● Daily security briefing
Sunday, July 12, 2026
On July 12, 2026, there were no new advisories from CERT or PSIRT, but 61 CVEs were published, including several critical vulnerabilities. Notably, CVE-2026-56271 and CVE-2026-15511 both received a critical CVSS score of 9.8, affecting Flowise and Comfast CF-WR631AX respectively. Additionally, CVE-2026-56260, with a CVSS score of 9.1, was identified in Crawl4AI, which allows arbitrary file writes. Other high-severity vulnerabilities include CVE-2026-15480 and CVE-2026-15483, both affecting Trendnet devices, with CVSS scores of 8.8. Security teams should prioritize addressing these vulnerabilities to mitigate potential risks.
3 critical9 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-56271CVSS 9.8Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENC
- criticalCVE-2026-15511CVSS 9.8A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the
- criticalCVE-2026-56260CVSS 9.1Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesyst
- highCVE-2026-15480CVSS 8.8A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /sbin/rc of the component Web Service. Such manipulation of t
- highCVE-2026-15483CVSS 8.8A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipula
- highCVE-2026-61876CVSS 8.8LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCP
- highCVE-2026-59260CVSS 8.8OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-li
- highCVE-2026-61875CVSS 8.8luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers
- highCVE-2026-15481CVSS 8.8A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connectio
- highCVE-2026-15484CVSS 8.8A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. The affected element is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulati
- highCVE-2026-58596CVSS 8.3Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
- highCVE-2026-56241CVSS 8.3Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RP