33 vulnerabilities across 13 products scored HIGH or above on July 27, 2026.
๐ด CRITICAL: 3 ๐ HIGH: 30 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-63770 (glanceapp/glance) โ F1: theoretical โ poc, AAS: 9.0 โ 11.5 (HIGH โ HIGH). Originally in 2026-07-20 bulletin. ๐ด [CRITICAL] arista/velocloud_orchestrator 1 CVE | CVSS 4.0: 10.0 | AAS 14.3
cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:* (>= 5.2.0, < 5.2.3.14) cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:* (>= 6.1.0, < 6.1.3.4) cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:* (>= 6.4.0, < 6.4.2.4) Arista VeloCloud Orchestrator (VCO) on-premises deployments are affected by a critical vulnerability (CVE-2026-16812, CVSS 10.0) that exposes privileged internal functionality to remote attackers. Successful exploitation can fully compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages. This vulnerability is being exploited in the wild.
...