130 vulnerabilities across 9 products scored HIGH or above on July 21, 2026.

  • πŸ”΄ CRITICAL: 5
  • 🟠 HIGH: 125

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-63770 (glanceapp/glance) β€” F1: theoretical β†’ poc, AAS: 9.0 β†’ 11.5 (HIGH β†’ HIGH). Originally in 2026-07-20 bulletin.
  • [UPGRADED] CVE-2026-45695 (kopia/kopia) β€” F1: exploitable β†’ functional, AAS: 11.1 β†’ 13.1 (HIGH β†’ CRITICAL). Originally in 2026-07-16 bulletin.
  • [UPGRADED] CVE-2026-55579 (pheditor/pheditor) β€” F1: exploitable β†’ functional, AAS: 10.9 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-07-16 bulletin.
  • [UPGRADED] CVE-2026-54526 (argoproj/argo-workflows) β€” F1: exploitable β†’ itw, AAS: 9.8 β†’ 12.8 (HIGH β†’ CRITICAL). Originally in 2026-07-16 bulletin.
  • [UPGRADED] CVE-2026-47984 (adobe/commerce) β€” F1: exploitable β†’ functional, AAS: 10.7 β†’ 14.5 (HIGH β†’ CRITICAL). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-57087 (microsoft/windows) β€” F1: exploitable β†’ itw, AAS: 10.6 β†’ 13.6 (HIGH β†’ CRITICAL). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-50313 (microsoft/windows) β€” F1: exploitable β†’ functional, AAS: 9.6 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-40400 (microsoft/windows) β€” F1: exploitable β†’ functional, AAS: 9.3 β†’ 11.3 (HIGH β†’ HIGH). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-50306 (microsoft/windows) β€” F1: exploitable β†’ functional, AAS: 9.1 β†’ 11.1 (HIGH β†’ HIGH). Originally in 2026-07-14 bulletin.
  • [UPGRADED] CVE-2026-58319 (apache/doris) β€” F1: exploitable β†’ itw, AAS: 10.5 β†’ 13.5 (HIGH β†’ CRITICAL). Originally in 2026-07-14 bulletin.

πŸ”΄ [CRITICAL] oracle/coherence

52 CVEs | CVSS 3.1: 10.0 | AAS 13.9

  • cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:coherence:*:*:*:*:*:*:*:*

Oracle Coherence, a core component of Oracle Fusion Middleware, is affected by 52 vulnerabilities disclosed in the July 2026 Critical Patch Update, including multiple critical-severity flaws with CVSS scores up to 10.0. The lead vulnerability allows an unauthenticated attacker with network access via TCP to achieve full takeover of affected Coherence instances across versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, and functional exploit code is available. Organizations running Oracle Coherence in any capacity should treat this as an emergency patching priority and apply the fixes from Oracle’s July 2026 Critical Patch Update advisory immediately.

Vendor Advisory


🟠 [HIGH] mozilla/firefox

47 CVEs | CVSS 3.1: 10.0 | AAS 11.8

  • cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* (< 153.0.0)
  • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* (>= 141.0, < 153.0)
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* (>= 128.1.0, < 140.13.0)
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* (>= 140.1.0, < 140.13.0)
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* (< 153.0.0)

Mozilla Firefox is affected by 47 vulnerabilities, including multiple high-severity flaws with CVSS scores up to 10.0, with at least one enabling a sandbox escape through an invalid pointer in the Disability Access APIs component. These issues are considered exploitable and affect Firefox versions prior to 153, as well as Thunderbird prior to 153, posing serious risk to any organization relying on these browsers in managed or unmanaged endpoint environments. All administrators and end users should update to Firefox 153 and Thunderbird 153 immediately and verify deployment across their fleet.

Vendor Advisory


🟠 [HIGH] oracle/application_testing_suite

3 CVEs | CVSS 3.1: 9.8 | AAS 11.4

  • cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:application_testing_suite:*:*:*:*:*:*:*:*

Oracle Application Testing Suite version 13.3.0.1 is affected by 3 vulnerabilities, including multiple critical-severity flaws with CVSS scores up to 9.8 that allow an unauthenticated attacker with network access via TCP to achieve full system takeover with complete impact to confidentiality, integrity, and availability. These vulnerabilities are considered exploitable and require no user interaction or privileges, making them particularly dangerous for any organization with exposed instances. Teams running Application Testing Suite should apply the patches from Oracle’s July 2026 Critical Patch Update immediately and restrict network access to the service until remediation is confirmed.

Vendor Advisory


🟠 [HIGH] google/chrome

8 CVEs | CVSS 3.1: 9.6 | AAS 11.4

  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* (< 150.0.7871.182)

Google Chrome is affected by 8 vulnerabilities, including multiple high-severity flaws with CVSS scores up to 9.6, with at least one enabling a sandbox escape via an out-of-bounds read and write in the ANGLE graphics component on Android, triggerable through a crafted HTML page. These issues affect Chrome versions prior to 150.0.7871.182 and are considered exploitable, posing risk to any organization with Chrome deployed across desktop or mobile endpoints. Administrators should push Chrome updates to version 150.0.7871.182 or later across all managed devices immediately, and verify that auto-update policies are functioning for unmanaged endpoints.

Vendor Advisory


🟠 [HIGH] oracle/webcenter_content

2 CVEs | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:oracle:webcenter_content:*:*:*:*:*:*:*:*

Oracle WebCenter Content, part of Oracle Fusion Middleware, is affected by 2 vulnerabilities in the Content Server component, including at least one critical-severity flaw with a CVSS score of 9.8 that allows an unauthenticated attacker with network access via HTTP to achieve full takeover of the system. Versions 12.2.1.4.0 and 14.1.2.0.0 are confirmed affected, and the vulnerabilities are easily exploitable with no privileges or user interaction required. Organizations running WebCenter Content should apply the fixes from Oracle’s July 2026 Critical Patch Update without delay and audit network exposure to these instances.

Vendor Advisory


🟠 [HIGH] oracle/access_manager

1 CVE | CVSS 3.1: 8.8 | AAS 10.1

  • cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*

Oracle Access Manager version 14.1.2.1.0, a component of Oracle Fusion Middleware, is affected by a high-severity vulnerability in the Authentication Engine with a CVSS score of 8.8 that allows a low-privileged attacker with network access via HTTP to achieve full takeover of the system with complete impact to confidentiality, integrity, and availability. The flaw is easily exploitable and particularly concerning given Access Manager’s role as a centralized authentication and single sign-on gateway, meaning compromise could cascade across dependent applications. Organizations using Oracle Access Manager should apply the patch from Oracle’s July 2026 Critical Patch Update immediately and review access logs for any signs of exploitation.

Vendor Advisory


🟠 [HIGH] developer-developer/free_builder_for_elementor

1 CVE | CVSS 3.1: 8.8 | AAS 10.1

  • cpe:2.3:a:developer-developer:free_builder_for_elementor:*:*:*:*:*:*:*:* (< 1.6.7)

The Free Builder for Elementor WordPress plugin prior to version 1.6.7 contains a high-severity stored cross-site scripting vulnerability with a CVSS score of 8.8 that allows unauthenticated attackers to inject malicious scripts through contact form submissions, which execute in the browser of any logged-in administrator who views the form entries in the dashboard. This is particularly dangerous as it requires no authentication to exploit and targets administrative sessions, potentially leading to full site compromise. WordPress administrators using this plugin should update to version 1.6.7 or later immediately and review recent contact form submissions for any suspicious or unexpected content.

Vendor Advisory


🟠 [HIGH] netty/netty

2 CVEs | CVSS 3.1: 7.5 | AAS 9.1

  • cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* (>= 4.1.0, < 4.1.136)
  • cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* (>= 4.2.0, < 4.2.16)

Netty, a widely used Java network application framework, is affected by 2 high-severity vulnerabilities with CVSS scores up to 7.5, including at least one in the SPDY SETTINGS decoder that allows a remote peer to send a crafted SETTINGS frame causing excessive heap growth and resource exhaustion through amplification of a roughly 2 MiB input into hundreds of thousands of map entries. These flaws affect versions prior to 4.1.136.Final and 4.2.16.Final and are exploitable remotely, posing denial-of-service risk to any application or middleware built on Netty, which is embedded in numerous enterprise products including Elasticsearch, Cassandra, and Spring. Teams should update to Netty 4.1.136.Final or 4.2.16.Final immediately, and check downstream dependencies for bundled Netty versions that may also require updates.

Vendor Advisory


🟠 [HIGH] solarwinds/serv-u

14 CVEs | CVSS 3.1: 9.1 | AAS 9.0

  • cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* (< 2026.3)

SolarWinds Serv-U is affected by 14 vulnerabilities with CVSS scores up to 9.1, including multiple high-severity flaws such as a broken access control issue that allows a domain administrator to escalate privileges by creating system administrator accounts, with greater impact on non-Windows deployments. Serv-U is a widely deployed managed file transfer solution and a historically targeted product by advanced threat actors, making this batch of vulnerabilities particularly urgent for organizations relying on it for secure file exchange. Administrators should update to the patched version documented in the SolarWinds Serv-U 2026.3 release notes immediately and audit existing accounts for any unauthorized privilege escalations.

Vendor Advisory