20 vulnerabilities across 15 products scored HIGH or above on July 10, 2026.
- π HIGH: 20
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-54003 (getkirby/kirby) β F1: theoretical β poc, AAS: 11.8 β 13.5 (HIGH β CRITICAL). Originally in 2026-07-09 bulletin.
- [UPGRADED] CVE-2026-55207 (pimcore/pimcore) β F1: theoretical β poc, AAS: 9.1 β 11.6 (HIGH β HIGH). Originally in 2026-07-09 bulletin.
- [UPGRADED] CVE-2026-57480 (parse-community/parse-server) β F1: theoretical β poc, AAS: 9.8 β 12.3 (HIGH β CRITICAL). Originally in 2026-07-08 bulletin.
- [UPGRADED] CVE-2026-55500 (decolua/9router) β F1: theoretical β poc, AAS: 9.1 β 11.6 (HIGH β HIGH). Originally in 2026-07-06 bulletin.
π [HIGH] jetbrains/intellij_idea
1 CVE | CVSS 3.1: 9.8 | AAS 11.8
cpe:2.3:a:jetbrains:intellij_idea:*:*:*:*:*:*:*:*(< 2026.1.4)
JetBrains IntelliJ IDEA versions prior to 2026.1.4 and the 2026.2 branch are affected by a critical path traversal vulnerability (CVE-2026-59792, CVSS 9.8) in project workspace ID handling that enables code execution. This flaw is classified as exploitable, making it a high-priority remediation item for any development team running affected versions.
Organizations using IntelliJ IDEA should update to version 2026.1.4 or later immediately and review the vendor advisory at jetbrains.com for additional guidance.
- π CVE-2026-59792 (CVSS 3.1: 9.8)
π [HIGH] jetbrains/teamcity
3 CVEs | CVSS 3.1: 8.8 | AAS 11.7
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*(< 2026.1.2)
JetBrains TeamCity versions prior to 2026.1.2 are affected by three vulnerabilities, including at least one (CVSS 8.8) that allows arbitrary file access through the Perforce VCS integration. Proof-of-concept exploit code is available, elevating the risk of near-term exploitation against exposed CI/CD infrastructure.
Organizations running TeamCity should upgrade to version 2026.1.2 or later without delay and consult the vendor advisory at jetbrains.com for full details on all three issues.
- π CVE-2026-59793 (CVSS 3.1: 8.8)
- π CVE-2026-59795 (CVSS 3.1: 8.1)
- π CVE-2026-59796 (CVSS 3.1: 8.1)
π [HIGH] langroid/langroid
3 CVEs | CVSS 4.0: 10.0 | AAS 11.7
cpe:2.3:a:langroid:langroid:*:*:*:*:*:*:*:*
Langroid versions prior to 0.65.5 are affected by three vulnerabilities, including at least one rated CVSS 10.0, where the Neo4jChatAgent passes LLM-generated Cypher queries directly to the Neo4j driver without validation or allowlisting. Exploitation via prompt injection is straightforward, and proof-of-concept code is available, allowing an attacker to read, modify, or destroy all graph data and potentially escalate further through APOC or security procedures.
Teams using Langroid with Neo4j integrations should upgrade to version 0.65.5 or later immediately and review the fix commit linked in the vendor advisory for additional hardening guidance.
- π CVE-2026-55615 (CVSS 4.0: 9.2)
- π CVE-2026-54769 (CVSS 3.1: 10.0)
- π CVE-2026-54760 (CVSS 4.0: 9.3)
π [HIGH] decolua/9router
2 CVEs | CVSS 3.1: 9.9 | AAS 11.6
cpe:2.3:a:decolua:9router:*:*:*:*:*:*:*:*(< 0.5.2)
9Router by Decolua versions prior to 0.4.80 are affected by two vulnerabilities, including at least one rated CVSS 9.9, where the database settings endpoint permits unauthenticated full database export and import, exposing all stored credentials, API keys, and OAuth tokens while also allowing complete database overwrite. Proof-of-concept exploit code is available, making immediate action critical for any deployment with network-reachable API endpoints.
Organizations running 9Router should upgrade to version 0.4.80 or later immediately and rotate any credentials, API keys, or tokens that may have been stored in the application database.
- π CVE-2026-55500 (CVSS 3.1: 9.9)
- π CVE-2026-55638 (CVSS 3.1: 8.6)
π [HIGH] snipeitapp/snipe-it
1 CVE | CVSS 3.1: 7.7 | AAS 11.3
cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*(< 8.6.2)
Snipe-IT versions prior to 8.6.2 are affected by a mass assignment vulnerability (CVE-2026-54329, CVSS 7.7) in the Accessories API, where a low-privileged authenticated user can manipulate the company_id parameter to create accessory records under other companies when Full Multiple Companies Support is enabled. A functional exploit is available, making this a practical cross-tenant data integrity risk for multi-company deployments.
Organizations using Snipe-IT with multi-company support should upgrade to version 8.6.2 or later and audit accessory records for any unauthorized cross-company entries.
- π CVE-2026-54329 (CVSS 3.1: 7.7)
π [HIGH] vikunja/vikunja
1 CVE | CVSS 4.0: 9.3 | AAS 11.2
cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*(< 2.2.1)
Vikunja versions prior to 2.2.1 are affected by an authorization flaw (CVE-2026-56765, CVSS 9.3) that exposes share hashes to read-only users, enabling escalation to admin-level access, and a separate insecure direct object reference in the attachment endpoint that allows any authenticated user to download and delete file attachments across all projects instance-wide. Proof-of-concept exploit code is available, compounding the risk of both privilege escalation and widespread data loss.
Administrators running self-hosted Vikunja instances should upgrade to version 2.2.1 or later immediately and review the security advisory linked on GitHub for additional mitigation details.
- π CVE-2026-56765 (CVSS 4.0: 9.3)
π [HIGH] authorizerdev/authorizerdev/authorizer
1 CVE | CVSS 3.1: 9.3 | AAS 10.9
cpe:2.3:a:authorizerdev:authorizerdev_authorizer:*:*:*:*:*:*:*:*
Authorizer by authorizerdev is affected by an open redirect vulnerability (CVE-2026-54072, CVSS 9.3) where the /authorize endpoint accepts arbitrary redirect URIs without validation against AllowedOrigins, allowing an attacker to steal access tokens, ID tokens, and refresh tokens by redirecting authenticated users to a malicious URL. The attack requires no authentication, as the necessary client_id is publicly exposed via the GraphQL meta endpoint, and the flaw is classified as exploitable.
Organizations using Authorizer should review the advisory at GitHub for available patches and, if no full fix is available, restrict network access to the /authorize endpoint and monitor for suspicious redirect activity.
- π CVE-2026-54072 (CVSS 3.1: 9.3)
π [HIGH] rabbitmq/rabbitmq-server
1 CVE | CVSS 4.0: 8.7 | AAS 10.9
cpe:2.3:a:rabbitmq:rabbitmq-server:*:*:*:*:*:*:*:*(< 3.13.15)cpe:2.3:a:rabbitmq:rabbitmq-server:*:*:*:*:*:*:*:*(>= 4.0.0, < 4.0.20)cpe:2.3:a:rabbitmq:rabbitmq-server:*:*:*:*:*:*:*:*(>= 4.1.0, < 4.1.11)cpe:2.3:a:rabbitmq:rabbitmq-server:*:*:*:*:*:*:*:*(>= 4.2.0, < 4.2.6)
RabbitMQ Server versions prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6 are affected by a credential disclosure vulnerability (CVE-2026-57219, CVSS 8.7) where the obsolete GET /api/auth endpoint exposes the OAuth 2 client secret to unauthenticated callers when the management plugin is enabled with oauth_client_secret configured. Any organization running RabbitMQ with OAuth 2 integration for management access should treat this as a high-priority issue, as leaked client secrets could enable unauthorized access to the broker.
Upgrade to version 3.13.15, 4.0.20, 4.1.11, or 4.2.6 depending on your release branch, and rotate any OAuth 2 client secrets that may have been exposed.
- π CVE-2026-57219 (CVSS 4.0: 8.7)
π [HIGH] renstillmann/super_forms_βdrag&_drop_form_builder
1 CVE | CVSS 3.1: 9.8 | AAS 10.6
cpe:2.3:a:renstillmann:super_forms_drag_drop_form_builder:*:*:*:*:*:*:*:*
The Super Forms β Drag & Drop Form Builder plugin for WordPress versions up to and including 6.3.313 is affected by a critical arbitrary file upload vulnerability (CVE-2026-14894, CVSS 9.8) where unauthenticated attackers can upload malicious files through the submit_form AJAX handler due to missing file type validation and no capability checks, with the session nonce freely obtainable via a public endpoint. This flaw is classified as exploitable and poses an immediate risk of full site compromise through webshell upload on any WordPress site running the affected plugin.
Site administrators should update Super Forms to the latest patched version immediately, audit their uploads directories for suspicious files, and consider temporarily deactivating the plugin if an update cannot be applied right away.
- π CVE-2026-14894 (CVSS 3.1: 9.8)
π [HIGH] prowler-cloud/prowler
1 CVE | CVSS 3.1: 9.6 | AAS 10.4
cpe:2.3:a:prowler-cloud:prowler:*:*:*:*:*:*:*:*(< 5.30.3)
Prowler cloud security platform versions prior to 5.30.3 are affected by a critical SAML authentication bypass vulnerability (CVE-2026-59151, CVSS 9.6) where the ACS finish logic derives tenant membership from the asserted email domain rather than binding token issuance to the validated SAML configuration, allowing an attacker with a controlled SAML IdP to escalate into arbitrary tenants. This flaw is classified as exploitable and represents a direct cross-tenant compromise risk for any multi-tenant Prowler deployment using SAML authentication.
Organizations running Prowler with SAML-based SSO should upgrade to version 5.30.3 or later immediately, review tenant access logs for anomalous cross-tenant activity, and verify that SAML IdP configurations are tightly scoped.
- π CVE-2026-59151 (CVSS 3.1: 9.6)
π [HIGH] flux159/mcp-server-kubernetes
1 CVE | CVSS 4.0: 9.3 | AAS 10.4
cpe:2.3:a:flux159:mcp-server-kubernetes:*:*:*:*:*:*:*:*(< 3.9.0)
MCP Server Kubernetes versions prior to 3.9.0 are affected by an argument injection vulnerability (CVE-2026-61459, CVSS 9.3) where attackers can bypass the security flag check in kubectl tools by supplying parameters with leading dashes, enabling injection of the –server flag to redirect kubectl commands to an attacker-controlled API server and exfiltrate the operator’s bearer token for full cluster compromise. This flaw is classified as exploitable and poses a critical risk to any Kubernetes environment managed through the MCP server integration.
Teams using MCP Server Kubernetes should upgrade to version 3.9.0 or later immediately, rotate any Kubernetes service account tokens that may have been exposed, and audit cluster access logs for unexpected API server connections.
- π CVE-2026-61459 (CVSS 4.0: 9.3)
π [HIGH] tilt-dev/tilt
1 CVE | CVSS 4.0: 9.2 | AAS 10.3
cpe:2.3:a:tilt-dev:tilt:*:*:*:*:*:*:*:*
Tilt versions 0.20.8 through 0.37.3 are affected by a missing authentication vulnerability (CVE-2026-55884, CVSS 9.2) where the HUD HTTP server exposes unauthenticated endpoints that allow network attackers to trigger developer-defined resources, tamper with Tiltfile arguments, read full engine state including session tokens, and proxy authenticated requests to the Kubernetes API server. This flaw is classified as exploitable and is particularly dangerous when the HUD is bound to a non-loopback address, enabling remote compromise of both the development environment and connected Kubernetes clusters.
Development teams using Tilt should upgrade to a patched version immediately, ensure the HUD is bound only to localhost, and rotate any Kubernetes credentials accessible through the Tilt session.
- π CVE-2026-55884 (CVSS 4.0: 9.2)
π [HIGH] openreplay/openreplay
1 CVE | CVSS 3.1: 9.3 | AAS 10.3
cpe:2.3:a:openreplay:openreplay:*:*:*:*:*:*:*:*(>= 1.24.0, < 1.25.0)
OpenReplay versions 1.24.0 through before 1.25.0 are affected by a stored cross-site scripting vulnerability (CVE-2026-55879, CVSS 9.3) where unauthenticated attackers can inject malicious script through custom event names and page URLs submitted via the public tracking SDK, which are stored in ClickHouse without output encoding and rendered unsanitized in the authenticated dashboard, enabling session JWT theft and full account takeover. This flaw is classified as exploitable and is particularly severe because it requires no authentication to exploit yet compromises authenticated dashboard users.
Organizations running self-hosted OpenReplay should upgrade to version 1.25.0 or later immediately, review ClickHouse event data for suspicious payloads, and invalidate active dashboard sessions.
- π CVE-2026-55879 (CVSS 3.1: 9.3)
π [HIGH] getgrav/grav
1 CVE | CVSS 4.0: 9.2 | AAS 10.2
cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*(< 1.2.0)
The Grav CMS database plugin (grav-plugin-database) versions prior to 1.2.0 are affected by a SQL injection vulnerability (CVE-2026-58492, CVSS 9.2) where the PDO::tableExists method interpolates table name arguments directly into raw SQL queries without any sanitization, escaping, or whitelisting, enabling arbitrary SQL execution against the configured database. This flaw is classified as exploitable and impacts any Grav site using the database plugin where attacker-controlled input can reach table name parameters through consuming plugins or custom code.
Site administrators using Grav with the database plugin should update to version 1.2.0 or later immediately and audit any custom or third-party plugins that pass user input to database plugin methods.
- π CVE-2026-58492 (CVSS 4.0: 9.2)
π [HIGH] rustdesk/rustdesk
1 CVE | CVSS 4.0: 8.7 | AAS 10.1
cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:*:*:*:*(< 1.4.9)
RustDesk versions prior to 1.4.9 are affected by a session scope enforcement vulnerability (CVE-2026-57850, CVSS 8.7) where the server fails to validate a peer’s authorized connection type, allowing an authenticated remote peer granted a limited session such as FileTransfer or PortForward to inject control messages reserved for full Remote sessions, effectively escalating to complete host observation and control. This flaw is classified as exploitable and is a significant concern for any organization relying on RustDesk’s session type restrictions to limit remote access permissions.
Organizations using RustDesk should upgrade to version 1.4.9 or later immediately and review remote access logs for any sessions where limited-scope peers may have performed actions outside their granted permissions.
- π CVE-2026-57850 (CVSS 4.0: 8.7)