17 vulnerabilities across 8 products scored HIGH or above on July 17, 2026.
- π΄ CRITICAL: 1
- π HIGH: 16
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-57219 (rabbitmq/rabbitmq_server) β F1: theoretical β itw, AAS: 10.9 β 13.7 (HIGH β CRITICAL). Originally in 2026-07-10 bulletin.
- [UPGRADED] CVE-2026-55884 (tilt-dev/tilt) β F1: exploitable β itw, AAS: 10.3 β 13.0 (HIGH β CRITICAL). Originally in 2026-07-10 bulletin.
- [UPGRADED] CVE-2026-55879 (openreplay/openreplay) β F1: exploitable β itw, AAS: 10.3 β 13.3 (HIGH β CRITICAL). Originally in 2026-07-10 bulletin.
π΄ [CRITICAL] wordpress/wordpress
1 CVE | CVSS 3.1: 9.8 | AAS 15.7
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*(>= 6.9.0, < 6.9.5)cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*(>= 7.0.0, < 7.0.2)
WordPress core versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 contain a critical vulnerability (CVE-2026-63030, CVSS 9.8) involving REST API batch endpoint route confusion that, when chained with a separate WP_Query SQL injection flaw, enables unauthenticated remote code execution. A proof-of-concept exploit is publicly available, significantly raising the risk of active exploitation against any unpatched WordPress installation. All organizations running affected WordPress versions should update to 6.9.5 or 7.0.2 immediately, review web application firewall rules to filter malicious REST API batch requests, and inspect logs for signs of exploitation. Refer to the vendor advisory at the linked GitHub security advisory for full details.
- π΄ CVE-2026-63030 (CVSS 3.1: 9.8)
π [HIGH] ibm/langflow_oss
10 CVEs | CVSS 3.1: 9.9 | AAS 10.9
cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:*(>= 1.0.0)cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:*(>= 1.0.0, < 1.10.2)
IBM Langflow OSS versions 1.0.0 through 1.10.0 are affected by 10 vulnerabilities, including multiple critical and high-severity issues up to CVSS 9.9. The most severe flaw allows unauthenticated remote attackers to obtain full superuser access by exploiting the default-enabled auto-login endpoint, which issues long-lived administrative tokens without authentication, compounded by permissive CORS settings that widen the attack surface. Organizations running Langflow OSS should immediately apply the fixes referenced in the IBM support advisory, disable the AUTO_LOGIN configuration if not already done, and audit environments for signs of unauthorized access or token abuse.
- π CVE-2026-9103 (CVSS 3.1: 9.8)
- π CVE-2026-9202 (CVSS 3.1: 9.8)
- π CVE-2026-8505 (CVSS 3.1: 9.8)
- π CVE-2026-9198 (CVSS 3.1: 9.8)
- π CVE-2026-13446 (CVSS 3.1: 9.8)
- π CVE-2026-9135 (CVSS 3.1: 9.9)
- π CVE-2026-8481 (CVSS 3.1: 9.9)
- π CVE-2026-8476 (CVSS 3.1: 9.9)
- π CVE-2026-8859 (CVSS 3.1: 9.9)
- π CVE-2026-8635 (CVSS 3.1: 9.9)
π [HIGH] fossasia/open-event-server
1 CVE | CVSS 4.0: 8.7 | AAS 10.8
cpe:2.3:a:fossasia:open-event-server:*:*:*:*:*:*:*:*
FOSSASIA Open Event Server through version 1.19.1 contains a high-severity missing authentication vulnerability (CVE-2026-63101, CVSS 8.7) that allows unauthenticated attackers to export complete group member rosters, including email addresses, names, join dates, and roles, by exploiting an unprotected CSV export endpoint. Attackers can trivially enumerate group IDs and bulk-harvest sensitive member data without any credentials, making this a significant data exposure risk for any organization running a public-facing instance. Organizations using Open Event Server should restrict access to the group followers export and task status endpoints immediately, monitor logs for unauthorized export requests, and apply a patch as soon as one becomes available from the vendor.
- π CVE-2026-63101 (CVSS 4.0: 8.7)
π [HIGH] zalando/skipper
1 CVE | CVSS 4.0: 7.8 | AAS 10.0
cpe:2.3:a:zalando:skipper:*:*:*:*:*:*:*:*
Zalando Skipper versions prior to 0.26.10 contain a high-severity policy bypass vulnerability (CVE-2026-50197, CVSS 7.8) in which the Open Policy Agent integration silently skips request body inspection for HTTP/1.1 chunked transfer-encoded requests and HTTP/2 requests missing a content-length header, passing an empty body to OPA while the upstream service processes the full payload. This allows attackers to craft requests that evade OPA authorization policies entirely while still delivering malicious content to backend services. Organizations using Skipper with OPA-based request body authorization should upgrade to version 0.26.10 immediately and review access logs for suspicious chunked or content-length-omitting requests that may have bypassed policy enforcement.
- π CVE-2026-50197 (CVSS 4.0: 7.8)
π [HIGH] pipeboard-co/meta-ads-mcp
1 CVE | CVSS 3.1: 8.3 | AAS 9.9
cpe:2.3:a:pipeboard-co:meta-ads-mcp:*:*:*:*:*:*:*:*
The meta-ads-mcp package version 1.0.113 from Pipeboard contains a high-severity server-side request forgery vulnerability (CVE-2026-54549, CVSS 8.3) in the upload_ad_image MCP tool, where an attacker-controlled image_url parameter is passed directly to an HTTP fetch call without any scheme, host, or IP address validation. When deployed using the officially supported streamable-http transport, an unauthenticated remote attacker can abuse this to reach internal services, cloud metadata endpoints, and other network resources accessible from the server. Organizations using meta-ads-mcp should upgrade to a patched version as soon as one is available, restrict network egress from the server to only required external hosts, and review logs for unexpected outbound requests originating from the upload_ad_image endpoint.
- π CVE-2026-54549 (CVSS 3.1: 8.3)
π [HIGH] adobe/acrobat_reader
1 CVE | CVSS 3.1: 7.8 | AAS 9.6
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
Adobe Acrobat Reader is affected by a high-severity heap-based buffer overflow vulnerability (CVE-2026-48373, CVSS 7.8) that can allow arbitrary code execution in the context of the current user when a victim opens a specially crafted malicious file. Given Acrobat Reader’s massive install base and the user-interaction-only requirement for exploitation, this flaw poses a significant risk through phishing campaigns and malicious document delivery. Organizations should apply the latest Adobe security update referenced in APSB26-63 immediately, remind users not to open unexpected PDF attachments, and ensure endpoint protection solutions are updated to detect exploitation attempts.
- π CVE-2026-48373 (CVSS 3.1: 7.8)
π [HIGH] getgrav/grav
1 CVE | CVSS 4.0: 9.1 | AAS 9.3
cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
Grav CMS versions prior to 2.0.4 contain a high-severity two-factor authentication bypass vulnerability (CVE-2026-62232, CVSS 9.1) in the login plugin, where an attacker who knows a victim’s password can exploit the regenerate2FASecret task during the pending TOTP challenge window to overwrite the 2FA secret with an attacker-chosen value, effectively reducing two-factor authentication to password-only protection. The task lacks both proper authorization checks and CSRF nonce validation, making exploitation straightforward for any attacker with compromised credentials. Organizations running Grav CMS with 2FA enabled should upgrade to version 2.0.4 immediately, audit admin account activity for unauthorized 2FA secret changes, and consider enforcing additional access controls on administrative endpoints.
- π CVE-2026-62232 (CVSS 4.0: 9.1)
π [HIGH] codeigniter4/codeigniter4
1 CVE | CVSS 3.1: 9.8 | AAS 9.1
cpe:2.3:a:codeigniter4:codeigniter4:*:*:*:*:*:*:*:*
CodeIgniter4 versions prior to 4.7.3 contain a critical file upload validation bypass vulnerability (CVE-2026-48062, CVSS 9.8) where the ext_in validation rule checks the MIME-derived extension rather than the actual client-provided filename extension, allowing an attacker to upload executable files such as shell.php disguised with benign content that passes image validation checks. This flaw can lead to remote code execution on any application relying on CodeIgniter’s built-in upload validation to restrict file types. Organizations using CodeIgniter4 should upgrade to version 4.7.3 immediately, audit existing upload directories for suspicious files with executable extensions, and consider implementing server-level restrictions that prevent script execution in upload directories as a defense-in-depth measure.
- π CVE-2026-48062 (CVSS 3.1: 9.8)