● Daily security briefing
Tuesday, July 7, 2026
On July 7, 2026, security advisory activity was robust, with 177 advisories issued and 2,697 CVEs published. Notably, four new vulnerabilities were added to the Known Exploited Vulnerabilities (KEV) catalog, including CVE-2026-48282 affecting Adobe ColdFusion and CVE-2026-48908 related to JoomShaper SP Page Builder. Critical advisories included updates from Adobe and several from Siemens, highlighting vulnerabilities in Mendix Studio Pro and SINEC OS. Additionally, several critical CVEs were published, such as CVE-2026-34037, CVE-2026-34047, and CVE-2026-34048, all related to the Coolify tool, which poses significant risks to server management.
18 critical6 highacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
- exploitedCVE-2026-48282CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability
- exploitedCVE-2026-48908CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
- exploitedCVE-2026-56290CVE-2026-56290: Joomlack Page Builder Improper Access Control Vulnerability
- exploitedCVE-2026-55255CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcisaCISA Adds One Known Exploited Vulnerability to Catalog
- highexploitedcisaCISA Adds Three Known Exploited Vulnerabilities to Catalog
- criticalexploitedcccsAdobe security advisory (AV26-647) – Update 2
- criticalcisaLabcenter Proteus 9
- criticalcisaSiemens Mendix Studio Pro
- criticalcisaSiemens SINEC OS
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (python-pip): Vulnerability allows code execution
- criticalcisaHydro-Québec Le Circuit Electrique charging station backend
- highcert-bund[UPDATE] [high] HCL BigFix Compliance (Ruby): Multiple vulnerabilities
- highcert-bund[UPDATE] [high] GnuTLS: Multiple vulnerabilities
- highcert-bund[NEW] [high] Coolify: Multiple vulnerabilities
- criticalcisaHitachi Energy PROMOD V
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-34037CVSS 9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php
- criticalCVE-2026-34047CVSS 9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the
- criticalCVE-2026-34048CVSS 9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authenti
- criticalCVE-2026-13019CVSS 9.8Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated
- criticalCVE-2026-53483CVSS 9.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release ver
- criticalCVE-2026-53481CVSS 9.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release ver
- criticalCVE-2026-14345CVSS 9.8The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.
- criticalCVE-2026-12375CVSS 9.8The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distri
- criticalCVE-2026-33264CVSS 9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG
- criticalCVE-2026-59705CVSS 9.8mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessi
- criticalCVE-2011-10043CVSS 9.8Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to specify ar
- criticalCVE-2026-59800CVSS 9.89Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 177 above.