41 vulnerabilities across 14 products scored HIGH or above on July 01, 2026.
- π HIGH: 41
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-52785 (opf/openproject) β F1: exploitable β functional, AAS: 11.1 β 13.1 (HIGH β CRITICAL). Originally in 2026-06-26 bulletin.
- [UPGRADED] CVE-2026-45405 (dokku/dokku) β F1: exploitable β itw, AAS: 10.3 β 12.8 (HIGH β CRITICAL). Originally in 2026-06-26 bulletin.
- [UPGRADED] CVE-2026-54636 (dokku/dokku) β F1: exploitable β itw, AAS: 10.3 β 13.9 (HIGH β CRITICAL). Originally in 2026-06-26 bulletin.
- [UPGRADED] CVE-2026-52884 (notepad-plus-plus/notepad) β F1: exploitable β functional, AAS: 9.1 β 11.1 (HIGH β HIGH). Originally in 2026-06-26 bulletin.
- [UPGRADED] CVE-2026-54825 (wpdatatables/wpdatatables) β F1: exploitable β functional, AAS: 9.6 β 11.6 (HIGH β HIGH). Originally in 2026-06-26 bulletin.
- [UPGRADED] CVE-2026-50189 (appsmith/appsmith) β F1: exploitable β functional, AAS: 9.7 β 10.8 (HIGH β HIGH). Originally in 2026-06-24 bulletin.
- [UPGRADED] CVE-2026-54067 (siyuan-note/siyuan) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-06-24 bulletin.
- [UPGRADED] CVE-2026-52794 (sentry/sentry) β F1: exploitable β itw, AAS: 9.3 β 10.9 (HIGH β HIGH). Originally in 2026-06-24 bulletin.
π [HIGH] google/chrome
25 CVEs | CVSS 3.1: 9.6 | AAS 11.4
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*(< 150.0.7871.46)
Google Chrome versions prior to 150.0.7871.46 are affected by 25 vulnerabilities, including multiple critical-severity issues. The most severe is a use-after-free in the Dawn graphics layer that could allow a remote attacker to escape the browser sandbox via a crafted HTML page, carrying a CVSS score of 9.6. Additional flaws span multiple Chrome components and are considered exploitable.
All organizations and individuals running Google Chrome or Chromium-based browsers should prioritize this update. Security teams should ensure all endpoints are updated to version 150.0.7871.46 or later immediately. Refer to the vendor advisory at chromereleases.googleblog.com for the full list of addressed issues and additional detail.
- π CVE-2026-14417 (CVSS 3.1: 9.6)
- π CVE-2026-14424 (CVSS 3.1: 9.6)
- π CVE-2026-14392 (CVSS 3.1: 9.6)
- π CVE-2026-14398 (CVSS 3.1: 9.6)
- π CVE-2026-14397 (CVSS 3.1: 9.6)
- π CVE-2026-14425 (CVSS 3.1: 9.6)
- π CVE-2026-14419 (CVSS 3.1: 9.6)
- π CVE-2026-14423 (CVSS 3.1: 9.6)
- π CVE-2026-14420 (CVSS 3.1: 9.6)
- π CVE-2026-14390 (CVSS 3.1: 9.6)
- π CVE-2026-14405 (CVSS 3.1: 9.6)
- π CVE-2026-14403 (CVSS 3.1: 8.8)
- π CVE-2026-14395 (CVSS 3.1: 8.8)
- π CVE-2026-14383 (CVSS 3.1: 8.8)
- π CVE-2026-14432 (CVSS 3.1: 8.8)
- π CVE-2026-14393 (CVSS 3.1: 8.8)
- π CVE-2026-14407 (CVSS 3.1: 8.8)
- π CVE-2026-14430 (CVSS 3.1: 8.8)
- π CVE-2026-14431 (CVSS 3.1: 8.8)
- π CVE-2026-14387 (CVSS 3.1: 9.6)
- π CVE-2026-14411 (CVSS 3.1: 9.6)
- π CVE-2026-14382 (CVSS 3.1: 9.6)
- π CVE-2026-14416 (CVSS 3.1: 9.6)
- π CVE-2026-14427 (CVSS 3.1: 8.3)
- π CVE-2026-14400 (CVSS 3.1: 8.3)
π [HIGH] tinacms/tinacms
2 CVEs | CVSS 4.0: 7.8 | AAS 10.8
cpe:2.3:a:tinacms:tinacms:*:*:*:*:*:*:*:*
TinaCMS, a headless content management system, is affected by 2 vulnerabilities in versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, with a maximum CVSS score of 7.8. The flaws involve cross-origin postMessage handlers that fail to verify message origin and a rich-text URL sanitization bypass, enabling stored cross-site scripting and session takeover. Proof-of-concept exploit code is available.
Organizations using TinaCMS for content management should update to @tinacms/app 2.5.6 or tinacms 3.9.3 or later immediately. Review the vendor pull request at github.com/tinacms/tinacms/pull/7056 for full remediation details and assess whether any content authoring sessions may have been compromised.
- π CVE-2026-55660 (CVSS 4.0: 7.6)
- π CVE-2026-54074 (CVSS 3.1: 7.8)
π [HIGH] bps/html::gumbo
1 CVE | CVSS 3.1: 9.8 | AAS 10.8
cpe:2.3:a:bps:html_gumbo:*:*:*:*:*:*:*:*
HTML::Gumbo versions before 0.19, a Perl HTML parsing library, contains a critical heap memory disclosure vulnerability with a CVSS score of 9.8. A type confusion flaw in the walk_tree function mishandles template elements as text nodes, causing a strlen heap over-read that leaks process memory to any caller parsing HTML input containing a template element. The vulnerability is considered exploitable and could expose sensitive data from application memory.
Teams running Perl applications or services that depend on HTML::Gumbo for HTML parsing should update to version 0.19 or later immediately. Refer to the Debian bug tracker at bugs.debian.org/1104789 for additional advisory details and patching guidance.
- π CVE-2025-15646 (CVSS 3.1: 9.8)
π [HIGH] ladybirdbrowser/ladybird
1 CVE | CVSS 4.0: 8.9 | AAS 10.4
cpe:2.3:a:ladybirdbrowser:ladybird:*:*:*:*:*:*:*:*
The Ladybird web browser contains a dangling-reference memory-safety vulnerability in its WebAssembly ESM-integration module loader, carrying a CVSS score of 8.9. When a JavaScript function is imported into a WebAssembly module via the ESM path, a stack-local FunctionType is passed by reference and later destroyed while a callback still holds a reference to it, creating a use-after-free condition that is considered exploitable.
Anyone testing or developing with the Ladybird browser should update to the latest source as soon as a fix is available. Review the vendor advisory at the Ladybird GitHub repository for patch status and monitor for updated builds that address the flaw in WebAssemblyModule.cpp.
- π CVE-2026-58592 (CVSS 4.0: 8.9)
π [HIGH] hoppscotch/hoppscotch
1 CVE | CVSS 3.1: 10.0 | AAS 10.2
cpe:2.3:a:hoppscotch:hoppscotch:*:*:*:*:*:*:*:*
Hoppscotch, an open-source API development ecosystem, contains a critical mass assignment vulnerability in self-hosted deployments of hoppscotch-backend version 2026.4.1 and earlier, carrying a maximum CVSS score of 10.0. The unauthenticated POST /v1/onboarding/config endpoint accepts arbitrary properties due to a missing input validation whitelist, allowing an attacker to inject and overwrite sensitive infrastructure configuration entries without any authentication.
Organizations running self-hosted Hoppscotch instances should review the fix in the vendor pull request at github.com/hoppscotch/hoppscotch/pull/6171 and update immediately. Until patched, consider restricting network access to the onboarding endpoint or placing it behind authentication as a mitigation.
- π CVE-2026-50160 (CVSS 3.1: 10.0)
π [HIGH] yamadashy/repomix
1 CVE | CVSS 3.1: 8.8 | AAS 10.1
cpe:2.3:a:yamadashy:repomix:*:*:*:*:*:*:*:*
Repomix, a code repository packaging tool by yamadashy, contains an argument injection vulnerability in its remote branch handling with a CVSS score of 8.8. The –remote-branch CLI option passes unsanitized user input directly to git fetch and git checkout subprocesses without proper delimiters or validation, allowing an attacker to achieve arbitrary command execution or bypass security controls. The vulnerability is considered exploitable.
Developers and teams using repomix with remote repository functionality should update to a patched version immediately. Review the vendor advisory at github.com/advisories/GHSA-9mm9-rqhj-j5mx for remediation details, and avoid using the –remote-branch option with untrusted input until a fix is applied.
- π CVE-2026-49987 (CVSS 3.1: 8.8)
π [HIGH] containerd/containerd
1 CVE | CVSS 4.0: 7.3 | AAS 10.1
cpe:2.3:a:containerd:containerd:*:*:*:*:*:*:*:*
Containerd, a widely used open-source container runtime, contains a vulnerability in versions prior to 1.7.32, 2.0.9, 2.2.4, and 2.3.1 that allows bypass of the Kubernetes runAsNonRoot security restriction, with a CVSS score of 7.3. When a container image specifies a numeric User directive that exceeds 32-bit integer bounds, containerd misinterprets it as a username, and a crafted /etc/passwd file can map that string to UID 0, causing the container to run as root. Proof-of-concept exploit code is available.
Organizations running Kubernetes clusters or using containerd directly should update to versions 1.7.32, 2.0.9, 2.2.4, or 2.3.1 or later immediately. Review the vendor advisory at github.com/containerd/containerd/security/advisories/GHSA-fqw6-gf59-qr4w for full details and audit container images for abnormally large numeric User values.
- π CVE-2026-46680 (CVSS 4.0: 7.3)
π [HIGH] gradio-app/gradio
1 CVE | CVSS 4.0: 8.7 | AAS 10.1
cpe:2.3:a:gradio-app:gradio:*:*:*:*:*:*:*:*
Gradio versions before 6.16.0 contain a path traversal vulnerability in the FileExplorer component’s preprocess method, carrying a CVSS score of 8.7. An unauthenticated attacker can supply crafted directory traversal sequences or absolute paths that cause the application to bypass the configured root directory, enabling arbitrary file read and exposure of sensitive files on the host system. The vulnerability is considered exploitable.
Teams running Gradio-based applications, particularly machine learning demos and interfaces exposed to the network, should update to version 6.16.0 or later immediately. Review the vendor fix at the linked GitHub commit for details and audit any publicly accessible Gradio deployments for potential prior exploitation.
- π CVE-2026-49119 (CVSS 4.0: 8.7)
π [HIGH] ultravnc/ultravnc
3 CVEs | CVSS 3.1: 9.3 | AAS 9.9
cpe:2.3:a:uvnc:ultravnc:*:*:*:*:*:*:*:*(<= 1.8.2.2)cpe:2.3:a:ultravnc:ultravnc:*:*:*:*:*:*:*:*
UltraVNC repeater through version 1.8.2.2 is affected by 3 vulnerabilities, including multiple critical-severity issues with a maximum CVSS score of 9.3. The most severe involves a hardcoded default administrator password of “adminadmi2” on the HTTP administration server, which lacks rate limiting or lockout, allowing any remote attacker who can reach the repeater HTTP port to authenticate and gain full administrative control. The vulnerabilities are considered exploitable.
Organizations using UltraVNC repeater should immediately verify that default credentials have been changed, restrict network access to the repeater HTTP administration port, and monitor the UltraVNC GitHub repository at github.com/ultravnc/UltraVNC for patched releases addressing all three flaws.
- π CVE-2026-7839 (CVSS 3.1: 9.1)
- π CVE-2026-7840 (CVSS 4.0: 9.3)
- π CVE-2026-7838 (CVSS 4.0: 8.7)
π [HIGH] rarlab/winrar
1 CVE | CVSS 3.1: 7.8 | AAS 9.6
cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*
WinRAR and UnRAR contain an out-of-bounds heap write vulnerability in the RAR5 recovery volume parser with a CVSS score of 7.8. A crafted set of two or more .rev files can exploit a size validation flaw in RecVolumes5::ReadHeader, where subsequent recovery files supply values checked against their own headers rather than the actual allocated buffer size, allowing an attacker to write controlled data beyond heap boundaries. The vulnerability is considered exploitable and could be triggered by opening a malicious archive.
Organizations and end users running WinRAR or applications incorporating the UnRAR library should update to the latest version immediately. Review the vendor advisory for patching details and exercise caution with recovery volume files from untrusted sources.
- π CVE-2026-14191 (CVSS 3.1: 7.8)
π [HIGH] pretix/pretix-oppwa
1 CVE | CVSS 4.0: 9.0 | AAS 9.4
cpe:2.3:a:pretix:pretix-oppwa:*:*:*:*:*:*:*:*
The pretix-oppwa payment integration plugin, used with payment providers such as VR Payment and Hobex, contains a server-side request forgery vulnerability with a CVSS score of 9.0. The plugin accepts a user-controlled resourcePath query parameter during the payment callback redirect and appends it to the base URL for transaction status verification without sufficient validation, allowing an attacker to manipulate the server into making requests to arbitrary endpoints. The vulnerability is considered exploitable.
Organizations using pretix with the Oppwa-based payment integration should update to pretix 2026.5.3 or later immediately as detailed in the vendor advisory at pretix.eu/about/en/blog/20260701-release-2026-5-3/. Review transaction logs for any anomalous callback URLs that may indicate prior exploitation attempts.
- π CVE-2026-13603 (CVSS 4.0: 9.0)
π [HIGH] nodebb/nodebb
1 CVE | CVSS 4.0: 8.7 | AAS 9.3
cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:*
NodeBB contains an ActivityPub authentication bypass vulnerability with a CVSS score of 8.7. The inbound federation middleware verifies HTTP signatures and checks object origin but fails to validate that the attributedTo field matches the authenticated remote actor, allowing a federated attacker to impersonate any local user by setting attributedTo to a numeric user ID, which silently bypasses actor assertion checks. The vulnerability is considered exploitable.
Organizations running NodeBB instances with ActivityPub federation enabled should update beyond version 4.13.2 immediately and review the referenced source at github.com/NodeBB/NodeBB for a patched release. Consider temporarily disabling ActivityPub federation until a fix is applied, and audit recent federated posts for signs of author spoofing.
- π CVE-2026-58593 (CVSS 4.0: 8.7)
π [HIGH] latepoint/latepoint_β_calendar_booking_plugin_for_appointments_and_events
1 CVE | CVSS 3.1: 8.8 | AAS 9.1
cpe:2.3:a:latepoint:latepoint_calendar_booking_plugin_for_appointments_and_events:*:*:*:*:*:*:*:*(< 5.6.4)
The LatePoint Calendar Booking Plugin for Appointments and Events for WordPress versions up to and including 5.6.3 contains a privilege escalation vulnerability with a CVSS score of 8.8. An authenticated user with Agent-level access can exploit an insecure direct object reference in the order controller’s create_or_update function to overwrite any customer’s email address, including those linked to WordPress Administrator accounts, enabling full site takeover through password reset. The vulnerability is considered exploitable.
WordPress site administrators using the LatePoint plugin should update beyond version 5.6.3 immediately and audit order and customer records for unauthorized email changes. Review the referenced source at plugins.trac.wordpress.org for patching details and consider temporarily restricting Agent-level access until the fix is applied.
- π CVE-2026-13228 (CVSS 3.1: 8.8)
π [HIGH] altium/altium_enterprise_server
1 CVE | CVSS 4.0: 9.4 | AAS 9.0
cpe:2.3:a:altium:altium_enterprise_server:*:*:*:*:*:*:*:*
Altium Enterprise Server and Altium 365 contain a path traversal vulnerability in the shared Git Service component with a CVSS score of 9.4. An authenticated user with basic git access can exploit unsanitized file-manipulation operations to move arbitrary files outside the intended repository directory, enabling placement of attacker-controlled scripts into locations where the service automatically executes them, resulting in remote code execution. The vulnerability is considered exploitable.
Organizations using Altium Enterprise Server or Altium 365 should review the vendor security advisory at altium.com/platform/security-compliance/security-advisories and apply available patches immediately. Audit git service access logs for suspicious file-move operations and restrict repository access to trusted users until remediation is confirmed.
- π CVE-2026-14439 (CVSS 4.0: 9.4)