● Daily security briefing
Sunday, July 5, 2026
On July 5, 2026, there were no new advisories from CERT or PSIRT, and the day saw the publication of 86 CVEs. Among the notable vulnerabilities, CVE-2026-9085 and CVE-2026-14721 both received a high severity rating of 8.8, indicating critical access control issues in TUBITAK B. Other significant vulnerabilities include CVE-2026-12250 with a CVSS score of 7.9, related to sensitive information exposure in TUBITAK BILGEM Software, and several others in the 7.3 to 7.8 range affecting various software projects. Security teams should prioritize reviewing these vulnerabilities to mitigate potential risks.
12 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- highCVE-2026-9085CVSS 8.8Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allo
- highCVE-2026-14721CVSS 8.8A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoi
- highCVE-2026-12250CVSS 7.9Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavation. This iss
- highCVE-2026-6509CVSS 7.8Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from <=
- highCVE-2026-14764CVSS 7.3A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Manageme
- highCVE-2026-14763CVSS 7.3A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations P
- highCVE-2026-14770CVSS 7.3A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_room.php. Performing a manipulation of the a
- highCVE-2026-14768CVSS 7.3A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument loc
- highCVE-2026-14762CVSS 7.3A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Mana
- highCVE-2026-14756CVSS 7.3A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component
- highCVE-2026-14755CVSS 7.3A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of
- highCVE-2026-14769CVSS 7.3A security vulnerability has been detected in code-projects Real State Services 1.0. This issue affects some unknown processing of the file /pay.php. Such manipulation of the argum