19 vulnerabilities across 15 products scored HIGH or above on July 02, 2026.
- π΄ CRITICAL: 1
- π HIGH: 18
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-52785 (opf/openproject) β F1: exploitable β functional, AAS: 11.1 β 13.1 (HIGH β CRITICAL). Originally in 2026-06-26 bulletin.
- [UPGRADED] CVE-2026-45405 (dokku/dokku) β F1: exploitable β itw, AAS: 10.3 β 12.8 (HIGH β CRITICAL). Originally in 2026-06-26 bulletin.
- [UPGRADED] CVE-2026-54636 (dokku/dokku) β F1: exploitable β itw, AAS: 10.3 β 13.9 (HIGH β CRITICAL). Originally in 2026-06-26 bulletin.
- [UPGRADED] CVE-2026-52884 (notepad-plus-plus/notepad) β F1: exploitable β functional, AAS: 9.1 β 11.1 (HIGH β HIGH). Originally in 2026-06-26 bulletin.
- [UPGRADED] CVE-2026-54825 (wpdatatables/wpdatatables) β F1: exploitable β functional, AAS: 9.6 β 11.6 (HIGH β HIGH). Originally in 2026-06-26 bulletin.
π΄ [CRITICAL] craftcms/cms
2 CVEs | CVSS 4.0: 8.7 | AAS 12.8
cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*
Craft CMS versions 4.0.0-RC1 through 4.17.x and 5.0.0-RC1 through 5.9.x are affected by two critical vulnerabilities, including multiple issues that enable server-side request forgery and arbitrary JavaScript injection through the resource-js endpoint. With a CVSS 4.0 score of 8.7, these flaws allow attackers to manipulate host headers to bypass internal URL validation, and exploitation is considered feasible. Organizations running Craft CMS should upgrade immediately to version 4.18.0 or 5.10.0 and review the vendor advisory at the linked GitHub pull request for additional hardening guidance around trustedHosts configuration.
- π΄ CVE-2026-55791 (CVSS 4.0: 6.9)
- π CVE-2026-55794 (CVSS 4.0: 8.7)
π [HIGH] decolua/9router
1 CVE | CVSS 3.1: 9.8 | AAS 10.9
cpe:2.3:a:decolua:9router:*:*:*:*:*:*:*:*
Decolua 9router contains a critical authentication bypass vulnerability stemming from a hardcoded default JWT secret that is publicly known and committed to the source repository. Any unauthenticated remote attacker can forge valid session tokens to gain full administrative access to the dashboard and API on any instance where the JWT_SECRET environment variable has not been explicitly configured, earning this flaw a CVSS 3.1 score of 9.8. Administrators running 9router should immediately set a strong, unique JWT_SECRET environment variable, rotate any existing session tokens, and review the vendor advisory for patched versions.
- π CVE-2026-49352 (CVSS 3.1: 9.8)
π [HIGH] erlang/otp
2 CVEs | CVSS 4.0: 8.7 | AAS 10.6
cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= 28.0, < 28.0.1)cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= 26.0, < 26.2.5.12)cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= 27.0, < 27.3.4)
Erlang/OTP is affected by two vulnerabilities, including multiple issues in the SSL and DTLS subsystems, with a maximum CVSS 4.0 score of 8.7. An unauthenticated remote attacker can exploit a TOCTOU race condition in the dtls_packet_demux module by sending rapid ClientHello reconnections from the same source address, crashing all active DTLS sessions on a listener and causing a denial of service. Organizations running Erlang/OTP-based services that rely on DTLS or SSL should apply patches promptly and consult the vendor advisories for affected version details and remediation guidance.
- π CVE-2026-55950 (CVSS 4.0: 8.7)
- π CVE-2026-55952 (CVSS 4.0: 8.2)
π [HIGH] divi_engine/divi_form_builder
1 CVE | CVSS 3.1: 9.8 | AAS 10.6
cpe:2.3:a:divi_engine:divi_form_builder:*:*:*:*:*:*:*:*(< 5.1.9)
The Divi Form Builder plugin for WordPress versions 5.1.8 and earlier contains a critical arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution, rated CVSS 3.1 score of 9.8. The flaw exists in the do_image_upload function where attacker-controlled input is used to define allowed file extensions, enabling upload of PHP-executable files such as .phtml, .phar, and .php7 to bypass validation entirely. WordPress administrators using this plugin should update immediately to a patched version and audit their servers for any unauthorized file uploads or signs of compromise.
- π CVE-2026-5524 (CVSS 3.1: 9.8)
π [HIGH] creative_themes/blocksy_companion_pro
1 CVE | CVSS 3.1: 10.0 | AAS 10.3
cpe:2.3:a:creative_themes:blocksy_companion_pro:*:*:*:*:*:*:*:*
The Blocksy Companion Pro plugin for WordPress versions 2.1.46 and earlier is affected by an unauthenticated remote code execution vulnerability carrying the maximum CVSS 3.1 score of 10.0. This flaw allows any remote attacker without credentials to execute arbitrary code on the server, representing a complete compromise of the affected WordPress installation. Site administrators running Blocksy Companion Pro should update to a patched version immediately, audit their environments for indicators of compromise, and review the Patchstack advisory for further details.
- π CVE-2026-57624 (CVSS 3.1: 10.0)
π [HIGH] suse/rancher
1 CVE | CVSS 3.1: 9.9 | AAS 10.2
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
SUSE Rancher Fleet contains a critical cross-tenant credential access vulnerability with a CVSS 3.1 score of 9.9, caused by missing validation of valuesFrom references in the Helm Deployer component. An authenticated tenant owner can exploit this flaw to access Fleet credentials belonging to other tenants, breaking multi-tenant isolation. Organizations running Fleet versions 0.12 through 0.15 should upgrade immediately to 0.12.15, 0.13.11, 0.14.6, or 0.15.2 respectively, and review the vendor security advisory for any additional remediation steps.
- π CVE-2026-44935 (CVSS 3.1: 9.9)
π [HIGH] ubiquiti_inc/unifi_os_server
3 CVEs | CVSS 3.1: 9.9 | AAS 10.2
cpe:2.3:a:ubiquiti_inc:unifi_os_server:*:*:*:*:*:*:*:*(< 4.1.16)
Ubiquiti UniFi OS is affected by three vulnerabilities, including multiple command injection and input validation flaws, with a maximum CVSS 3.1 score of 9.9. A low-privileged attacker with network access can exploit these issues to execute arbitrary commands on the host device, potentially achieving full system compromise. Administrators managing UniFi OS infrastructure should apply the latest firmware updates immediately and consult Ubiquiti Security Advisory Bulletin 066 for affected versions and patching instructions.
- π CVE-2026-54402 (CVSS 3.1: 9.9)
- π CVE-2026-54403 (CVSS 3.1: 8.6)
- π CVE-2026-54404 (CVSS 3.1: 8.8)
π [HIGH] electerm/electerm
1 CVE | CVSS 3.1: 8.8 | AAS 10.1
cpe:2.3:a:electerm:electerm:*:*:*:*:*:*:*:*
Electerm, an open-source terminal and SSH client, contains a command injection vulnerability in its file system operations with a CVSS 3.1 score of 8.8. The rmrf, mv, and cp functions in the application construct shell commands by directly interpolating file paths without proper escaping of shell metacharacters, allowing an attacker to inject arbitrary commands through crafted file names. Users of Electerm should update to a patched version immediately and review the GitHub security advisory for affected version details and remediation guidance.
- π CVE-2026-49255 (CVSS 3.1: 8.8)
π [HIGH] ase/admin_and_site_enhancements_(ase)_pro
1 CVE | CVSS 3.1: 9.6 | AAS 9.9
cpe:2.3:a:ase:admin_and_site_enhancements_ase_pro:*:*:*:*:*:*:*:*
The Admin and Site Enhancements (ASE) Pro plugin for WordPress versions 8.8.5 and earlier contains an unauthenticated cross-site scripting vulnerability with a CVSS 3.1 score of 9.6. The exceptionally high severity rating indicates that this XSS flaw can be triggered without any authentication and likely carries significant impact potential beyond typical script injection, such as administrative account takeover. WordPress administrators using ASE Pro should update to a patched version immediately and review the Patchstack advisory for further details on affected configurations and remediation steps.
- π CVE-2026-57625 (CVSS 3.1: 9.6)
π [HIGH] microsoft/microsoft_365_copilot
1 CVE | CVSS 3.1: 9.3 | AAS 9.6
cpe:2.3:a:microsoft:microsoft_365_copilot:*:*:*:*:*:*:*:*
Microsoft 365 Copilot is affected by an open redirect vulnerability with a CVSS 3.1 score of 9.3 that can be exploited by an unauthorized attacker over the network to elevate privileges. The high severity rating suggests the redirect can be chained to achieve significant impact beyond simple phishing, potentially enabling credential theft or session hijacking within the M365 ecosystem. Organizations using Microsoft 365 Copilot should monitor the Microsoft Security Response Center advisory for mitigation guidance, as this is a cloud-hosted service where remediation is primarily vendor-applied.
- π CVE-2026-41106 (CVSS 3.1: 9.3)
π [HIGH] cockpit-project/cockpit
1 CVE | CVSS 4.0: 8.2 | AAS 9.5
cpe:2.3:a:cockpit-project:cockpit:*:*:*:*:*:*:*:*(< 364)
Cockpit CMS versions prior to release 364 contain a path traversal and local file inclusion vulnerability with a CVSS 4.0 score of 8.2, allowing unauthenticated attackers to read arbitrary files or execute PHP code by injecting dot-dot sequences into the URL. The flaw stems from unvalidated PATH_INFO being used directly in filesystem path construction, and when the resolved path ends in a .php extension, the application passes it to include(), enabling remote code execution. Administrators running Cockpit CMS should upgrade to release 364 or later immediately and review systems for any signs of unauthorized file access or compromise.
- π CVE-2026-58467 (CVSS 4.0: 8.2)
π [HIGH] apereo/cas
1 CVE | CVSS 4.0: 9.3 | AAS 9.4
cpe:2.3:a:apereo:cas:*:*:*:*:*:*:*:*(>= 7.3.0, < 8.0.0-RC6)
Apereo CAS versions 7.3.0 through 8.0.0-RC5 contain a cryptographic vulnerability with a CVSS 4.0 score of 9.3, caused by AES-GCM initialization vector reuse that allows unauthenticated remote attackers to recover plaintext webflow conversation state. By collecting client-side webflow execution tokens from the login page, an attacker can exploit keystream reuse from a fixed all-zero IV to decrypt sensitive session data through known-plaintext analysis. Organizations using Apereo CAS should upgrade to version 8.0.0-RC6 or later and consult the vendor advisory for additional mitigation details.
- π CVE-2026-59099 (CVSS 4.0: 9.3)
π [HIGH] lobehub/lobehub
1 CVE | CVSS 4.0: 8.3 | AAS 9.2
cpe:2.3:a:lobehub:lobehub:*:*:*:*:*:*:*:*
LobeChat versions prior to 2.2.10-canary.18 contain a server-side request forgery vulnerability with a CVSS 4.0 score of 8.3, where the skill import and topic cover update endpoints use unprotected fetch calls that bypass the project’s SSRF-safe wrapper. An authenticated attacker can exploit these endpoints to direct internal HTTP requests to arbitrary URLs, including cloud instance metadata services, potentially exposing sensitive credentials and infrastructure details. Organizations running self-hosted LobeChat instances should upgrade to version 2.2.10-canary.18 or later and review cloud metadata access logs for any signs of unauthorized internal requests.
- π CVE-2026-59095 (CVSS 4.0: 8.3)
π [HIGH] pathwaycom/pathway
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:pathwaycom:pathway:*:*:*:*:*:*:*:*(< 0.31.2)
Pathway versions through 0.31.1 contain a denial-of-service vulnerability with a CVSS 4.0 score of 8.7, where unauthenticated HTTP endpoints accept user-supplied glob patterns that are processed by a recursive matcher with exponential worst-case complexity. An attacker can submit crafted glob patterns with multiple wildcard tokens to the retrieve, inputs, or answer endpoints, causing excessive CPU consumption and rendering the service unresponsive. Organizations using Pathway should update to a version containing commit d09722e or later and consider implementing input validation or rate limiting on exposed API endpoints.
- π CVE-2026-59094 (CVSS 4.0: 8.7)
π [HIGH] weaviate/weaviate
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:weaviate:weaviate:*:*:*:*:*:*:*:*(< 1.38.0)
Weaviate versions prior to 1.38.0 contain a privilege escalation vulnerability with a CVSS 4.0 score of 8.7, where the RBAC role assignment endpoints fail to verify that the assigning principal holds the permissions contained in the role being granted. An authenticated user with role assignment privileges can assign roles with permissions exceeding their own, effectively escalating their access or granting unauthorized access to other users and groups. Organizations running Weaviate with RBAC enabled should upgrade to version 1.38.0 or later and audit existing role assignments for any unauthorized privilege grants.
- π CVE-2026-59093 (CVSS 4.0: 8.7)