25 vulnerabilities across 15 products scored HIGH or above on July 30, 2026.

  • πŸ”΄ CRITICAL: 1
  • 🟠 HIGH: 24

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-65921 (jfrog/artifactory) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-07-27 bulletin.
  • [UPGRADED] CVE-2026-66014 (jfrog/artifactory) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-07-27 bulletin.
  • [UPGRADED] CVE-2026-65617 (jfrog/artifactory) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-07-27 bulletin.

πŸ”΄ [CRITICAL] somta/juggle

1 CVE | CVSS 4.0: 9.3 | AAS 12.0

  • cpe:2.3:a:somta:juggle:*:*:*:*:*:*:*:*

Somta Juggle through version 1.6.0 is affected by a critical remote code execution vulnerability (CVE-2026-67208, CVSS 9.3). An unauthenticated attacker can reach the exposed H2 database web console at the /h2-console endpoint, log in with default shipped credentials, and execute arbitrary operating system commands, achieving root-level access when running the stock Docker image.

Organizations running Juggle in any environment, particularly in Docker deployments, should treat this as an urgent priority. Until a patched release is available, teams should immediately restrict network access to the /h2-console endpoint, change the default H2 database credentials, and review the vendor advisory at the linked GitHub issue for further guidance.

Vendor Advisory


🟠 [HIGH] solarwinds/web_help_desk

1 CVE | CVSS 3.1: 9.8 | AAS 11.4

  • cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*

SolarWinds Web Help Desk is affected by a critical SAML authentication bypass vulnerability (CVE-2026-28323, CVSS 9.8) that allows attackers to circumvent authentication entirely on instances with SAML 2.0 authentication enabled. Given SolarWinds Web Help Desk’s widespread use in enterprise IT service management and the severity of a full authentication bypass, this issue demands immediate attention from any organization relying on SAML-based single sign-on for their helpdesk environment.

Administrators should consult the SolarWinds security configuration advisory immediately, apply any available patches or mitigations, and audit authentication logs for signs of unauthorized access. Organizations unable to patch promptly should consider temporarily disabling SAML 2.0 authentication in favor of an alternative method until a fix is in place.

Vendor Advisory


🟠 [HIGH] vmware/vcenter

1 CVE | CVSS 3.1: 9.8 | AAS 11.4

  • cpe:2.3:a:vmware:vcenter:*:*:*:*:*:*:*:*

VMware vCenter Server is affected by a critical authentication bypass vulnerability in the VMware Directory Service (CVE-2026-59309, CVSS 9.8) that allows an attacker with network access to completely bypass authentication and gain unauthorized access to the vCenter management platform. Given that vCenter serves as the centralized control plane for VMware virtualized environments across most enterprise data centers, successful exploitation could grant an attacker full administrative control over an organization’s entire virtual infrastructure.

All organizations running VMware vCenter should treat this as an emergency priority, review the Broadcom security advisory immediately, and apply the available patch without delay. In the interim, teams should restrict network access to vCenter management interfaces to trusted administrative networks only and monitor Directory Service logs for any anomalous authentication activity.

Vendor Advisory


🟠 [HIGH] vmware/vcenter_server

1 CVE | CVSS 3.1: 9.8 | AAS 11.4

  • cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*

VMware vCenter Server is affected by a critical directory traversal vulnerability in its Syslog server component (CVE-2026-59310, CVSS 9.8) that enables an attacker with network access to achieve arbitrary code execution. As vCenter Server is the central management hub for VMware virtualized environments widely deployed across enterprises, this vulnerability poses a severe risk of full infrastructure compromise.

Organizations running vCenter Server should apply the patch referenced in the Broadcom security advisory immediately. Until patching is complete, restrict network access to vCenter management interfaces to trusted administrative segments only and monitor for unusual activity targeting the Syslog service. Note that this vulnerability is covered in the same advisory as CVE-2026-59309, so teams should ensure both issues are addressed in a single remediation effort.

Vendor Advisory


🟠 [HIGH] ibm/app_connect_enterprise

2 CVEs | CVSS 3.1: 9.8 | AAS 10.9

  • cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:* (>= 12.0.1.0, < 12.0.12.28)
  • cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:* (>= 13.0.1.0, < 13.0.7.3)

IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2 are affected by 2 vulnerabilities (CVE-2026-15435, CVE-2026-14522, max CVSS 9.8), including at least one critical directory traversal flaw that allows a remote attacker to write arbitrary files on the system via specially crafted URL requests containing path traversal sequences. Organizations using App Connect Enterprise for integration workflows should treat this as a high priority given the potential for remote, unauthenticated file manipulation.

Administrators should consult the IBM support advisory and upgrade to patched versions immediately. Teams unable to patch right away should review network access controls to limit exposure of App Connect Enterprise interfaces and monitor for suspicious requests containing directory traversal patterns.

Vendor Advisory


🟠 [HIGH] ibm/langflow_oss

3 CVEs | CVSS 3.1: 9.9 | AAS 10.9

  • cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:* (>= 1.0.0, < 1.10.2)
  • cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:* (>= 1.0.0)

IBM Langflow OSS versions 1.0.0 through 1.10.1 are affected by 3 vulnerabilities (CVE-2026-12940, CVE-2026-12946, CVE-2026-13435, max CVSS 9.9), including at least one critical unauthenticated remote code execution flaw via environment variable injection in the Model Context Protocol stdio launcher. An incomplete blocklist of dangerous environment variables such as SHELLOPTS, BASHOPTS, and PS4 allows remote attackers to achieve code execution without any authentication, making this an immediate concern for any organization deploying Langflow for AI workflow orchestration.

Administrators should consult the IBM support advisory and upgrade to a patched version without delay. Any internet-facing Langflow instances should be taken offline or placed behind strict access controls until remediation is complete, and teams should review logs for signs of exploitation targeting the MCP launcher.

Vendor Advisory


🟠 [HIGH] vmware/cloud_foundation

1 CVE | CVSS 3.1: 9.3 | AAS 10.8

  • cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*

VMware Cloud Foundation is affected by a critical out-of-bounds write vulnerability in the VMXNET3 virtual network adapter on the underlying ESXi hypervisor (CVE-2026-47876, CVSS 9.3), which allows an attacker with local administrative privileges on a guest virtual machine to escape the VM and execute code on the host. This is a VM escape vulnerability, meaning a compromised guest can lead to full hypervisor compromise, putting all co-hosted workloads at risk across Cloud Foundation deployments.

Organizations running VMware Cloud Foundation or ESXi with VMXNET3 adapters should apply the patch from the Broadcom security advisory as an emergency priority. As a temporary mitigation, teams may consider switching affected VMs to a non-VMXNET3 adapter type where operationally feasible, and should audit VM administrator access to reduce exposure until patching is complete.

Vendor Advisory


🟠 [HIGH] apache_software_foundation/apache_jspwiki

2 CVEs | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:apache:apache_jspwiki:*:*:*:*:*:*:*:* (< 2.12.4)

Apache JSPWiki versions up to 2.12.3 are affected by 2 vulnerabilities (CVE-2026-28812, CVE-2026-28813, max CVSS 9.8), including at least one critical flaw in the UserManager component that allows attackers to impersonate other users and escalate privileges due to missing authorization checks. Organizations using JSPWiki for internal or external-facing wikis should act promptly, as user impersonation can lead to unauthorized access to sensitive content and administrative takeover.

Administrators should upgrade to Apache JSPWiki version 2.12.4 or newer, which addresses both issues. Until the upgrade is applied, teams should review user access logs for signs of suspicious authentication or privilege escalation activity.

Vendor Advisory


🟠 [HIGH] avitorio/outstatic

1 CVE | CVSS 3.1: 9.1 | AAS 10.5

  • cpe:2.3:a:outstatic:outstatic:*:*:*:*:*:*:*:* (< 2.1.10)

Outstatic CMS versions 2.1.9 and earlier are affected by a critical hardcoded JWT signing secret vulnerability (CVE-2026-52539, CVSS 9.1) that allows unauthenticated remote attackers to forge administrative session tokens when the OST_TOKEN_SECRET environment variable is not explicitly configured. Since the default secret is publicly visible in the source code repository, any Outstatic deployment relying on the default value is trivially exploitable, granting full administrative access to the CMS.

Organizations running Outstatic should immediately verify that a strong, unique OST_TOKEN_SECRET environment variable is set in their deployment configuration and invalidate all existing sessions. Administrators should also upgrade to a patched version when available and audit access logs for any unauthorized administrative activity.

Vendor Advisory


🟠 [HIGH] gladinet/centrestack

5 CVEs | CVSS 4.0: 9.3 | AAS 10.5

  • cpe:2.3:a:gladinet:centrestack:*:*:*:*:*:*:*:*

Gladinet CentreStack versions before 17.5 are affected by 5 vulnerabilities (CVE-2026-54363, CVE-2026-54367, CVE-2026-54368, CVE-2026-54365, CVE-2026-54366, max CVSS 9.3), including multiple critical flaws stemming from a hardcoded cryptographic key that allows unauthenticated attackers to forge encrypted authentication tokens, call privileged API endpoints, and obtain domain administrator credentials for complete system takeover. Because the static key is shared across all installations, every unpatched CentreStack deployment is equally vulnerable regardless of configuration.

Organizations using CentreStack for file sharing and remote access should upgrade to version 17.5 or newer immediately and rotate any cryptographic keys or administrator credentials that may have been compromised. Teams should also audit API access logs for suspicious use of x-glad-auth headers or calls to sensitive endpoints such as acquiretenantbackuptoken.

Vendor Advisory


🟠 [HIGH] rails/rails

1 CVE | CVSS 4.0: 9.5 | AAS 10.3

  • cpe:2.3:a:rails:rails:*:*:*:*:*:*:*:*

Ruby on Rails Action Pack versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1 are affected by a critical vulnerability in Active Storage (CVE-2026-66066, CVSS 9.5) where unsafe libvips operations are not disabled for untrusted content, allowing an unauthenticated attacker to upload a crafted image file and read arbitrary files accessible to the Rails process. A proof-of-concept exploit is publicly available, and any Rails application configured to use libvips that accepts image uploads from untrusted users is at risk of server-side file disclosure.

Teams running affected Rails versions should upgrade to 7.2.3.2, 8.0.5.1, or 8.1.3.1 immediately. If patching is not immediately possible, consider temporarily switching the image processing backend away from libvips or restricting image upload functionality until the fix is applied.

Vendor Advisory


🟠 [HIGH] adobe/adobe_campaign_classic

1 CVE | CVSS 3.1: 10.0 | AAS 10.2

  • cpe:2.3:a:adobe:adobe_campaign_classic:*:*:*:*:*:*:*:*

Adobe Campaign Classic is affected by a maximum-severity incorrect authorization vulnerability (CVE-2026-48449, CVSS 10.0) that allows arbitrary code execution in the context of the current user without any user interaction, with scope change indicating potential impact beyond the vulnerable component. Given Campaign Classic’s role as a core enterprise marketing automation platform handling sensitive customer data and communications, this vulnerability poses an extreme risk to affected organizations.

Administrators should immediately apply the patch detailed in Adobe security bulletin APSB26-114 and review system logs for any signs of unauthorized access or anomalous execution activity. Organizations unable to patch immediately should restrict network access to Campaign Classic instances and evaluate taking them offline until remediation is complete.

Vendor Advisory


🟠 [HIGH] ase/admin_and_site_enhancements_(ase)_pro

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:ase:admin_and_site_enhancements_ase_pro:*:*:*:*:*:*:*:*

The Admin and Site Enhancements (ASE) Pro plugin for WordPress versions up to and including 8.9.0 is affected by a critical remote code execution vulnerability (CVE-2026-16610, CVSS 9.8) where unauthenticated attackers can execute arbitrary code through unsanitized input that reaches an eval() call in the recursive_html function, with authentication and CAPTCHA protections both bypassable. Any WordPress site running the ASE Pro plugin is at immediate risk of full server compromise.

Site administrators should update the ASE Pro plugin to a patched version immediately or deactivate it until a fix is applied. Teams should also review web server logs for suspicious POST requests targeting frontend form save handlers, as exploitation requires no authentication and is trivially achievable.

Vendor Advisory


🟠 [HIGH] webpros/plesk

1 CVE | CVSS 3.1: 9.9 | AAS 10.1

  • cpe:2.3:a:webpros:plesk:*:*:*:*:*:*:*:*

WebPros Plesk is affected by a critical SQL injection vulnerability in its XML-RPC API (CVE-2026-58046, CVSS 9.9) that allows any remote authenticated user, even with low privileges, to read arbitrary data from the Plesk database and achieve full compromise of the hosting control panel. Given Plesk’s widespread use as a web hosting management platform often controlling multiple customer sites, databases, and email services, exploitation could cascade into a breach of every hosted property on the server.

Administrators should apply the patch referenced in the Plesk support advisory immediately and audit XML-RPC API access logs for suspicious queries. Any low-privileged Plesk accounts that are unnecessary or unrecognized should be disabled, and teams should consider restricting API access to trusted networks until remediation is confirmed.

Vendor Advisory


🟠 [HIGH] ibm/websphere_application_server

3 CVEs | CVSS 3.1: 8.5 | AAS 10.0

  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* (>= 8.5.0)
  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* (>= 9.0.0)
  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* (>= 8.5)
  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* (>= 9.0)
  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* (>= 17.0.0.3, < 26.0.0.8)

IBM WebSphere Application Server versions 8.5 and 9.0 are affected by 3 vulnerabilities (CVE-2026-11536, CVE-2026-10842, CVE-2026-9322, max CVSS 8.5), including at least one remote code execution flaw in the SOAP/JMX connector. WebSphere Application Server remains widely deployed in enterprise Java environments, and exploitation of the SOAP/JMX connector could allow attackers to execute arbitrary code on application servers hosting critical business workloads.

Administrators should consult the IBM support advisory and apply the available patches promptly. As an interim measure, teams should restrict network access to SOAP and JMX management ports to trusted administrative hosts only and monitor for unusual connector activity.

Vendor Advisory