30 vulnerabilities across 15 products scored HIGH or above on July 07, 2026.

  • πŸ”΄ CRITICAL: 3
  • 🟠 HIGH: 27

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-55952 (erlang/erlang_otp) β€” F1: theoretical β†’ poc, AAS: 9.2 β†’ 11.7 (HIGH β†’ HIGH). Originally in 2026-07-02 bulletin.
  • [UPGRADED] CVE-2026-13603 (pretix/pretix-oppwa) β€” F1: exploitable β†’ itw, AAS: 9.4 β†’ 11.9 (HIGH β†’ HIGH). Originally in 2026-07-01 bulletin.

πŸ”΄ [CRITICAL] better-auth/better-auth

2 CVEs | CVSS 3.1: 9.1 | AAS 12.7

  • cpe:2.3:a:better-auth:better-auth:*:*:*:*:*:*:*:* (< 1.6.11)

Better-auth, an open-source authentication framework, is affected by two critical vulnerabilities including at least one with a CVSS score of 9.1. Applications that use the OIDC provider or MCP plugins with confidential OAuth clients registered are exposed to authentication bypass conditions that could allow attackers to compromise OAuth flows. Proof-of-concept exploit code is available, increasing the urgency for exploitation in the wild.

Security teams running better-auth with OIDC provider or MCP plugin configurations should review the vendor advisory at the link above immediately and upgrade to the latest patched release. Given the critical severity and public exploit availability, this should be treated as a high-priority remediation item.

Vendor Advisory


πŸ”΄ [CRITICAL] coollabsio/coolify

12 CVEs | CVSS 3.1: 9.9 | AAS 12.6

  • cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:*

Coolify, an open-source self-hosted server and application management platform, is affected by twelve vulnerabilities including multiple critical-severity issues with a maximum CVSS score of 9.9. The flaws include cross-tenant authorization bypasses that allow authenticated users to clone resources into destinations owned by other teams, along with additional security defects that could compromise multi-tenant isolation. Proof-of-concept exploit code is publicly available for at least one of these issues.

Organizations running Coolify should upgrade to version 4.0.0-beta.464 or later immediately. Given the volume of vulnerabilities, the critical severity, and the risk of cross-tenant data exposure, this should be prioritized as an urgent remediation, particularly in shared or multi-team deployments.

Vendor Advisory


πŸ”΄ [CRITICAL] esri/portal_for_arcgis

1 CVE | CVSS 3.1: 9.8 | AAS 12.4

  • cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux, and Kubernetes contains a critical missing authentication vulnerability with a CVSS score of 9.8. The flaw allows a remote, unauthenticated attacker to access an unprotected API exposing critical functionality, and proof-of-concept exploit code is publicly available.

Organizations running Portal for ArcGIS should consult the Esri June 2026 security bulletin linked above and apply the recommended patches or upgrade immediately. Internet-facing deployments should be treated as highest priority given the unauthenticated remote attack vector.

Vendor Advisory


🟠 [HIGH] decolua/9router

1 CVE | CVSS 4.0: 9.2 | AAS 11.7

  • cpe:2.3:a:decolua:9router:*:*:*:*:*:*:*:* (< 0.4.44)

9Router, an open-source routing management tool by Decolua, versions prior to 0.4.44 contain a high-severity OS command injection vulnerability with a CVSS 4.0 score of 9.2. The unauthenticated POST endpoint for Tailscale installation lacks any authorization check, allowing a remote attacker to inject arbitrary OS commands that execute with root privileges via the sudoPassword field. Proof-of-concept exploit code is publicly available.

Anyone running 9Router should upgrade to version 0.4.44 or later immediately. Since this flaw requires no authentication and provides root-level command execution, any internet-exposed instance should be considered actively at risk until patched.

Vendor Advisory


🟠 [HIGH] open-webui/open-webui

1 CVE | CVSS 3.1: 8.0 | AAS 11.3

  • cpe:2.3:a:open-webui:open-webui:*:*:*:*:*:*:*:*

Open WebUI, a popular self-hosted web interface for large language models, contains a high-severity stored cross-site scripting vulnerability with a CVSS score of 8.0. Specially crafted HTML tags in chat messages allow an attacker to inject persistent JavaScript that executes every time a victim opens the affected chat transcript, enabling theft of access tokens and full account takeover. The risk is amplified when chat sharing is enabled, as malicious transcripts can be distributed to other users on the same server or across the Open WebUI community.

Administrators running Open WebUI should review the vendor advisory and upgrade to the latest patched version as soon as possible. Proof-of-concept exploit code is publicly available, making prompt remediation essential.

Vendor Advisory


🟠 [HIGH] mem0ai/mem0

2 CVEs | CVSS 4.0: 9.3 | AAS 10.7

  • cpe:2.3:a:mem0ai:mem0:*:*:*:*:*:*:*:*

Mem0, an AI memory management platform by mem0ai, is affected by two high-severity vulnerabilities with a maximum CVSS 4.0 score of 9.3. The flaws stem from missing authentication middleware on API endpoints, allowing unauthenticated attackers to read, write, and delete arbitrary user memories, expose private content by supplying arbitrary user IDs, and trigger a global denial-of-service by invoking pause endpoints across all users. These vulnerabilities are considered actively exploitable.

Organizations using Mem0’s OpenMemory API component should review the vendor repository for patches immediately and restrict network access to exposed API endpoints until a fix is applied. Given the unauthenticated nature of these attacks and the sensitivity of stored memory data, any internet-facing deployment should be treated as compromised until verified otherwise.

Vendor Advisory


🟠 [HIGH] topoteretes/cognee

1 CVE | CVSS 4.0: 9.3 | AAS 10.2

  • cpe:2.3:a:topoteretes:cognee:*:*:*:*:*:*:*:*

Cognee, an open-source AI knowledge management framework by Topoteretes, versions prior to 1.2.0 contain a high-severity improper access control vulnerability with a CVSS 4.0 score of 9.3. An unauthenticated attacker can self-register an account and overwrite the global LLM provider configuration without any admin authorization check, redirecting all instance-wide LLM operations to an attacker-controlled endpoint and enabling exfiltration of prompts, uploaded documents, and extracted entities. This vulnerability is considered actively exploitable.

Organizations running Cognee should upgrade to version 1.2.0 or later immediately by referencing the linked commit. Any internet-exposed instance should be assumed compromised until the patch is verified in place, as the attack requires no privileged access and silently redirects all AI processing traffic.

Vendor Advisory


🟠 [HIGH] zhenorzz/zhenorzz/goploy

1 CVE | CVSS 3.1: 9.6 | AAS 9.9

  • cpe:2.3:a:zhenorzz:zhenorzz_goploy:*:*:*:*:*:*:*:*

Goploy, an open-source deployment platform by zhenorzz, contains a high-severity insecure direct object reference vulnerability with a CVSS score of 9.6. The project file management API endpoints fail to verify that a project belongs to the caller’s namespace, allowing any authenticated user with manager-level permissions to add, edit, and remove files in projects owned by other namespaces by simply manipulating the project or file row ID in the request body. This vulnerability is considered actively exploitable.

Organizations using Goploy should review the vendor advisory and upgrade to the latest patched version immediately. In multi-tenant or multi-team deployments, this flaw effectively breaks all namespace isolation, so restricting access to the application until patched is strongly recommended.

Vendor Advisory


🟠 [HIGH] labring/fastgpt

1 CVE | CVSS 3.1: 8.6 | AAS 9.9

  • cpe:2.3:a:labring:fastgpt:*:*:*:*:*:*:*:*

FastGPT, an open-source AI knowledge base platform by Labring, versions prior to v4.15.0-beta5 contain a high-severity authorization bypass vulnerability with a CVSS score of 8.6. The file handling endpoints authorize an unrelated resource but then sign or read S3 objects using a key taken directly from the request without verifying it belongs to the caller’s team, allowing an authenticated attacker to supply another tenant’s key and access their private file contents through the chat-file presign or dataset endpoints. This vulnerability is considered actively exploitable.

Organizations running FastGPT should upgrade to version 4.15.0-beta5 or later immediately by referencing the linked commit. Multi-tenant deployments are particularly at risk, as the flaw completely bypasses cross-team data isolation for stored files and datasets.

Vendor Advisory


🟠 [HIGH] kovidgoyal/calibre

1 CVE | CVSS 4.0: 8.5 | AAS 9.4

  • cpe:2.3:a:kovidgoyal:calibre:*:*:*:*:*:*:*:*

Calibre, the widely used open-source e-book management application, versions prior to 9.10.0 contain a high-severity arbitrary code execution vulnerability with a CVSS 4.0 score of 8.5. A malicious EPUB, OPF, or PDF file can execute arbitrary Python code simply by having its metadata read through common operations like Add Books or Edit Books, by embedding a crafted custom column definition that is passed unsanitized to exec() in the template formatter. This vulnerability is considered actively exploitable and requires no special interaction beyond opening a malicious file.

All Calibre users should upgrade to version 9.10.0 or later immediately. Until patched, users should avoid importing e-books or metadata from untrusted sources, as merely adding a file to the library is sufficient to trigger code execution.

Vendor Advisory


🟠 [HIGH] koodo-reader/koodo-reader

1 CVE | CVSS 4.0: 8.4 | AAS 9.3

  • cpe:2.3:a:koodo-reader:koodo-reader:*:*:*:*:*:*:*:*

Koodo Reader, an open-source e-book reader application, version 2.3.0 and earlier contains a high-severity remote code execution vulnerability with a CVSS 4.0 score of 8.4. A malicious EPUB file can exploit the combination of enabled Node.js integration in subframes and unsanitized innerHTML rendering to spawn a hidden iframe with full Node.js API access, executing arbitrary operating system commands with the victim’s privileges simply by opening the crafted book. This vulnerability is considered actively exploitable.

Users of Koodo Reader should check the vendor advisory for a patched release and upgrade immediately. Until a fix is applied, users should avoid importing or opening EPUB files from untrusted sources, as merely opening a malicious book is sufficient to compromise the system.

Vendor Advisory


🟠 [HIGH] microrealestate/microrealestate

1 CVE | CVSS 4.0: 8.8 | AAS 9.2

  • cpe:2.3:a:microrealestate:microrealestate:*:*:*:*:*:*:*:*

MicroRealEstate, an open-source property management platform, versions through 1.0.0-alpha3 contain a high-severity authentication bypass vulnerability with a CVSS 4.0 score of 8.8. The lack of token state management allows attackers to brute-force one-time passwords and log in as any user on the platform, completely undermining the authentication mechanism. This vulnerability is considered actively exploitable.

Organizations running MicroRealEstate should check the vendor repository for a patched release and upgrade immediately. Any internet-facing deployment should be considered at high risk of unauthorized access until the fix is confirmed in place, and administrators should review access logs for signs of OTP brute-force activity.

Vendor Advisory


🟠 [HIGH] dataease/dataease

2 CVEs | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

DataEase, an open-source data visualization and analysis tool, is affected by two high-severity vulnerabilities with a maximum CVSS 4.0 score of 8.7. The flaws include an authentication bypass in the share proxy interface that generates and returns valid link tokens before validating share passwords or tickets, allowing unauthenticated attackers who know a protected share UUID to obtain access tokens and make subsequent API calls without valid credentials. These vulnerabilities are considered actively exploitable.

Organizations running DataEase should upgrade to version 2.10.24 or later immediately. Any deployment using password-protected sharing features is particularly at risk, as the authentication check is effectively bypassed, exposing shared data and dashboards to unauthorized access.

Vendor Advisory


🟠 [HIGH] vtiger/vtiger_crm

2 CVEs | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*

Vtiger CRM versions prior to 8.4.0 are affected by two high-severity vulnerabilities with a maximum CVSS 4.0 score of 8.7, including at least one authenticated remote code execution flaw. A low-privileged user can upload a malicious .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist which omits the .phar extension, with the file stored web-accessible and executable due to a misconfigured .htaccess that is silently ignored on modern Apache versions. Proof-of-concept exploit code is publicly available.

Organizations running Vtiger CRM should upgrade to version 8.4.0 or later immediately. Until patched, administrators should consider adding .phar to the extension denylist in config.inc.php and verifying that .htaccess restrictions are functioning correctly on their Apache version.

Vendor Advisory


🟠 [HIGH] ghostfolio/ghostfolio

1 CVE | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:ghostfolio:ghostfolio:*:*:*:*:*:*:*:*

Ghostfolio, an open-source wealth management and portfolio tracking application, contains a high-severity access control vulnerability with a CVSS 4.0 score of 8.7. The public portfolio API endpoint fails to validate grantee user filtering on private access IDs, allowing unauthenticated attackers who possess a private access ID to retrieve full portfolio data including holdings, quantities, buy prices, and performance metrics without any authentication. This vulnerability is considered actively exploitable.

Organizations and individuals running Ghostfolio should check the vendor repository for a patched release and upgrade immediately. Until a fix is applied, users should consider disabling or revoking any private access IDs to prevent unauthorized exposure of sensitive financial data.

Vendor Advisory