33 vulnerabilities across 13 products scored HIGH or above on July 27, 2026.
- π΄ CRITICAL: 3
- π HIGH: 30
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-63770 (glanceapp/glance) β F1: theoretical β poc, AAS: 9.0 β 11.5 (HIGH β HIGH). Originally in 2026-07-20 bulletin.
π΄ [CRITICAL] arista/velocloud_orchestrator
1 CVE | CVSS 4.0: 10.0 | AAS 14.3
cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*(>= 5.2.0, < 5.2.3.14)cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*(>= 6.1.0, < 6.1.3.4)cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*(>= 6.4.0, < 6.4.2.4)
Arista VeloCloud Orchestrator (VCO) on-premises deployments are affected by a critical vulnerability (CVE-2026-16812, CVSS 10.0) that exposes privileged internal functionality to remote attackers. Successful exploitation can fully compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages. This vulnerability is being exploited in the wild.
Organizations running on-premises VCO should treat this as an emergency priority. Hosted and dedicated VCO instances have already been patched by Arista. On-prem administrators should immediately consult the vendor advisory at the link above and apply available patches or mitigations without delay.
- π΄ CVE-2026-16812 (CVSS 4.0: 10.0)
π΄ [CRITICAL] pheditor/pheditor
2 CVEs | CVSS 3.1: 9.9 | AAS 12.9
cpe:2.3:a:pheditor:pheditor:*:*:*:*:*:*:*:*
Pheditor, a single-file PHP editor and file manager, is affected by 2 critical vulnerabilities (including CVE-2026-55579 and CVE-2026-48030, max CVSS 9.9) impacting versions 2.0.1 through 2.0.5. The most severe issue involves a hardcoded default password with no forced change on first login, granting attackers full access to file editing, uploads, and terminal functionality, enabling arbitrary file read/write and remote code execution. Functional exploit code is available for at least one of these vulnerabilities.
Any organization running Pheditor in this version range should upgrade to version 2.0.6 immediately via the vendor’s GitHub release page. Given the trivial exploitability and full system compromise potential, exposed instances should be considered at high risk of active exploitation.
- π΄ CVE-2026-55579 (CVSS 3.1: 9.8)
- π CVE-2026-48030 (CVSS 3.1: 9.9)
π΄ [CRITICAL] jetbrains/teamcity
1 CVE | CVSS 3.1: 9.8 | AAS 12.3
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
JetBrains TeamCity versions prior to 2026.1.3 and 2025.11.7 are affected by a critical unauthenticated remote code execution vulnerability (CVE-2026-63077, CVSS 9.8) in the agent polling protocol. This flaw requires no authentication to exploit, making any internet-exposed or internally accessible TeamCity instance a high-value target for attackers seeking to compromise CI/CD infrastructure and software supply chains.
Organizations running affected versions should upgrade to TeamCity 2026.1.3 or 2025.11.7 immediately and review the vendor advisory at the JetBrains security page. Given TeamCity’s role in build and deployment pipelines, compromise could have cascading impact across downstream software artifacts.
- π΄ CVE-2026-63077 (CVSS 3.1: 9.8)
π [HIGH] theopaid/facil.io
3 CVEs | CVSS 4.0: 8.7 | AAS 11.6
cpe:2.3:a:boazsegev:facil.io:*:*:*:*:*:*:*:*(>= 0.6.0)cpe:2.3:a:theopaid:facil.io:*:*:*:*:*:*:*:*
facil.io versions 0.6.0 through 0.7.6 are affected by 3 high-severity vulnerabilities (including CVE-2026-66730, CVE-2026-66729, and CVE-2026-66731, max CVSS 8.7), with the lead issue being a denial-of-service flaw in the multipart body parser. An unauthenticated remote attacker can permanently freeze worker processes at 100% CPU by sending a crafted multipart/form-data request with a partial closing boundary, causing an infinite parsing loop. Proof-of-concept exploit code is publicly available for at least one of these issues.
Teams using facil.io as an embedded HTTP framework in their applications should check their dependency versions immediately and monitor the vendor’s GitHub advisory for patches. Until a fix is applied, consider implementing request filtering or rate limiting on multipart uploads to reduce exposure.
- π CVE-2026-66730 (CVSS 4.0: 8.7)
- π CVE-2026-66729 (CVSS 4.0: 8.7)
- π CVE-2026-66731 (CVSS 4.0: 8.7)
π [HIGH] apache/thrift
9 CVEs | CVSS 4.0: 9.3 | AAS 11.6
cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:*(< 0.24.0)
Apache Thrift versions prior to 0.24.0 are affected by 9 vulnerabilities (including CVE-2026-55971, CVE-2026-48144, CVE-2026-55969, and others, max CVSS 9.3), with the lead issue being a heap-based buffer overflow in the C++ bindings. These flaws span multiple aspects of the Thrift framework and at least one is considered readily exploitable, posing significant risk to any application relying on Thrift for cross-language service communication.
Organizations using Apache Thrift in any language binding should upgrade to version 0.24.0 immediately. Given the wide deployment of Thrift as an RPC framework across microservices architectures, teams should audit their dependency trees for both direct and transitive usage and consult the Apache advisory for full details.
- π CVE-2026-55971 (CVSS 4.0: 9.3)
- π CVE-2026-48144 (CVSS 4.0: 9.1)
- π CVE-2026-55969 (CVSS 4.0: 8.7)
- π CVE-2026-43871 (CVSS 4.0: 8.7)
- π CVE-2026-58389 (CVSS 4.0: 8.7)
- π CVE-2026-58662 (CVSS 4.0: 8.7)
- π CVE-2026-55968 (CVSS 4.0: 8.7)
- π CVE-2026-48586 (CVSS 4.0: 8.7)
- π CVE-2026-48145 (CVSS 4.0: 8.2)
π [HIGH] erlang/otp
5 CVEs | CVSS 4.0: 9.1 | AAS 10.7
cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= OTP-27.0, < OTP-27.3.4)cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= OTP-28.0, < OTP-28.0.1)cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= OTP-26.0, < OTP-26.2.5.12)cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= 27.0, < 27.3.4)cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*(>= 28.0, < 28.0.1)
Erlang/OTP is affected by 5 high-severity vulnerabilities (including CVE-2026-55953, CVE-2026-58227, CVE-2026-59250, and others, max CVSS 9.1) impacting the SSL/TLS implementation. The lead issue is a failure in the TLS 1.2 and DTLS client to verify that the server-selected cipher suite was actually offered by the client, potentially allowing a malicious server or man-in-the-middle attacker to force use of a weak or unintended cipher suite. While exploitation is currently theoretical, the breadth of these flaws across Erlang’s core TLS stack warrants prompt attention.
Organizations running Erlang/OTP-based systems, including platforms like RabbitMQ, CouchDB, and custom BEAM applications, should review the vendor advisory and upgrade to patched OTP releases as soon as available. Any service relying on Erlang’s built-in SSL module for TLS 1.2 or DTLS connections should be evaluated for exposure.
- π CVE-2026-55953 (CVSS 4.0: 9.1)
- π CVE-2026-58227 (CVSS 4.0: 8.7)
- π CVE-2026-59250 (CVSS 4.0: 8.3)
- π CVE-2026-54890 (CVSS 4.0: 8.2)
- π CVE-2026-59251 (CVSS 4.0: 8.7)
π [HIGH] strategy11_team/awp_classifieds
1 CVE | CVSS 3.1: 9.3 | AAS 10.3
cpe:2.3:a:strategy11:awp_classifieds:*:*:*:*:*:*:*:*(< 4.4.8)
The AWP Classifieds plugin for WordPress versions 4.4.7 and earlier is affected by a high-severity unauthenticated SQL injection vulnerability (CVE-2026-59550, CVSS 9.3). This flaw requires no authentication to exploit, allowing remote attackers to directly query and extract data from the WordPress database, potentially compromising user credentials, site content, and other sensitive information.
WordPress site administrators using the AWP Classifieds plugin should update beyond version 4.4.7 immediately or deactivate the plugin until a patch is applied. Review the Patchstack advisory for full details and consider auditing database logs for signs of exploitation.
- π CVE-2026-59550 (CVSS 3.1: 9.3)
π [HIGH] ruben_garcia/gamipress
1 CVE | CVSS 3.1: 9.3 | AAS 10.3
cpe:2.3:a:ruben_garcia:gamipress:*:*:*:*:*:*:*:*(< 7.9.8)
The GamiPress plugin for WordPress versions 7.9.7 and earlier is affected by a high-severity unauthenticated SQL injection vulnerability (CVE-2026-59538, CVSS 9.3). Since no authentication is required, any site running an affected version is exposed to remote database extraction, potentially compromising user accounts, credentials, and all stored site data.
WordPress administrators using GamiPress should update to a patched version immediately or disable the plugin until a fix is applied. Review the Patchstack advisory for technical details and audit database activity for indicators of exploitation.
- π CVE-2026-59538 (CVSS 3.1: 9.3)
π [HIGH] programmervuln/cveadvisory-
1 CVE | CVSS 3.1: 8.8 | AAS 9.6
cpe:2.3:a:programmervuln:cveadvisory-:*:*:*:*:*:*:*:*
LibRaw version 0.21 is affected by a high-severity buffer overflow vulnerability (CVE-2026-51235, CVSS 8.8) in the stretch() and fuji_rotate() functions used during raw image processing. An attacker could exploit this flaw by supplying a crafted raw image file, potentially achieving code execution in any application that relies on LibRaw for image decoding, including photo editors, media libraries, and file preview services.
Organizations and developers using LibRaw, either directly or as a dependency in image processing workflows, should check for updated versions at the vendor’s site and patch promptly. Given LibRaw’s widespread use as an embedded library, teams should also audit their software supply chains for transitive dependencies on the affected version.
- π CVE-2026-51235 (CVSS 3.1: 8.8)
π [HIGH] jfrog/artifactory
3 CVEs | CVSS 3.1: 8.8 | AAS 9.2
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:*
JFrog Artifactory is affected by 3 high-severity vulnerabilities (including CVE-2026-65921, CVE-2026-66014, and CVE-2026-65617, max CVSS 8.8), with the lead issue being a path traversal weakness in archive extraction handling that allows malicious archive entries to be written outside the intended build artifacts directory. Given Artifactory’s central role in software supply chains as a binary repository manager, exploitation could enable an attacker to overwrite critical files or inject malicious artifacts into build pipelines.
Organizations running self-managed Artifactory instances should consult the JFrog release documentation immediately and upgrade to the latest patched version. Due to the supply chain implications, teams should also audit recently published artifacts for signs of tampering.
- π CVE-2026-65921 (CVSS 3.1: 8.8)
- π CVE-2026-66014 (CVSS 3.1: 8.8)
- π CVE-2026-65617 (CVSS 3.1: 8.8)
π [HIGH] apple/macos
4 CVEs | CVSS 3.1: 7.8 | AAS 9.1
cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:*
Apple macOS is affected by 4 high-severity vulnerabilities (including CVE-2026-43749, CVE-2026-39874, CVE-2026-43698, and CVE-2026-39875, max CVSS 7.8), with the lead issue being a path validation flaw that allows a malicious application to escalate privileges to root. These vulnerabilities affect multiple macOS releases and have been fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Organizations managing macOS fleets should prioritize deploying these updates immediately through their endpoint management systems. Local privilege escalation to root represents a significant risk in enterprise environments, particularly on shared or developer workstations.
- π CVE-2026-43749 (CVSS 3.1: 7.8)
- π CVE-2026-39874 (CVSS 3.1: 7.8)
- π CVE-2026-43698 (CVSS 3.1: 7.8)
- π CVE-2026-39875 (CVSS 3.1: 7.8)
π [HIGH] nitroshare/nitroshare-desktop
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:nitroshare:nitroshare-desktop:*:*:*:*:*:*:*:*
NitroShare Desktop through version 0.3.4 is affected by a high-severity path traversal vulnerability (CVE-2026-66050, CVSS 8.7) in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files to any location accessible by the current user. By crafting malicious filenames in transfer headers, an attacker can place files in sensitive locations such as the Windows Startup folder, enabling persistent code execution without any user interaction.
Organizations with NitroShare Desktop deployed on internal networks should remove or disable the application immediately, as the project appears unmaintained and no patch is currently available. Any machine running NitroShare on a shared or untrusted network segment should be treated as potentially exposed.
- π CVE-2026-66050 (CVSS 4.0: 8.7)
π [HIGH] thorsten/phpmyfaq
1 CVE | CVSS 4.0: 9.4 | AAS 9.0
cpe:2.3:a:thorsten:phpmyfaq:*:*:*:*:*:*:*:*
phpMyFAQ versions prior to 4.1.6 are affected by a high-severity remote code execution vulnerability (CVE-2026-66398, CVSS 9.4) that allows authenticated administrators with configuration and attachment privileges to write arbitrary PHP files to the application root. By uploading a malicious ZIP archive as an attachment and manipulating the updater configuration path, an attacker with admin access can achieve full code execution as the web server user.
Organizations running phpMyFAQ should upgrade to version 4.1.6 immediately and review the GitHub security advisory for full details. While exploitation requires administrative credentials, compromised admin accounts or insider threats make this a serious risk, and teams should audit admin account access and enable multi-factor authentication where possible.
- π CVE-2026-66398 (CVSS 4.0: 9.4)