23 vulnerabilities across 12 products scored HIGH or above on July 20, 2026.

  • ๐ŸŸ  HIGH: 23

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-45695 (kopia/kopia) โ€” F1: exploitable โ†’ functional, AAS: 11.1 โ†’ 13.1 (HIGH โ†’ CRITICAL). Originally in 2026-07-16 bulletin.
  • [UPGRADED] CVE-2026-55579 (pheditor/pheditor) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 12.9 (HIGH โ†’ CRITICAL). Originally in 2026-07-16 bulletin.
  • [UPGRADED] CVE-2026-54526 (argoproj/argo-workflows) โ€” F1: exploitable โ†’ itw, AAS: 9.8 โ†’ 12.8 (HIGH โ†’ CRITICAL). Originally in 2026-07-16 bulletin.
  • [UPGRADED] CVE-2026-47984 (adobe/commerce) โ€” F1: exploitable โ†’ functional, AAS: 10.7 โ†’ 14.5 (HIGH โ†’ CRITICAL). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-57087 (microsoft/windows) โ€” F1: exploitable โ†’ itw, AAS: 10.6 โ†’ 13.6 (HIGH โ†’ CRITICAL). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-50313 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.6 โ†’ 11.6 (HIGH โ†’ HIGH). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-40400 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.3 โ†’ 11.3 (HIGH โ†’ HIGH). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-50306 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-58319 (apache/doris) โ€” F1: exploitable โ†’ itw, AAS: 10.5 โ†’ 12.0 (HIGH โ†’ CRITICAL). Originally in 2026-07-14 bulletin.

๐ŸŸ  [HIGH] rvc-boss/gpt-sovits

1 CVE | CVSS 4.0: 9.3 | AAS 10.7

  • cpe:2.3:a:rvc-boss:gpt-sovits:*:*:*:*:*:*:*:*

Failed to authenticate. API Error: 401 Invalid authentication credentials

Vendor Advisory


๐ŸŸ  [HIGH] neutrinolabs/xrdp

3 CVEs | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:* (< 0.10.7)

Failed to authenticate. API Error: 401 Invalid authentication credentials

Vendor Advisory


๐ŸŸ  [HIGH] surrealdb/surrealdb

6 CVEs | CVSS 4.0: 9.2 | AAS 10.5

  • cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:* (< 3.2.0)

Failed to authenticate. API Error: 401 Invalid authentication credentials

Vendor Advisory


๐ŸŸ  [HIGH] kvcache-ai/ktransformers

1 CVE | CVSS 4.0: 9.3 | AAS 10.2

  • cpe:2.3:a:kvcache-ai:ktransformers:*:*:*:*:*:*:*:*

Failed to authenticate. API Error: 401 OAuth access token has expired. Re-authenticate to continue.

Vendor Advisory


๐ŸŸ  [HIGH] freescout-help-desk/freescout

3 CVEs | CVSS 3.1: 9.4 | AAS 10.2

  • cpe:2.3:a:freescout-help-desk:freescout:*:*:*:*:*:*:*:*

Failed to authenticate. API Error: 401 OAuth access token has expired. Re-authenticate to continue.

Vendor Advisory


๐ŸŸ  [HIGH] dotcms/dotcms

1 CVE | CVSS 4.0: 9.4 | AAS 10.0

  • cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*

Failed to authenticate. API Error: 401 OAuth access token has expired. Re-authenticate to continue.

Vendor Advisory


๐ŸŸ  [HIGH] freerdp/freerdp

2 CVEs | CVSS 4.0: 9.3 | AAS 9.9

  • cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* (>= 3.0.0, < 3.28.0)

Failed to authenticate. API Error: 401 Invalid authentication credentials

Vendor Advisory


๐ŸŸ  [HIGH] heyform/heyform

2 CVEs | CVSS 3.1: 9.0 | AAS 9.4

  • cpe:2.3:a:heyform:heyform:*:*:*:*:*:*:*:* (< 3.0.0-rc.9)

Failed to authenticate. API Error: 401 OAuth access token has expired. Re-authenticate to continue.

Vendor Advisory


๐ŸŸ  [HIGH] wazuh/wazuh

1 CVE | CVSS 3.1: 8.4 | AAS 9.1

  • cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* (< 4.14.5)

Failed to authenticate. API Error: 401 OAuth access token has expired. Re-authenticate to continue.

Vendor Advisory


๐ŸŸ  [HIGH] bestpractical/rt

1 CVE | CVSS 3.1: 9.1 | AAS 9.0

  • cpe:2.3:a:bestpractical:rt:*:*:*:*:*:*:*:*

Failed to authenticate. API Error: 401 OAuth access token has expired. Re-authenticate to continue.

Vendor Advisory


๐ŸŸ  [HIGH] roocodeinc/roo-code

1 CVE | CVSS 4.0: 7.7 | AAS 9.0

  • cpe:2.3:a:roocodeinc:roo-code:*:*:*:*:*:*:*:*

Failed to authenticate. API Error: 401 OAuth access token has expired. Re-authenticate to continue.

Vendor Advisory


๐ŸŸ  [HIGH] glanceapp/glance

1 CVE | CVSS 4.0: 8.2 | AAS 9.0

  • cpe:2.3:a:glanceapp:glance:*:*:*:*:*:*:*:* (< 0.8.6)

Failed to authenticate. API Error: 401 Invalid authentication credentials

Vendor Advisory