148 vulnerabilities across 15 products scored HIGH or above on July 14, 2026.
🔴 CRITICAL: 6 🟠 HIGH: 142 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-57219 (rabbitmq/rabbitmq_server) — F1: theoretical → itw, AAS: 10.9 → 13.7 (HIGH → CRITICAL). Originally in 2026-07-10 bulletin. [UPGRADED] CVE-2026-55884 (tilt-dev/tilt) — F1: exploitable → itw, AAS: 10.3 → 13.0 (HIGH → CRITICAL). Originally in 2026-07-10 bulletin. [UPGRADED] CVE-2026-55879 (openreplay/openreplay) — F1: exploitable → itw, AAS: 10.3 → 13.3 (HIGH → CRITICAL). Originally in 2026-07-10 bulletin. [UPGRADED] CVE-2026-54003 (getkirby/kirby) — F1: theoretical → poc, AAS: 11.8 → 11.5 (HIGH → HIGH). Originally in 2026-07-09 bulletin. [UPGRADED] CVE-2026-59827 (metabase/metabase) — F1: exploitable → itw, AAS: 11.2 → 13.1 (HIGH → CRITICAL). Originally in 2026-07-09 bulletin. [UPGRADED] CVE-2026-59148 (mockoon/mockoon) — F1: exploitable → itw, AAS: 9.6 → 12.6 (HIGH → CRITICAL). Originally in 2026-07-09 bulletin. [UPGRADED] CVE-2026-59858 (vim/vim) — F1: exploitable → itw, AAS: 9.3 → 12.3 (HIGH → CRITICAL). Originally in 2026-07-09 bulletin. [UPGRADED] CVE-2026-55207 (pimcore/pimcore) — F1: theoretical → poc, AAS: 9.1 → 11.6 (HIGH → HIGH). Originally in 2026-07-09 bulletin. [UPGRADED] CVE-2026-57480 (parse-community/parse-server) — F1: theoretical → poc, AAS: 9.8 → 12.3 (HIGH → CRITICAL). Originally in 2026-07-08 bulletin. [UPGRADED] CVE-2026-59705 (mem0ai/mem0) — F1: exploitable → itw, AAS: 10.7 → 12.9 (HIGH → CRITICAL). Originally in 2026-07-07 bulletin. [UPGRADED] CVE-2026-53511 (kovidgoyal/calibre) — F1: exploitable → itw, AAS: 9.4 → 12.4 (HIGH → CRITICAL). Originally in 2026-07-07 bulletin. 🔴 [CRITICAL] adobe/coldfusion 1 CVE | CVSS 3.1: 10.0 | AAS 14.3
...