● Daily security briefing
Monday, July 6, 2026
Today's security advisory activity included 199 advisories from CERT/PSIRT, with no new additions to the Known Exploited Vulnerabilities (KEV) list. Significant updates were issued for vulnerabilities in Apache Camel, the Linux Kernel, Eclipse Jetty, Golang Go, Microsoft Windows, and Google Chrome, all categorized as high severity. Notable CVEs published today include several critical vulnerabilities, such as CVE-2026-48316 affecting ColdFusion, and GHSA-vjc7-jrh9-9j86, which involves unauthenticated access in 9router. Other critical vulnerabilities include issues in Langroid, Crawl4AI, and Plesk XML API, highlighting the need for immediate attention from security teams.
12 critical12 highacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highcert-bund[UPDATE] [high] Apache Camel (Neo4j): Vulnerability allows data manipulation
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities allow denial of service
- highcert-bund[UPDATE] [high] Eclipse Jetty: Multiple vulnerabilities allow Denial of Service
- highcert-bund[UPDATE] [high] Golang Go: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Microsoft Windows and Windows Server: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[UPDATE] [high] Apache Camel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Google Chrome: Multiple vulnerabilities allow unspecified attack
- highcert-bund[UPDATE] [high] http/2 implementations: Vulnerability allows denial of service
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Apache Camel: Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVSS 10GHSA-vjc7-jrh9-9j86: 9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
- criticalCVE-2026-54769CVSS 10GHSA-q9p7-wqxg-mrhc: Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
- criticalCVE-2026-48316CVSS 10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the curre
- criticalCVE-2026-57572CVSS 10Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromi
- criticalCVE-2026-48614CVSS 9.9An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root an
- criticalCVE-2026-55500CVSS 9.9GHSA-qvfm-67h2-2qfx: 9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
- criticalCVE-2026-34038CVSS 9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability
- criticalCVE-2026-46454CVSS 9.8Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without a
- criticalCVE-2026-9181CVSS 9.8ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could
- criticalCVE-2026-46456CVSS 9.8Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Camel Exchange through a componen
- criticalCVE-2026-48204CVSS 9.8Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation
- criticalCVE-2026-46455CVSS 9.8Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keyc
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
- 100%CVE-2023-44487
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 199 above.