· 9.8A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.1.5% → 24%
New this week, ranked by depth score
The 12 that matter most of the 867 published.
CVE-2026-16232Critical· 9.1CISA KEV0dayPoCAn authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successfu…
CVE-2026-66012Critical· 10.0PoCSiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, i…
CVE-2026-15630Critical· 9.9PoCCVE-2026-15630
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
CVE-2026-65606Critical· 9.6PoCSiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts t…
CVE-2026-65605Critical· 9.6PoCSiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied wh…
CVE-2026-59891Critical· 9.6PoCCredential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
CVE-2026-61736Critical· 9.3PoCLightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2026-58424High· 8.9PoCGitea: Permanent Fork PR Workflow Approval Gate Bypass
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-65013High· 8.8PoCOnlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…
CVE-2026-63764High· 8.6PoCLMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…
LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original U…
CVE-2026-63765High· 8.2PoCChatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing au…
GHSA-w28w-gp39-m4p6Critical· 10.0Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-63030WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL In…kev, exploited, epss98
- CVE-2026-60137WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.kev, exploited, epss73
- CVE-2026-0770Langflow affected by Remote Code Execution via validate_code() exec()kev, exploited, epss79
- CVE-2026-56290The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.epss85
- CVE-2026-8037OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…epss98
- CVE-2026-39808A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…epss97
- CVE-2026-25089A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …epss94
- CVE-2026-45659Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.epss94
Most-affected vendors
By CVEs published in the period.