● Daily security briefing
Friday, July 10, 2026
On July 10, 2026, the security advisory landscape saw the addition of two significant Known Exploited Vulnerabilities (KEVs): CVE-2026-56291, related to Balbooa Forms, and CVE-2026-48939, concerning iCagenda, both involving unrestricted file uploads. The day also featured critical advisories, including CISA's update on two KEVs and a critical vulnerability impacting Roundcube Webmail (CVE-2025-49113). Additionally, multiple high-severity advisories were issued regarding vulnerabilities in the Linux kernel, with updates highlighting various issues that could lead to denial of service. Notable CVEs included several critical vulnerabilities with CVSS scores of 10, such as GHSA-m5f5-28qr-9g9r, related to PrestaShop, and CVE-2026-54769, affecting the Langroid framework. Overall, while CERT/PSIRT output was relatively quiet, the notable CVEs indicate ongoing security challenges.
13 critical10 high1 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- criticalexploitedcccsAL25-007 - Vulnerability impacting Roundcube Webmail – CVE-2025-49113 – Update 1
- unknownexploitedubuntuUSN-8528-1: Linux kernel (Xilinx ZynqMP) vulnerabilities
- highexploitedcisaCISA Adds Two Known Exploited Vulnerabilities to Catalog
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities allow denial of service
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities allow denial of service
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-54159CVSS 10GHSA-m5f5-28qr-9g9r: prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
- criticalCVE-2026-54769CVSS 10Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Executio
- criticalCVE-2026-50551CVSS 9.9GHSA-56mp-4f3v-fgj2: SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
- criticalCVE-2026-54158CVSS 9.9GHSA-5xfx-xj4h-5p7r: SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
- criticalCVE-2026-54067CVSS 9.9GHSA-mvjr-vv3c-w4qv: SiYuan: Stored XSS to RCE via CSS-snippet breakout in renderSnippet()
- criticalCVE-2026-14480CVSS 9.9OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename
- criticalCVE-2026-55500CVSS 9.99Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and set
- criticalCVE-2026-14894CVSS 9.8The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. T
- criticalCVE-2026-61459CVSS 9.8MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass
- criticalCVE-2026-56765CVSS 9.8Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-l
- criticalCVE-2026-12761CVSS 9.8The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up
- criticalCVE-2026-15282CVSS 9.8The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 207 above.