VulnSea

Weekly digest

Week 31, 2026 (27 Jul – 2 Aug)

611 new CVEs this week, in line with the recent average. Of those, 61 critical and 215 high. 34 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. 3 CVEs saw exploit probability (EPSS) jump by ten points or more. google was the most-affected vendor with 27.

611
New CVEs
61
Critical
2
KEV additions
5
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

Rising exploit probability

Largest EPSS increases inside the period (≥ 10 points).

  • CVE-2026-12569Critical· 9.8A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM2.3%30%
  • CVE-2025-21760High· 7.8In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_…9.5%33%
  • CVE-2025-68493High· 8.1Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…23%37%

New this week, ranked by depth score

The 12 that matter most of the 611 published.

CVE-2026-59310Critical· 9.8CISA KEVPoC
1mo ago

vCenter directory-traversal vulnerability

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

HadalVMware · Cloud FoundationEPSS 50%via CVEORG
CVE-2026-42016High· 8.1CISA KEVPoC
1mo ago

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Abyssaljfrog · artifactoryEPSS 9.1%via CVEORG
CVE-2026-66066CriticalPoC
1mo ago

Action Pack is a framework for handling and responding to web requests

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload …

Abyssalactivestorage · activestorageEPSS 28%via NVD
CVE-2026-14266High· 7.80dayPoC
1mo ago

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this …

Abyssal7-zip · 7-zipEPSS 0.74%via NVD
CVE-2026-52887Critical· 10.0PoC
1mo ago

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

Abyssalnocobase · @nocobase/plugin-notification-in-app-messageEPSS 0.89%via GHSA
CVE-2026-17566Critical· 9.9PoC
1mo ago

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the…

AbyssalEPSS 0.56%via NVD
CVE-2026-65321Critical· 9.8PoC
1mo ago

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS state…

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS state…

AbyssalEPSS 0.98%via NVD
CVE-2026-15964Critical· 9.8PoC
1mo ago

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_aj…

AbyssalEPSS 0.63%via NVD
CVE-2026-68771Critical· 9.8PoC
1mo ago

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserial…

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserial…

AbyssalEPSS 0.78%via NVD
CVE-2026-63223Critical· 9.8PoC
1mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when a…

AbyssalEPSS 0.76%via NVD
CVE-2026-68503Critical· 9.8PoC
1mo ago

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc…

Abyssalgrisuno · LazyOwnEPSS 0.50%via NVD
CVE-2026-59243Critical· 9.8PoC
1mo ago

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…

Abyssalapache · apache-airflow-providers-fabEPSS 0.45%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-12569A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM92
  • CVE-2025-68493Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…65
  • CVE-2025-49619Skyvern has a Jinja runtime leak63
  • CVE-2026-55450Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak63
  • CVE-2025-21760In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_…50

Most-affected vendors

By CVEs published in the period.