1 vulnerability across 1 product scored HIGH or above on July 25, 2026.
- ๐ HIGH: 1
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-63770 (glanceapp/glance) โ F1: theoretical โ poc, AAS: 9.0 โ 11.5 (HIGH โ HIGH). Originally in 2026-07-20 bulletin.
๐ [HIGH] openremote/openremote
1 CVE | CVSS 4.0: 9.3 | AAS 9.7
cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:*
OpenRemote โ Authentication Bypass in Console Registration API
OpenRemote versions prior to 1.26.2 are affected by one high-severity vulnerability (CVSS 9.3) that allows unauthenticated attackers to bypass authentication in the console registration API and overwrite existing console assets by supplying a known asset identifier. This can be exploited to hijack push notification tokens and console metadata, enabling attackers to redirect notifications to attacker-controlled devices or deny delivery to legitimate consoles entirely.
Organizations running OpenRemote for IoT asset management or building automation should treat this as urgent. Update to version 1.26.2 or later immediately. Review the vendor advisory at the linked GitHub Security Advisory for full details and assess whether any console assets may have been tampered with prior to patching.
- ๐ CVE-2026-66013 (CVSS 4.0: 9.3)