22 vulnerabilities across 15 products scored HIGH or above on July 09, 2026.

  • 🟠 HIGH: 22

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-55500 (decolua/9router) β€” F1: theoretical β†’ poc, AAS: 9.1 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-07-06 bulletin.
  • [UPGRADED] CVE-2026-55952 (erlang/erlang_otp) β€” F1: theoretical β†’ poc, AAS: 9.2 β†’ 11.7 (HIGH β†’ HIGH). Originally in 2026-07-02 bulletin.

🟠 [HIGH] ruvnet/ruflo

1 CVE | CVSS 3.1: 10.0 | AAS 11.8

  • cpe:2.3:a:ruvnet:ruflo:*:*:*:*:*:*:*:* (< 3.16.3)

Ruflo, an agent meta-harness for Claude Code and Codex by ruvnet, is affected by one critical vulnerability (CVE-2026-59726, CVSS 10.0). The default docker-compose deployment exposes MCP bridge endpoints without authentication, allowing an unauthenticated network attacker to execute arbitrary commands in the bridge container, extract provider API keys, and tamper with AgentDB learning-store patterns. This vulnerability is considered exploitable.

Teams running ruflo in any networked environment should upgrade to version 3.16.3 immediately. Until patched, restrict network access to the MCP bridge endpoints and audit for unauthorized tool invocations or credential exposure. Refer to the vendor commit on GitHub for patch details.

Vendor Advisory


🟠 [HIGH] getkirby/kirby

3 CVEs | CVSS 4.0: 9.1 | AAS 11.8

  • cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*

Kirby CMS by getkirby is affected by three vulnerabilities, including at least one rated CVSS 9.1, which could allow a remote attacker to bypass local-IP checks by spoofing request headers such as Forwarded, X-Client-IP, or X-Real-IP when the CMS runs behind a reverse proxy with no configured user accounts. Successful exploitation could enable an unauthenticated attacker to install the Panel and create an admin account, effectively taking over the site.

Organizations running Kirby behind a reverse proxy should upgrade to version 4.9.4 or 5.4.4 immediately. As an interim measure, ensure at least one admin account is configured on all public-facing Kirby instances and review reverse proxy header handling. Refer to the vendor advisory on GitHub for full patch details and additional CVE information.

Vendor Advisory


🟠 [HIGH] metabase/metabase

2 CVEs | CVSS 3.1: 9.9 | AAS 11.2

  • cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* (< 1.58.15)
  • cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* (>= 1.59.0, < 1.59.12)
  • cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* (>= 1.60.0, < 1.60.6.3)
  • cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* (>= 1.61.0, < 1.61.1.4)

Metabase, an open-source business intelligence and embedded analytics platform, is affected by two vulnerabilities, including at least one rated CVSS 9.9 and considered exploitable. The lead issue allows an authenticated user with native query permissions on an H2 database connection, including the default sample database, to achieve remote code execution on the Metabase server through unsafe deserialization of Java objects in H2 query results.

Organizations running Metabase should upgrade immediately to version 1.58.15, 1.59.12, 1.60.6.3, or 1.61.1.4 depending on their release track. As an interim mitigation, restrict native query access and consider removing or disabling H2 database connections, particularly the default sample database. Refer to the vendor advisory on GitHub for full details on both vulnerabilities.

Vendor Advisory


🟠 [HIGH] creativethemeshq/blocksy_companion

1 CVE | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:creativethemeshq:blocksy_companion:*:*:*:*:*:*:*:* (< 2.1.47)

The Blocksy Companion plugin for WordPress by CreativeThemesHQ is affected by one critical vulnerability (CVE-2026-15158, CVSS 9.8) that is considered exploitable. A flaw in the Custom Fonts extension’s file type validation uses substring matching instead of proper extension checking, allowing an attacker to upload malicious files with double extensions such as shell.woff2.php and achieve remote code execution on the web server.

All WordPress site operators using Blocksy Companion version 2.1.46 or earlier should update immediately to a patched release. If an update is not yet available, disable the Custom Fonts extension as an interim mitigation and audit upload directories for suspicious files with double extensions. Refer to the vendor advisory for technical details.

Vendor Advisory


🟠 [HIGH] yeswiki/yeswiki

2 CVEs | CVSS 3.1: 9.5 | AAS 10.0

  • cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:* (< 4.4.5)

YesWiki, an open-source wiki platform, is affected by two vulnerabilities, including at least one rated CVSS 9.5 and considered exploitable. The lead issue is a missing authorization check in the EraseSpamedCommentsAction that allows any user with default write access to permanently delete arbitrary wiki pages by supplying crafted page tags, which on fresh installs means any unauthenticated visitor.

Organizations running YesWiki should apply patches as soon as they become available. As an immediate mitigation, restrict the default write ACL from the permissive wildcard setting to authenticated and trusted users only, and review access controls on all wiki actions. Refer to the vendor advisory on GitHub for full details on both vulnerabilities.

Vendor Advisory


🟠 [HIGH] nesquena/hermes-webui

2 CVEs | CVSS 4.0: 9.3 | AAS 9.9

  • cpe:2.3:a:nesquena:hermes-webui:*:*:*:*:*:*:*:* (< 0.51.788)

Hermes WebUI by nesquena is affected by two vulnerabilities, including at least one rated CVSS 9.3 and considered exploitable. The lead issue exposes embedded terminal API endpoints without any authentication, allowing a remote attacker to achieve full remote code execution as the server process user through a simple sequence of four unauthenticated HTTP requests that create a session, attach a PTY shell, and execute arbitrary commands.

Anyone running Hermes WebUI prior to version 0.51.788 should upgrade immediately. If an update cannot be applied right away, restrict network access to the application to trusted hosts only and ensure it is not exposed to the internet. Refer to the vendor commit on GitHub for patch details on both vulnerabilities.

Vendor Advisory


🟠 [HIGH] coollabsio/coolify

1 CVE | CVSS 3.1: 8.8 | AAS 9.6

  • cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:* (< 4.0.0-beta.469)

Coolify, an open-source self-hosted server and application management platform by coollabsio, is affected by one vulnerability (CVE-2026-59734, CVSS 8.8) that is considered exploitable. The health check configuration parameters including host, method, and path are directly interpolated into shell commands without sanitization, allowing any authenticated user to inject and execute arbitrary commands inside deployment containers.

Organizations running Coolify should upgrade to version 4.0.0-beta.469 or later immediately. As an interim measure, restrict access to health check configuration settings to trusted administrators only and audit existing health check parameters for suspicious input. Refer to the vendor commit on GitHub for patch details.

Vendor Advisory


🟠 [HIGH] mockoon/mockoon

1 CVE | CVSS 3.1: 8.8 | AAS 9.6

  • cpe:2.3:a:mockoon:mockoon:*:*:*:*:*:*:*:* (< 9.7.0)

Mockoon, an open-source mock API design and runtime tool, is affected by one vulnerability (CVE-2026-59148, CVSS 8.8) that is considered exploitable. The admin API is mounted on the same listener as user-defined mock routes with no authentication and a fully permissive CORS policy, allowing any unauthenticated caller who can reach the mock server port to read environment variables, write arbitrary process environment variables, and manipulate server configuration.

Teams running Mockoon in any networked environment should upgrade to version 9.7.0 or later immediately. Until patched, ensure mock server ports are not accessible from untrusted networks and consider firewall rules to restrict access to known development hosts only. Refer to the vendor commit on GitHub for full patch details.

Vendor Advisory


🟠 [HIGH] n8n/n8n

1 CVE | CVSS 4.0: 7.6 | AAS 9.4

  • cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* (< 2.27.4)

n8n, an open-source workflow automation platform, is affected by one vulnerability (CVE-2026-59208, CVSS 7.6) that is considered exploitable. Instances configured with multiple trusted token-exchange issuers resolve external identities using only the JWT sub claim while ignoring the iss claim, allowing an attacker who holds a valid token from one trusted issuer to authenticate as any user on another trusted issuer whose sub value matches.

Organizations running n8n with multiple trusted token-exchange issuers should upgrade to version 2.27.4 or 2.28.1 immediately. As an interim measure, reduce the number of configured trusted issuers to one or audit for overlapping sub values across issuers. Refer to the vendor release notes on GitHub for full patch details.

Vendor Advisory


🟠 [HIGH] vim/vim

2 CVEs | CVSS 4.0: 8.4 | AAS 9.3

  • cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* (< 9.2.0736)

Vim, the widely used open-source command line text editor, is affected by two vulnerabilities, including at least one rated CVSS 8.4 and considered exploitable. The lead issue involves the C omni-completion script failing to sanitize tag file fields before interpolating them into executed Vim commands, allowing a crafted tags file in a project directory to execute arbitrary Ex commands when a developer triggers omni-completion on a C source file.

Developers and system administrators should upgrade Vim to version 9.2.0735 or later immediately. As an interim precaution, avoid using omni-completion in untrusted project directories and review tags files from external sources before opening associated code. Refer to the vendor commit on GitHub for patch details on both vulnerabilities.

Vendor Advisory


🟠 [HIGH] pimcore/pimcore

1 CVE | CVSS 3.1: 8.8 | AAS 9.1

  • cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:* (< 2025.4.6)
  • cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:* (>= 2026.1.0, < 2026.1.6)

Pimcore, an open-source data and experience management platform, is affected by one vulnerability (CVE-2026-55207, CVSS 8.8) involving a flawed password reset mechanism. An unauthenticated attacker who knows a valid admin username can submit a password reset request with an attacker-controlled URL, causing the server to generate a legitimate recovery token and email a malicious link to the victim that, when clicked, sends the token to the attacker for full account takeover.

Organizations running Pimcore should upgrade to version 2025.4.6 or 2026.1.6 immediately. Administrators should also review recent password reset activity for suspicious requests and advise users not to click reset links they did not initiate. Refer to the vendor security advisory on GitHub for full details.

Vendor Advisory


🟠 [HIGH] python_software_foundation/cpython

1 CVE | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:python:cpython:*:*:*:*:*:*:*:* (< 3.10.18)
  • cpe:2.3:a:python:cpython:*:*:*:*:*:*:*:* (>= 3.11.0, < 3.11.13)
  • cpe:2.3:a:python:cpython:*:*:*:*:*:*:*:* (>= 3.12.0, < 3.12.10)
  • cpe:2.3:a:python:cpython:*:*:*:*:*:*:*:* (>= 3.13.0, < 3.13.4)
  • cpe:2.3:a:python:cpython:*:*:*:*:*:*:*:* (>= 3.14.0a1, < 3.14.0b2)

CPython, the reference implementation of the Python programming language, is affected by one vulnerability (CVE-2026-15308, CVSS 8.7) that is considered exploitable. The incremental HTML parser in html.parser.HTMLParser can be driven into excessive CPU consumption through repeated unterminated markup declarations, enabling a denial-of-service attack against any application that parses untrusted HTML input using this module.

Any team running Python applications that process user-supplied or untrusted HTML through HTMLParser should update to a patched CPython release as soon as one is available for their version branch. As an interim mitigation, consider imposing input size limits or timeouts on HTML parsing operations and evaluate alternative parsing libraries for untrusted content. Refer to the vendor commit on GitHub for patch details.

Vendor Advisory


🟠 [HIGH] zeek/zeek

1 CVE | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:zeek:zeek:*:*:*:*:*:*:*:* (< 8.0.9)

Zeek, a widely deployed open-source network security monitoring sensor, is affected by one vulnerability (CVE-2026-60109, CVSS 8.7) that is considered exploitable. A null pointer dereference in the Kerberos protocol analyzer allows an unauthenticated remote attacker to crash the sensor by sending a crafted KRB_ERROR message, effectively blinding network monitoring in environments that rely on Zeek for traffic analysis and intrusion detection.

Organizations running Zeek should upgrade to version 8.0.9 or later immediately, as a sensor crash could create a window of unmonitored network activity. If immediate patching is not possible, consider deploying redundant sensors to maintain visibility during an attack. Refer to the vendor commit on GitHub for full patch details.

Vendor Advisory


🟠 [HIGH] divi_engine/divi_form_builder

1 CVE | CVSS 3.1: 8.8 | AAS 9.1

  • cpe:2.3:a:divi_engine:divi_form_builder:*:*:*:*:*:*:*:*

The Divi Form Builder plugin for WordPress by Divi Engine is affected by one vulnerability (CVE-2026-5523, CVSS 8.8) that is considered exploitable. Missing authorization checks in the user update and registration handling functions allow any authenticated attacker, even with minimal privileges such as a subscriber role, to modify arbitrary user accounts by submitting crafted form data with a target user ID, potentially leading to privilege escalation and full site compromise.

WordPress site operators using Divi Form Builder version 5.1.8 or earlier should update to a patched release immediately. As an interim measure, restrict form submissions to trusted users and audit user account records for unauthorized modifications. Refer to the vendor changelog for patch details.

Vendor Advisory


🟠 [HIGH] open-webui/open-webui

2 CVEs | CVSS 3.1: 8.0 | AAS 9.1

  • cpe:2.3:a:open-webui:open-webui:*:*:*:*:*:*:*:*

Open WebUI, a self-hosted AI platform, is affected by two vulnerabilities, including at least one rated CVSS 8.0 and considered exploitable. The lead issue allows malicious stored chat payloads to execute client-side Python via Pyodide in a same-origin web worker, enabling authenticated same-origin requests to admin-only endpoints and server-side code execution through configured tools when a victim clicks Run on a shared chat.

Organizations running Open WebUI should upgrade to version 0.10.0 or later immediately. As an interim measure, advise users not to execute code blocks from untrusted or shared chat sessions and restrict access to admin-level tool configurations. Refer to the vendor security advisory on GitHub for full details on both vulnerabilities.

Vendor Advisory