23 vulnerabilities across 15 products scored HIGH or above on July 15, 2026.
- π΄ CRITICAL: 2
- π HIGH: 21
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-57219 (rabbitmq/rabbitmq_server) β F1: theoretical β itw, AAS: 10.9 β 13.7 (HIGH β CRITICAL). Originally in 2026-07-10 bulletin.
- [UPGRADED] CVE-2026-55884 (tilt-dev/tilt) β F1: exploitable β itw, AAS: 10.3 β 13.0 (HIGH β CRITICAL). Originally in 2026-07-10 bulletin.
- [UPGRADED] CVE-2026-55879 (openreplay/openreplay) β F1: exploitable β itw, AAS: 10.3 β 13.3 (HIGH β CRITICAL). Originally in 2026-07-10 bulletin.
- [UPGRADED] CVE-2026-54003 (getkirby/kirby) β F1: theoretical β poc, AAS: 11.8 β 11.5 (HIGH β HIGH). Originally in 2026-07-09 bulletin.
- [UPGRADED] CVE-2026-59827 (metabase/metabase) β F1: exploitable β itw, AAS: 11.2 β 13.1 (HIGH β CRITICAL). Originally in 2026-07-09 bulletin.
- [UPGRADED] CVE-2026-59148 (mockoon/mockoon) β F1: exploitable β itw, AAS: 9.6 β 12.6 (HIGH β CRITICAL). Originally in 2026-07-09 bulletin.
- [UPGRADED] CVE-2026-59858 (vim/vim) β F1: exploitable β itw, AAS: 9.3 β 12.3 (HIGH β CRITICAL). Originally in 2026-07-09 bulletin.
- [UPGRADED] CVE-2026-55207 (pimcore/pimcore) β F1: theoretical β poc, AAS: 9.1 β 11.6 (HIGH β HIGH). Originally in 2026-07-09 bulletin.
- [UPGRADED] CVE-2026-57480 (parse-community/parse-server) β F1: theoretical β poc, AAS: 9.8 β 12.3 (HIGH β CRITICAL). Originally in 2026-07-08 bulletin.
π΄ [CRITICAL] wazuh/wazuh
1 CVE | CVSS 4.0: 10.0 | AAS 13.1
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*
Wazuh Manager versions prior to 5.0.0-beta3 are affected by a critical NDJSON injection vulnerability (CVE-2026-56699, CVSS 10.0) that allows enrolled agents to inject arbitrary OpenSearch bulk operations by exploiting insufficient escaping of the DataValue.index field. An attacker with agent enrollment can smuggle delete, index, or update operations executed under the manager’s admin credentials, enabling alert tampering, document deletion, and cross-agent SIEM state manipulation. Organizations running Wazuh Manager should upgrade to version 5.0.0-beta3 or later immediately and review OpenSearch indices for signs of unauthorized modifications; refer to the vendor advisory at github.com/wazuh/wazuh/security/advisories/GHSA-ff9g-85jq-r3g3 for full details.
- π΄ CVE-2026-56699 (CVSS 4.0: 10.0)
π΄ [CRITICAL] better-auth/better-auth
2 CVEs | CVSS 4.0: 9.1 | AAS 12.7
cpe:2.3:a:better-auth:better-auth:*:*:*:*:*:*:*:*
Better Auth, a popular TypeScript authentication and authorization library, is affected by two critical vulnerabilities (CVE-2026-53512, CVE-2026-53516, max CVSS 9.1) in versions prior to 1.6.11, including at least one flaw in the legacy oidcProvider and MCP plugins where OAuth token endpoints fail to verify the confidential client’s client_secret during refresh_token grants. An attacker who obtains a valid refresh token can exploit this to mint new access tokens and rotated refresh tokens without proper client authentication, compromising downstream applications relying on Better Auth for OAuth or MCP token issuance. Teams using Better Auth should upgrade to version 1.6.11 or later immediately and review token issuance logs for unauthorized refresh activity; see the vendor commit at github.com/better-auth/better-auth/commit/1f2ff42 for patch details.
- π΄ CVE-2026-53512 (CVSS 4.0: 9.1)
- π CVE-2026-53516 (CVSS 3.1: 8.3)
π [HIGH] metabase/metabase
1 CVE | CVSS 3.1: 10.0 | AAS 11.8
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
Metabase, the widely used open-source business intelligence platform, is affected by a critical remote code execution vulnerability (CVE-2026-50148, CVSS 10.0) impacting versions 1.54.0 through multiple release branches. A user with permission to add or edit database connections can achieve full server compromise by configuring a Snowflake connection to an attacker-controlled server, exploiting a flaw in the Snowflake JDBC driver to write arbitrary files to the Metabase host. Organizations running affected versions should upgrade immediately to one of the patched releases (1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, or 1.60.4) and audit which users have database connection management privileges; see the vendor advisory at github.com/metabase/metabase/security/advisories/GHSA-r6x2-rchx-q9g9 for details.
- π CVE-2026-50148 (CVSS 3.1: 10.0)
π [HIGH] cilium/cilium
1 CVE | CVSS 3.1: 9.2 | AAS 11.7
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
Cilium, the widely deployed Kubernetes networking and security solution, is affected by a high-severity vulnerability (CVE-2026-49445, CVSS 9.2) in versions prior to 1.17.14, 1.18.8, and 1.19.2 where enabling L7 functionality causes the Envoy instance to create a world-accessible admin.sock on cluster nodes. A local attacker can exploit this socket to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate the Envoy process entirely. Organizations running Cilium with L7 policy enforcement should upgrade to versions 1.17.14, 1.18.8, or 1.19.2 immediately and audit node-level access controls; see the vendor patch at github.com/cilium/cilium/commit/7bfbdd5 for details.
- π CVE-2026-49445 (CVSS 3.1: 9.2)
π [HIGH] wwbn/avideo
1 CVE | CVSS 3.1: 9.6 | AAS 11.5
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
WWBN AVideo, an open-source video platform, is affected by a high-severity stored DOM cross-site scripting vulnerability (CVE-2026-54458, CVSS 9.6) in the YPTSocket plugin in all versions prior to 29.0. An unauthenticated remote attacker can obtain a signed WebSocket token anonymously and inject arbitrary JavaScript that executes in the browser of every administrator viewing the YPTSocket online-users debug panel, enabling full account takeover. Organizations hosting AVideo instances should upgrade to version 29.0 or later immediately and review administrator sessions for signs of compromise; see the vendor patch at github.com/WWBN/AVideo/commit/8be71e5 for details.
- π CVE-2026-54458 (CVSS 3.1: 9.6)
π [HIGH] penpot/penpot
3 CVEs | CVSS 3.1: 9.9 | AAS 11.2
cpe:2.3:a:penpot:penpot:*:*:*:*:*:*:*:*(< 2.15.0)
Penpot, the open-source design and code collaboration platform, is affected by three high-severity vulnerabilities (CVE-2026-44986, CVE-2026-45806, CVE-2026-45805, max CVSS 9.9) in versions prior to 2.14.5, including multiple authentication and session handling flaws. The most critical issue allows a registered user to take over any non-blocked account by exploiting exposed team invitation tokens and a registration flow that issues sessions based on email matching without password verification. Organizations self-hosting Penpot should upgrade to version 2.14.5 immediately, review team invitation logs for abuse, and audit recent account activity for signs of unauthorized access; see the vendor patch at github.com/penpot/penpot/commit/9e68126 for details.
- π CVE-2026-44986 (CVSS 3.1: 9.9)
- π CVE-2026-45806 (CVSS 3.1: 7.7)
- π CVE-2026-45805 (CVSS 3.1: 8.8)
π [HIGH] decolua/9router
1 CVE | CVSS 3.1: 9.8 | AAS 10.9
cpe:2.3:a:decolua:9router:*:*:*:*:*:*:*:*
9Router, an AI router and token optimization tool by decolua, is affected by a high-severity authentication bypass vulnerability (CVE-2026-49352, CVSS 9.8) in versions 0.2.21 through 0.4.43 caused by a hardcoded fallback JWT secret used when the JWT_SECRET environment variable is not set. An attacker can forge valid auth_token cookies using the publicly known default secret to gain unauthorized administrative access to any 9Router instance deployed without an explicit JWT_SECRET configuration. Organizations using 9Router should upgrade to version 0.4.44 immediately, ensure JWT_SECRET is explicitly set in all environments, and rotate any existing sessions; see the vendor patch at github.com/decolua/9router/commit/fe3ce25 for details.
- π CVE-2026-49352 (CVSS 3.1: 9.8)
π [HIGH] openwrt/luci
1 CVE | CVSS 3.1: 9.6 | AAS 10.9
cpe:2.3:a:openwrt:luci:*:*:*:*:*:*:*:*
OpenWrt LuCI, the web administration interface used on millions of embedded devices, is affected by a high-severity stored cross-site scripting vulnerability (CVE-2026-62948, CVSS 9.6) in versions prior to 25.12.5 where DHCPv6 client hostnames are written to the lease file without escaping, allowing newline injection of forged lease entries rendered as live HTML in the Active Leases panel. An unauthenticated attacker on the local network can send a crafted DHCPv6 FQDN option to execute arbitrary JavaScript in the browser of any administrator viewing the LuCI status page, enabling session hijacking and full router compromise. Organizations and individuals running OpenWrt should upgrade to version 25.12.5 or later immediately and review DHCP lease files for suspicious entries; see the vendor patch at github.com/openwrt/luci/commit/55379d0 for details.
- π CVE-2026-62948 (CVSS 3.1: 9.6)
π [HIGH] hkuds/lightrag
2 CVEs | CVSS 4.0: 9.3 | AAS 10.7
cpe:2.3:a:hkuds:lightrag:*:*:*:*:*:*:*:*(< 1.5.4)
LightRAG, an open-source retrieval-augmented generation framework by HKUDS, is affected by two high-severity vulnerabilities (CVE-2026-61740, CVE-2026-61736, max CVSS 9.3) in versions prior to 1.5.4, including multiple authentication bypass flaws. When deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, a remote unauthenticated attacker can bypass API key protection by exploiting a hardcoded default token secret to mint guest JWTs that are accepted before API key validation occurs, granting full access to protected endpoints. Organizations running LightRAG should upgrade to version 1.5.4 immediately, ensure AUTH_ACCOUNTS is explicitly configured in all deployments, and audit access logs for unauthorized API calls; see the vendor patch at github.com/HKUDS/LightRAG/commit/f7819aa for details.
- π CVE-2026-61740 (CVSS 4.0: 9.3)
- π CVE-2026-61736 (CVSS 3.1: 9.3)
π [HIGH] f5/nginx
2 CVEs | CVSS 4.0: 9.2 | AAS 10.5
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
F5 NGINX Plus and NGINX Open Source are affected by two high-severity vulnerabilities (CVE-2026-42533, CVE-2026-56434, max CVSS 9.2), including multiple flaws related to map directive regex matching where crafted HTTP requests can trigger heap-based memory issues when string expressions reference regex capture variables or non-cacheable variables under certain conditions. An unauthenticated remote attacker can exploit these issues by sending specially crafted requests, potentially causing denial of service or other memory corruption impacts across affected NGINX deployments. Organizations running NGINX Plus or NGINX Open Source should consult the F5 advisory at my.f5.com/manage/s/article/K000162097 immediately for affected version details and apply the recommended updates.
- π CVE-2026-42533 (CVSS 4.0: 9.2)
- π CVE-2026-56434 (CVSS 4.0: 8.3)
π [HIGH] directus/directus
1 CVE | CVSS 3.1: 8.6 | AAS 10.4
cpe:2.3:a:directus:directus:*:*:*:*:*:*:*:*
Directus, a widely used real-time API and dashboard for managing SQL database content, is affected by a high-severity cache poisoning vulnerability (CVE-2026-61836, CVSS 8.6) in versions prior to 12.0.0 where response cache keys omit authorization context such as share tokens, roles, and policies. When response caching is enabled, different share tokens or anonymous requests that resolve to the same cache key can receive responses intended for other authorization contexts, leading to unauthorized data exposure across permission boundaries. Organizations running Directus with response caching enabled should upgrade to version 12.0.0 immediately or disable response caching as a temporary mitigation; see the vendor patch at github.com/directus/directus/commit/7ba4efb for details.
- π CVE-2026-61836 (CVSS 3.1: 8.6)
π [HIGH] mantisbt/mantisbt
2 CVEs | CVSS 3.1: 9.5 | AAS 10.3
cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*
MantisBT version 2.28.3 and earlier is affected by two high-severity vulnerabilities (CVE-2026-52847, CVE-2026-47156, max CVSS 9.5), including multiple reflected cross-site scripting injection points in the unauthenticated admin install page where user-supplied parameters are echoed into HTML without escaping. While a Content Security Policy blocks inline script execution, the missing form-action directive allows exploitation through credential-phishing form injection and meta-tag open redirects, enabling attackers to craft malicious URLs that harvest administrator credentials. Organizations running MantisBT should apply patches as soon as they become available, restrict access to the admin install endpoint at the network level, and monitor for suspicious URLs targeting /admin/install.php; see the advisory at github.com/advisories/GHSA-77x8-3v3h-hrhv for details.
- π CVE-2026-52847 (CVSS 3.1: 9.5)
- π CVE-2026-47156 (CVSS 3.1: 9.5)
π [HIGH] open-webui/open-webui
1 CVE | CVSS 4.0: 9.0 | AAS 10.3
cpe:2.3:a:open-webui:open-webui:*:*:*:*:*:*:*:*
Open WebUI, a popular web interface for managing AI models, is affected by a high-severity cross-origin resource sharing misconfiguration (CVE-2026-56400, CVSS 9.0) in versions prior to 0.3.14 where the API permits authenticated requests from arbitrary origins. An attacker can host a malicious website that, when visited by an Open WebUI administrator, executes crafted cross-site requests to the /api/v1/functions endpoint to achieve arbitrary code execution on the Open WebUI instance. Organizations running Open WebUI should upgrade to version 0.3.14 or later immediately and review function endpoint logs for unauthorized activity; see the vendor advisory at github.com/open-webui/open-webui/security/advisories/GHSA-6xcp-7mpr-m7wm for details.
- π CVE-2026-56400 (CVSS 4.0: 9.0)
π [HIGH] labring/fastgpt
2 CVEs | CVSS 4.0: 9.3 | AAS 10.2
cpe:2.3:a:labring:fastgpt:*:*:*:*:*:*:*:*
FastGPT, a knowledge-based AI application platform by labring, is affected by two high-severity vulnerabilities (CVE-2026-50562, CVE-2026-61684, max CVSS 9.3), including multiple CI/CD pipeline flaws where artifacts built from untrusted pull request code can be downloaded and executed by privileged workflow_run jobs. An attacker can submit a malicious pull request that injects attacker-controlled Docker images into the build pipeline, potentially compromising the supply chain for all downstream FastGPT deployments. Organizations using FastGPT should update to the latest version immediately, audit any recently deployed container images for tampering, and review the vendor advisory at github.com/labring/FastGPT/security/advisories/GHSA-rvgc-2c29-g876 for remediation details.
- π CVE-2026-50562 (CVSS 4.0: 9.3)
- π CVE-2026-61684 (CVSS 4.0: 8.8)
π [HIGH] lightpanda-io/browser
2 CVEs | CVSS 3.1: 9.3 | AAS 10.1
cpe:2.3:a:lightpanda-io:browser:*:*:*:*:*:*:*:*
Lightpanda, a headless browser designed for AI and automation workflows, is affected by two high-severity vulnerabilities (CVE-2026-52843, CVE-2026-52842, max CVSS 9.3) in versions prior to 0.2.9, including multiple credential handling flaws where fetch() and XMLHttpRequest unconditionally attach session cookies to every HTTP request regardless of the configured credentials policy. An attacker-controlled origin loaded within a Lightpanda session can exploit this to issue authenticated cross-origin requests against any victim origin the session holds cookies for, bypassing standard browser same-origin protections. Teams using Lightpanda in automation or AI pipelines should upgrade to version 0.2.9 immediately and review any workflows that process untrusted URLs for potential cross-origin abuse; see the vendor patch at github.com/lightpanda-io/browser/commit/2cdaac7 for details.
- π CVE-2026-52843 (CVSS 3.1: 9.3)
- π CVE-2026-52842 (CVSS 3.1: 9.3)