148 vulnerabilities across 15 products scored HIGH or above on July 14, 2026.

  • πŸ”΄ CRITICAL: 6
  • 🟠 HIGH: 142

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-57219 (rabbitmq/rabbitmq_server) β€” F1: theoretical β†’ itw, AAS: 10.9 β†’ 13.7 (HIGH β†’ CRITICAL). Originally in 2026-07-10 bulletin.
  • [UPGRADED] CVE-2026-55884 (tilt-dev/tilt) β€” F1: exploitable β†’ itw, AAS: 10.3 β†’ 13.0 (HIGH β†’ CRITICAL). Originally in 2026-07-10 bulletin.
  • [UPGRADED] CVE-2026-55879 (openreplay/openreplay) β€” F1: exploitable β†’ itw, AAS: 10.3 β†’ 13.3 (HIGH β†’ CRITICAL). Originally in 2026-07-10 bulletin.
  • [UPGRADED] CVE-2026-54003 (getkirby/kirby) β€” F1: theoretical β†’ poc, AAS: 11.8 β†’ 11.5 (HIGH β†’ HIGH). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-59827 (metabase/metabase) β€” F1: exploitable β†’ itw, AAS: 11.2 β†’ 13.1 (HIGH β†’ CRITICAL). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-59148 (mockoon/mockoon) β€” F1: exploitable β†’ itw, AAS: 9.6 β†’ 12.6 (HIGH β†’ CRITICAL). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-59858 (vim/vim) β€” F1: exploitable β†’ itw, AAS: 9.3 β†’ 12.3 (HIGH β†’ CRITICAL). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-55207 (pimcore/pimcore) β€” F1: theoretical β†’ poc, AAS: 9.1 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-57480 (parse-community/parse-server) β€” F1: theoretical β†’ poc, AAS: 9.8 β†’ 12.3 (HIGH β†’ CRITICAL). Originally in 2026-07-08 bulletin.
  • [UPGRADED] CVE-2026-59705 (mem0ai/mem0) β€” F1: exploitable β†’ itw, AAS: 10.7 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-07-07 bulletin.
  • [UPGRADED] CVE-2026-53511 (kovidgoyal/calibre) β€” F1: exploitable β†’ itw, AAS: 9.4 β†’ 12.4 (HIGH β†’ CRITICAL). Originally in 2026-07-07 bulletin.

πŸ”΄ [CRITICAL] adobe/coldfusion

1 CVE | CVSS 3.1: 10.0 | AAS 14.3

  • cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*
  • cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*
  • cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*
  • cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*
  • cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*

Adobe ColdFusion is affected by a critical authorization bypass vulnerability (CVE-2026-48321, CVSS 10.0) that allows attackers to escalate privileges and gain unauthorized read and write access without any user interaction. All organizations running ColdFusion in production should treat this as an immediate priority, as the flaw is considered exploitable and carries the highest possible severity rating with a changed scope, meaning compromise can extend beyond the vulnerable component itself. Administrators should review Adobe’s advisory (APSB26-82) and apply the available patches without delay.

Vendor Advisory


πŸ”΄ [CRITICAL] vitest-dev/vitest

2 CVEs | CVSS 3.1: 9.8 | AAS 14.3

  • cpe:2.3:a:vitest-dev:vitest:*:*:*:*:*:*:*:*

Vitest, the Vite-powered JavaScript testing framework, is affected by 2 critical vulnerabilities (CVSS 9.8) including at least one path traversal flaw on Windows that allows attackers to read arbitrary files outside the project directory and potentially achieve arbitrary script execution through exposed API write and rerun features. Development teams using Vitest with the UI or API server enabled, particularly on Windows, should assess their exposure immediately, as proof-of-concept exploit code is available. Upgrade to Vitest 3.2.5 or 4.1.0 to remediate both issues.

Vendor Advisory


πŸ”΄ [CRITICAL] adobe/commerce

6 CVEs | CVSS 3.1: 10.0 | AAS 13.5

  • cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*
  • cpe:2.3:a:adobe:commerce:2.4.4:p1:*:*:*:*:*:*
  • cpe:2.3:a:adobe:commerce:2.4.4:p10:*:*:*:*:*:*
  • cpe:2.3:a:adobe:commerce:2.4.4:p11:*:*:*:*:*:*
  • cpe:2.3:a:adobe:commerce:2.4.4:p12:*:*:*:*:*:*

Adobe Commerce (Magento) is affected by 6 vulnerabilities, including multiple critical-severity flaws up to CVSS 10.0, with at least one unrestricted file upload issue that enables arbitrary code execution and could allow attackers to gain elevated access or full control over user sessions. These vulnerabilities are considered exploitable, making any organization running Adobe Commerce storefronts an immediate target. Administrators should review Adobe’s advisory (APSB26-73) and apply all available patches as a matter of urgency.

Vendor Advisory


πŸ”΄ [CRITICAL] adobe/coldfusion_2025

1 CVE | CVSS 3.1: 9.3 | AAS 12.4

  • cpe:2.3:a:adobe:coldfusion_2025:*:*:*:*:*:*:*:*

Adobe ColdFusion 2025 is affected by a critical missing authentication vulnerability (CVE-2026-48325, CVSS 9.3) that allows unauthenticated attackers to achieve arbitrary code execution without any user interaction, with a changed scope indicating potential impact beyond the vulnerable component. Any organization running ColdFusion 2025 should treat this as a top-priority issue given the lack of authentication requirements and the exploitable nature of the flaw. Review Adobe’s advisory (APSB26-82) and apply the available patch immediately.

Vendor Advisory


πŸ”΄ [CRITICAL] microsoft/windows

121 CVEs | CVSS 3.1: 9.9 | AAS 12.1

  • cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* (< 10.0.14393.9339)
  • cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* (< 10.0.14393.9339)
  • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* (< 10.0.17763.9020)
  • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* (< 10.0.17763.9020)
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

Microsoft Windows is affected by 121 vulnerabilities this cycle, including multiple critical-severity flaws up to CVSS 9.9, with at least one confirmed exploited in the wild involving a privilege escalation in Active Directory Federation Services (AD FS). The breadth of this patch set spans core Windows components, making it relevant to virtually every organization running Windows infrastructure. Security teams should prioritize this month’s Patch Tuesday updates immediately, focusing first on the actively exploited issues and any internet-facing services.

Vendor Advisory


πŸ”΄ [CRITICAL] jetbrains/youtrack

1 CVE | CVSS 3.1: 10.0 | AAS 12.1

  • cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:*

JetBrains YouTrack is affected by a critical authentication bypass vulnerability (CVE-2026-62422, CVSS 10.0) that allows attackers to gain full administrative access through direct database access, requiring no prior authentication. Any organization running YouTrack for project or issue tracking should treat this as an urgent priority given the maximum severity rating and the exploitable nature of the flaw. Upgrade immediately to YouTrack 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, or 2024.2.148429 depending on your release branch, and review JetBrains’ advisory for further details.

Vendor Advisory


🟠 [HIGH] pi-hole/pi-hole

1 CVE | CVSS 3.1: 8.8 | AAS 11.6

  • cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*

Pi-hole versions 6.0 through 6.4.2 are affected by a local privilege escalation vulnerability (CVE-2026-50130, CVSS 8.8) that allows an attacker with code execution as the unprivileged pihole user to escalate to root by replacing the logrotate configuration file, which is subsequently executed with root privileges via a daily cron job. Organizations and home users relying on Pi-hole for network-wide DNS filtering should take note, as proof-of-concept exploit code is publicly available. Upgrade to Pi-hole 6.4.3 to remediate this issue.

Vendor Advisory


🟠 [HIGH] apache/tomcat

2 CVEs | CVSS 3.1: 9.1 | AAS 11.5

  • cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* (>= 7.0.100, <= 7.0.109)
  • cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* (>= 8.5.38, <= 8.5.100)
  • cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* (>= 9.0.13, <= 9.0.119)
  • cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* (>= 10.1.0, <= 10.1.56)
  • cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* (>= 11.0.0, <= 11.0.23)

Apache Tomcat is affected by 2 high-severity vulnerabilities (up to CVSS 9.1), including at least one related to insufficient documentation of secure configuration requirements for the EncryptInterceptor, potentially leaving clustered Tomcat deployments exposed. Affected versions span a wide range across multiple branches: 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.13 through 9.0.119, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109. Organizations running Tomcat in clustered configurations should upgrade to versions 11.0.24, 10.1.57, or 9.0.120 and review the advisory to ensure EncryptInterceptor settings are properly secured.

Vendor Advisory


🟠 [HIGH] apache/kylin

2 CVEs | CVSS 3.1: 9.8 | AAS 11.4

  • cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:* (>= 4.0.0, < 5.0.4)

Apache Kylin versions 4 through 5.0.3 are affected by 2 critical vulnerabilities (up to CVSS 9.8), including at least one SQL injection flaw in a backend API used for refreshing table catalogs, which could allow attackers to inject malicious SQL into generated queries. Organizations using Kylin for OLAP analytics should act promptly, as these vulnerabilities are considered exploitable. Upgrade to Apache Kylin 5.0.4 to remediate both issues.

Vendor Advisory


🟠 [HIGH] google/chrome

5 CVEs | CVSS 3.1: 9.6 | AAS 11.4

  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* (< 150.0.7871.125)

Google Chrome is affected by 5 high-severity vulnerabilities (up to CVSS 9.6), including multiple use-after-free flaws, at least one of which can enable a sandbox escape on Windows via a crafted HTML page. These issues are exploitable through standard web browsing, making every organization with Chrome-based browsers or Chromium-derived products a potential target. Update Chrome to version 150.0.7871.125 or later immediately across all endpoints.

Vendor Advisory


🟠 [HIGH] apache/doris

1 CVE | CVSS 3.1: 9.1 | AAS 10.5

  • cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:* (< 3.1.0)

Apache Doris versions prior to 3.1.0 are affected by a critical missing authentication vulnerability (CVE-2026-58319, CVSS 9.1) that allows unauthenticated attackers with network access to the Frontend HTTP service to perform unauthorized administrative operations, potentially compromising cluster integrity and availability. Any organization running Apache Doris for real-time analytics should assess exposure immediately, particularly if the FE HTTP interface is reachable from untrusted networks. Upgrade to Apache Doris 3.1.0 or later to remediate this issue.

Vendor Advisory


🟠 [HIGH] argoproj/argo-helm

1 CVE | CVSS 3.1: 8.9 | AAS 10.3

  • cpe:2.3:a:argoproj:argo-helm:*:*:*:*:*:*:*:*

Argo CD, including deployments via argo-helm and Red Hat OpenShift GitOps, is affected by a high-severity vulnerability (CVE-2026-15416, CVSS 8.9) that allows unauthenticated attackers with network access to the repo-server to achieve remote code execution and potentially manipulate cached data to deploy malicious Kubernetes resources, leading to complete cluster compromise. Any organization using Argo CD for GitOps-driven Kubernetes management should treat this as a critical priority given the exploitable nature of the flaw and the potential for downstream cluster takeover. Review the Red Hat advisory and apply available patches or mitigations immediately, and restrict network access to the repo-server component.

Vendor Advisory


🟠 [HIGH] microsoft/visual_studio_code

2 CVEs | CVSS 3.1: 8.8 | AAS 10.2

  • cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*

Microsoft Visual Studio Code is affected by 2 high-severity vulnerabilities (up to CVSS 8.8), including at least one flaw involving inclusion of functionality from an untrusted control sphere that could allow an unauthorized attacker to bypass security features over a network. Development teams and organizations with VS Code deployed across their workforce should take note, as these issues could be leveraged through malicious extensions or crafted project files. Update Visual Studio Code to the latest version and review Microsoft’s advisory for full details.

Vendor Advisory


🟠 [HIGH] microsoft/microsoft_sharepoint_enterprise_server_2016

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* (< 16.0.19725.20434)

Microsoft SharePoint Enterprise Server 2016 is affected by a critical deserialization vulnerability (CVE-2026-50522, CVSS 9.8) that allows an unauthorized attacker to execute arbitrary code over the network without any authentication or user interaction. Organizations still running SharePoint 2016 should treat this as an urgent priority, as the flaw is considered exploitable and provides a direct path to remote code execution on a high-value collaboration platform. Apply the latest security update from Microsoft immediately and review the advisory for any additional mitigation guidance.

Vendor Advisory


🟠 [HIGH] microsoft/sharepoint_server

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* (< 16.0.19725.20434)

Microsoft SharePoint Server is affected by a critical deserialization vulnerability (CVE-2026-58644, CVSS 9.8) that enables an unauthorized attacker to achieve remote code execution over the network with no authentication or user interaction required. Any organization running SharePoint Server should treat this as an immediate priority given the exploitable status and the critical role SharePoint typically plays in enterprise collaboration and document management. Apply Microsoft’s security update without delay and review the advisory for affected versions and any additional hardening recommendations.

Vendor Advisory