12 vulnerabilities across 8 products scored HIGH or above on July 24, 2026.

  • 🟠 HIGH: 12

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-63770 (glanceapp/glance) β€” F1: theoretical β†’ poc, AAS: 9.0 β†’ 11.5 (HIGH β†’ HIGH). Originally in 2026-07-20 bulletin.

🟠 [HIGH] microsoft/microsoft_account

1 CVE | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:microsoft:microsoft_account:*:*:*:*:*:*:*:*

Microsoft Account is affected by a critical remote code execution vulnerability (CVE-2026-56165, CVSS 9.8) caused by a heap-based buffer overflow that allows an unauthorized attacker to execute arbitrary code over the network. This vulnerability is considered exploitable, making it an urgent priority for any organization relying on Microsoft Account services. Security teams should review the vendor advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56165 and apply available patches or mitigations immediately.

Vendor Advisory


🟠 [HIGH] microsoft/azure_kubernetes_service

1 CVE | CVSS 3.1: 10.0 | AAS 10.3

  • cpe:2.3:a:microsoft:azure_kubernetes_service:*:*:*:*:*:*:*:*

Microsoft Azure Kubernetes Service is affected by a critical vulnerability (CVE-2026-56163, CVSS 10.0) where missing authentication on a critical function allows an unauthorized attacker to elevate privileges remotely. With the maximum possible severity rating and confirmed exploitability, this poses an immediate threat to any organization running workloads on AKS. Security teams should consult the vendor advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56163 and apply patches or mitigations without delay.

Vendor Advisory


🟠 [HIGH] microsoft/microsoft_exchange_online

1 CVE | CVSS 3.1: 10.0 | AAS 10.3

  • cpe:2.3:a:microsoft:microsoft_exchange_online:*:*:*:*:*:*:*:*

Microsoft Exchange Online is affected by a critical authentication bypass vulnerability (CVE-2026-56191, CVSS 10.0) that allows an unauthorized attacker to tamper with data remotely due to improper authentication controls. Given the maximum severity rating and confirmed exploitability, this is an urgent concern for any organization using Exchange Online for email and collaboration. Security teams should immediately review the vendor advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56191 and follow any mitigation guidance provided by Microsoft.

Vendor Advisory


🟠 [HIGH] exim/exim

1 CVE | CVSS 3.1: 8.4 | AAS 10.1

  • cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*

Exim mail transfer agent versions prior to 4.99.5 are affected by a directory traversal vulnerability (CVE-2026-66140, CVSS 8.4) that allows an attacker to access files outside the mail spool directory and escalate privileges through mishandled queue-name arguments. This is exploitable and a serious concern for any organization running Exim as its MTA, which includes a large share of internet-facing mail servers. Administrators should upgrade to Exim 4.99.5 or later immediately and review the advisory at https://openwall.com/lists/oss-security/2026/07/22/9 for further details.

Vendor Advisory


🟠 [HIGH] ffmpeg/ffmpeg

4 CVEs | CVSS 4.0: 8.7 | AAS 10.1

  • cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

FFmpeg through version 8.1.2 is affected by 4 vulnerabilities (CVSS 8.7), including multiple memory corruption issues such as a signed integer overflow in the MACE6 audio decoder that enables heap corruption via crafted media files. These flaws are considered exploitable and are relevant to any organization using FFmpeg for media processing, transcoding, or in products that embed it as a dependency. Teams should update to a build containing the fix commit or later, and review the vendor advisory at https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718 for patch details.

Vendor Advisory


🟠 [HIGH] microsoft/microsoft_365_copilot

1 CVE | CVSS 3.1: 9.9 | AAS 9.2

  • cpe:2.3:a:microsoft:microsoft_365_copilot:*:*:*:*:*:*:*:*

Microsoft 365 Copilot is affected by a critical deserialization vulnerability (CVE-2026-50517, CVSS 9.9) that allows an authorized attacker to execute arbitrary code remotely by exploiting untrusted data handling. With near-maximum severity and confirmed exploitability, this is an urgent priority for any organization with M365 Copilot deployed across its environment. Security teams should review the vendor advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50517 and apply any available patches or mitigations as soon as possible.

Vendor Advisory


🟠 [HIGH] libssh2/libssh2

2 CVEs | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*

libssh2 through version 1.11.1 is affected by 2 vulnerabilities (CVSS 8.7), including multiple heap corruption issues such as a double-free in the sftp_open() function that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. These flaws are exploitable and a concern for any organization using libssh2 directly or through the many applications and tools that embed it as a dependency. Teams should update to a build containing commit 5e47761 or later, and review the advisory at https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0 for details.

Vendor Advisory


🟠 [HIGH] kortix-ai/suna

1 CVE | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:kortix-ai:suna:*:*:*:*:*:*:*:*

Kortix AI Suna before version 0.9.102 is affected by a broken access control vulnerability (CVE-2026-66027, CVSS 8.7) in the message queue API that allows authenticated attackers to read, delete, and inject prompts into other users’ sessions due to missing ownership and account isolation checks. This is exploitable and poses a serious risk to any organization running Suna, as attackers can manipulate AI agent sessions belonging to other users. Teams should upgrade to Suna 0.9.102 or later immediately and review the advisory at https://github.com/geo-chen/oss/blob/main/suna.md for full details.

Vendor Advisory