● Daily security briefing
Wednesday, July 8, 2026
On July 8, 2026, the security advisory landscape was marked by a significant number of advisories, with 134 from CERT/PSIRT and 1,665 CVEs published. Notable advisories included multiple high-severity vulnerabilities in Langflow, Red Hat Enterprise Linux, BeyondTrust Privileged Remote Access, and IBM Operational Decision Manager, among others. In terms of critical vulnerabilities, CVE-2026-54782 in CoreWCF and CVE-2026-56843 in WebPros Plesk both received a CVSS score of 10, highlighting their severity. Other critical CVEs of interest included vulnerabilities in Fluentd and various WordPress plugins, all of which pose serious risks if left unaddressed.
12 critical11 high1 unknownacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcccsLangflow security advisory (AV26-670)
- highcert-bund[UPDATE] [high] Langflow: Multiple vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (389-ds-base): Multiple vulnerabilities allow code execution and DoS
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (python-pip): Vulnerability allows code execution
- highcert-bund[NEW] [high] BeyondTrust Privileged Remote Access and Remote Support: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities enable denial of service
- highcert-bund[NEW] [high] IBM Operational Decision Manager: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] FreeRDP: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (perl-HTTP-Daemon): Vulnerability allows execution of arbitrary program code with service privileges
- highcert-bund[UPDATE] [high] Fleet: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Kiali for Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-52831CVSS 10GHSA-v5px-423j-pf7p: Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
- criticalCVE-2026-54782CVSS 10CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not corr
- criticalCVE-2026-56843CVSS 9.9Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is
- criticalCVE-2026-9695CVSS 9.8An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.
- criticalCVE-2026-44024CVSS 9.8Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing fil
- criticalCVE-2026-58480CVSS 9.8Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassi
- criticalCVE-2026-9701CVSS 9.8The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the passwo
- criticalCVE-2026-8307CVSS 9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Medi
- criticalCVE-2026-12153CVSS 9.8The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a
- criticalCVE-2026-53649CVSS 9.6GHSA-xqhv-chqm-fhcc: Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
- criticalCVE-2026-15062CVSS 9.6SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege users to execute SQL beyond th
- criticalCVE-2026-59702CVSS 9.3repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 134 above.