● Daily security briefing
Thursday, July 9, 2026
On July 9, 2026, there were 219 advisories from CERT/PSIRT, but no new additions to the Known Exploited Vulnerabilities (KEV) list. Significant advisories included high-severity updates for Aqua Security Trivy, Linux Kernel, and Netty, as well as new vulnerabilities in GitLab, Red Hat Enterprise Linux, and FreeRDP that allow for code execution. Notably, several critical CVEs were published today, including CVE-2026-59726 for Ruflo, CVE-2026-59827 for Metabase, and CVE-2026-15158 for the Blocksy Companion plugin, all of which pose serious risks such as remote code execution and arbitrary file uploads. Other critical vulnerabilities affecting various applications were also reported, emphasizing the need for immediate attention from security teams.
13 critical11 highacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highcert-bund[UPDATE] [high] Aqua Security Trivy: Vulnerability allows file manipulation
- highcert-bund[NEW] [high] GitLab: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Flowise: Multiple vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (python-pip): Vulnerability allows code execution
- highcert-bund[UPDATE] [high] Netty: Multiple vulnerabilities
- highcert-bund[NEW] [high] FreeRDP: Vulnerability allows code execution
- highcert-bund[UPDATE] [high] Gitea: Vulnerability allows bypassing of security measures
- highcert-bund[UPDATE] [high] QEMU and libvirt: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Red Hat OpenShift Container Platform (gRPC-Go): Vulnerability allows bypassing security measures
- highcert-bund[UPDATE] [high] IBM WebSphere Application Server: Multiple vulnerabilities
- criticalcisaSchneider Electric Easergy MiCOM Px40 Series
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-59726CVSS 10Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints
- criticalCVE-2026-59827CVSS 9.9Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection,
- criticalCVE-2026-15158CVSS 9.8The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the
- criticalCVE-2026-12116CVSS 9.8A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an atta
- criticalCVE-2026-14245CVSS 9.8The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions u
- criticalCVE-2026-52778CVSS 9.8GHSA-px5m-h76g-p7p8: YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
- criticalCVE-2026-5955CVSS 9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This i
- criticalCVE-2026-58123CVSS 9.8Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embed
- criticalCVE-2026-2342CVSS 9.3Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue af
- criticalCVE-2026-47646CVSS 9.3Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a netwo
- criticalCVE-2026-14261CVSS 9.1A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall
- criticalCVE-2026-59826CVSS 9.1Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connec
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 219 above.