26 vulnerabilities across 15 products scored HIGH or above on July 23, 2026.

  • πŸ”΄ CRITICAL: 1
  • 🟠 HIGH: 25

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-63770 (glanceapp/glance) β€” F1: theoretical β†’ poc, AAS: 9.0 β†’ 11.5 (HIGH β†’ HIGH). Originally in 2026-07-20 bulletin.
  • [UPGRADED] CVE-2026-45695 (kopia/kopia) β€” F1: exploitable β†’ functional, AAS: 11.1 β†’ 13.1 (HIGH β†’ CRITICAL). Originally in 2026-07-16 bulletin.
  • [UPGRADED] CVE-2026-55579 (pheditor/pheditor) β€” F1: exploitable β†’ functional, AAS: 10.9 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-07-16 bulletin.
  • [UPGRADED] CVE-2026-54526 (argoproj/argo-workflows) β€” F1: exploitable β†’ itw, AAS: 9.8 β†’ 12.8 (HIGH β†’ CRITICAL). Originally in 2026-07-16 bulletin.

πŸ”΄ [CRITICAL] jetbrains/intellij_idea

3 CVEs | CVSS 3.1: 10.0 | AAS 12.1

  • cpe:2.3:a:jetbrains:intellij_idea:*:*:*:*:*:*:*:*

JetBrains IntelliJ IDEA versions prior to 2026.2 are affected by three vulnerabilities, including at least one rated CRITICAL with a CVSS score of 10.0. The most severe issue allows unauthorized input injection during Remote Development sessions, which could enable an attacker to execute arbitrary actions without authentication. Organizations using IntelliJ IDEA, particularly those leveraging Remote Development features, should treat this as an urgent priority. Update to IntelliJ IDEA 2026.2 or later immediately and review the vendor advisory at https://www.jetbrains.com/privacy-security/issues-fixed/ for full details on all three CVEs.

Vendor Advisory


🟠 [HIGH] regularlabs.com/cache_cleaner_pro_extension_for_joomla

1 CVE | CVSS 3.1: 9.8 | AAS 11.1

  • cpe:2.3:a:regularlabs.com:cache_cleaner_pro_extension_for_joomla:*:*:*:*:*:*:*:*

The Cache Cleaner Pro extension for Joomla by Regular Labs contains a server-side request forgery vulnerability rated CRITICAL at CVSS 9.8. Custom query URLs can be abused to reach internal or reserved network services, potentially allowing an attacker to probe infrastructure, access sensitive endpoints, or pivot to backend systems not intended to be publicly reachable. Joomla administrators using Cache Cleaner Pro should update to the latest patched version immediately and review the vendor advisory at https://regularlabs.com/ for remediation guidance.

Vendor Advisory


🟠 [HIGH] joomshaper.com/easy_store_extension_for_joomla

1 CVE | CVSS 4.0: 9.3 | AAS 10.7

  • cpe:2.3:a:joomshaper.com:easy_store_extension_for_joomla:*:*:*:*:*:*:*:*

The Easy Store extension for Joomla by JoomShaper versions 1.0.0 through 2.0.1 contains an unauthenticated SQL injection vulnerability rated CRITICAL at CVSS 9.3, and proof-of-concept exploit code is publicly available. Improper validation of order parameters allows unauthenticated attackers to extract the entire database contents, including stored credentials and active session data. Joomla site operators running Easy Store should update beyond version 2.0.1 immediately and review the vendor advisory at https://www.joomshaper.com/easystore for patching details; affected sites should also rotate all database credentials and invalidate active sessions as a precaution.

Vendor Advisory


🟠 [HIGH] google/chrome

4 CVEs | CVSS 3.1: 8.8 | AAS 10.6

  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Google Chrome versions prior to 150.0.7871.186 are affected by four vulnerabilities, including multiple issues rated HIGH with a maximum CVSS of 8.8. The most severe is an out-of-bounds write in the Codecs component that could allow a remote attacker to escape the browser sandbox via a crafted HTML page, requiring no user interaction beyond visiting a malicious site. All organizations and end users running Chrome or Chromium-based browsers should update to version 150.0.7871.186 or later immediately and review the vendor advisory at https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html for full details.

Vendor Advisory


🟠 [HIGH] ninja_forms/ninja_forms_file_uploads_extension

1 CVE | CVSS 3.1: 9.6 | AAS 10.4

  • cpe:2.3:a:ninja_forms:ninja_forms_file_uploads_extension:*:*:*:*:*:*:*:*

The Ninja Forms File Uploads Extension for WordPress versions 3.3.26 and earlier contains an unauthenticated cross-site request forgery vulnerability rated CRITICAL at CVSS 9.6. An attacker can trick an authenticated user into executing unintended actions by visiting a malicious page, requiring no prior authentication to the target site, which makes this particularly dangerous for public-facing WordPress installations. Site administrators using this plugin should update beyond version 3.3.26 immediately and review the Patchstack advisory at https://patchstack.com/database/wordpress/plugin/ninja-forms-uploads/vulnerability/wordpress-ninja-forms-file-uploads-extension-plugin-3-3-26-cross-site-request-forgery-csrf-vulnerability for further details.

Vendor Advisory


🟠 [HIGH] h2oai/h2ogpt

1 CVE | CVSS 4.0: 9.3 | AAS 10.2

  • cpe:2.3:a:h2oai:h2ogpt:*:*:*:*:*:*:*:*

h2oGPT versions through 0.2.1 contain a path traversal vulnerability in the OpenAI-compatible files API rated CRITICAL at CVSS 9.3. An unauthenticated remote attacker can read, write, and delete arbitrary files accessible to the server process by injecting traversal sequences into the bearer token, which is compounded by the default API key being set to EMPTY, effectively bypassing all authentication. Organizations running h2oGPT should update beyond version 0.2.1 immediately, ensure a strong non-default API key is configured, and review the advisory at https://github.com/geo-chen/oss/blob/main/h2ogpt.md for full technical details.

Vendor Advisory


🟠 [HIGH] quenary/tugtainer

1 CVE | CVSS 3.1: 9.9 | AAS 10.2

  • cpe:2.3:a:quenary:tugtainer:*:*:*:*:*:*:*:*

Tugtainer, a self-hosted Docker container update automation tool, versions prior to 1.30.2 contain a server-side template injection vulnerability rated CRITICAL at CVSS 9.9. The notification template feature renders user-supplied title and body templates through an unsandboxed Jinja2 environment, allowing any authenticated user to execute arbitrary OS commands as root inside the container. Organizations running Tugtainer should update to version 1.30.2 immediately and review the security advisory at https://github.com/Quenary/tugtainer/security/advisories/GHSA-g2cj-2x47-78vq for full details.

Vendor Advisory


🟠 [HIGH] jetbrains/teamcity

2 CVEs | CVSS 3.1: 9.1 | AAS 10.2

  • cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

JetBrains TeamCity versions prior to 2026.1.2 and 2025.11.6 are affected by two vulnerabilities, including at least one rated CRITICAL at CVSS 9.1. The most severe issue allows code execution through a Kotlin DSL sandbox escape, which could enable an attacker to compromise the TeamCity server and potentially the broader CI/CD pipeline and connected infrastructure. Organizations running TeamCity should update to version 2026.1.2 or 2025.11.6 immediately and review the vendor advisory at https://www.jetbrains.com/privacy-security/issues-fixed/ for complete remediation guidance.

Vendor Advisory


🟠 [HIGH] cyberlord92/saml_single_sign_on_–_sso_login

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:cyberlord92:saml_single_sign_on_sso_login:*:*:*:*:*:*:*:*

The SAML Single Sign On – SSO Login plugin for WordPress versions up to and including 5.4.4 contains an authentication bypass vulnerability rated CRITICAL at CVSS 9.8. A loose boolean check on the return value of PHP’s openssl_verify() causes signature verification errors to be treated as successful, allowing unauthenticated attackers to log in as any existing WordPress user, including administrators. Any WordPress site using this plugin should update beyond version 5.4.4 immediately and review the vendor advisory at https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.4/class-mo-saml-login-validate.php#L118 for technical details; administrators should also audit recent login activity for signs of exploitation.

Vendor Advisory


🟠 [HIGH] ffmpeg/ffmpeg

4 CVEs | CVSS 4.0: 8.5 | AAS 9.9

  • cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

FFmpeg versions 2.7 through 8.1.2 are affected by four vulnerabilities, including multiple issues rated HIGH with a maximum CVSS of 8.5. The most severe is an out-of-bounds write in the TDSC video decoder where a crafted AVI file can trigger heap corruption by manipulating frame dimensions, potentially leading to remote code execution when processing untrusted media files. Organizations and projects that use FFmpeg for media processing should update beyond version 8.1.2 immediately and review the fix at https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c, paying particular attention to any pipelines that handle user-supplied or untrusted video content.

Vendor Advisory


🟠 [HIGH] avada_studio/avada_core

1 CVE | CVSS 3.1: 9.6 | AAS 9.9

  • cpe:2.3:a:avada_studio:avada_core:*:*:*:*:*:*:*:*

The Avada Core plugin for WordPress versions 5.15.6 and earlier contains an unauthenticated cross-site request forgery vulnerability rated CRITICAL at CVSS 9.6. An attacker can exploit this by tricking an authenticated administrator into visiting a malicious page, enabling unauthorized actions to be performed on the WordPress site without the user’s knowledge or consent. Sites running the Avada theme with the Avada Core plugin should update beyond version 5.15.6 immediately and review the Patchstack advisory at https://patchstack.com/database/wordpress/plugin/fusion-core/vulnerability/wordpress-avada-core-plugin-5-15-6-cross-site-request-forgery-csrf-vulnerability for full remediation details.

Vendor Advisory


🟠 [HIGH] bookly/bookly

1 CVE | CVSS 3.1: 9.3 | AAS 9.6

  • cpe:2.3:a:bookly:bookly:*:*:*:*:*:*:*:*

The Bookly appointment booking plugin for WordPress versions 27.7 and earlier contains an unauthenticated SQL injection vulnerability rated CRITICAL at CVSS 9.3. An attacker requires no authentication to exploit this flaw, potentially gaining full read access to the WordPress database including user credentials, customer data, and session tokens. WordPress site administrators using Bookly should update beyond version 27.7 immediately, review the Patchstack advisory at https://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-27-7-sql-injection-vulnerability for details, and audit database activity for signs of compromise.

Vendor Advisory


🟠 [HIGH] mz_automation/libiec61850

3 CVEs | CVSS 4.0: 9.2 | AAS 9.5

  • cpe:2.3:a:mz_automation:libiec61850:*:*:*:*:*:*:*:*

MZ Automation’s libiec61850 library is affected by three vulnerabilities, including multiple issues rated CRITICAL with a maximum CVSS of 9.2. The most severe is a heap-based buffer overflow triggered via a crafted MMS Initiate request, with remote code execution demonstrated when ASLR is disabled and memory corruption or denial of service possible even with ASLR enabled. Organizations using libiec61850 in industrial control systems and SCADA environments should prioritize patching immediately and review the CISA ICS advisory at https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06 for affected versions and mitigation guidance, given the critical nature of OT infrastructure this library typically supports.

Vendor Advisory


🟠 [HIGH] chatwoot/chatwoot

1 CVE | CVSS 4.0: 8.8 | AAS 9.2

  • cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:*

Chatwoot versions prior to 4.16.0 contain an authentication bypass vulnerability in the direct uploads controller rated HIGH at CVSS 8.8. Unauthenticated attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application’s storage backend across any tenant. Organizations running self-hosted or multi-tenant Chatwoot instances should update to version 4.16.0 immediately and review the issue details at https://github.com/chatwoot/chatwoot/issues/15072, along with auditing storage backends for any unauthorized file uploads.

Vendor Advisory


🟠 [HIGH] wpo365/wpo365_|seamless_wordpress+microsoft_integration(wpo365_|_login)

1 CVE | CVSS 3.1: 8.8 | AAS 9.1

  • cpe:2.3:a:wpo365:wpo365_seamless_wordpress_microsoft_integration_wpo365_login:*:*:*:*:*:*:*:*

The WPO365 | Login plugin for WordPress versions up to and including 43.2 contains a cross-site request forgery vulnerability rated HIGH at CVSS 8.8. The nonce verification check is disabled by default due to the ’enable_nonce_check’ option being absent from the default configuration, allowing an attacker to trick an authenticated administrator into submitting a crafted request that modifies the plugin’s settings, potentially compromising the Microsoft 365 integration and site authentication flow. WordPress administrators using WPO365 | Login should update beyond version 43.2 immediately and review the source details at https://plugins.trac.wordpress.org/browser/wpo365-login/tags/43.2/Services/Ajax_Service.php#L805 to understand the scope of impact.

Vendor Advisory