● Daily security briefing
Monday, July 13, 2026
On July 13, 2026, the security advisory landscape was marked by the addition of one known exploited vulnerability to the CISA catalog, specifically CVE-2008-4128, a Cross-Site Request Forgery vulnerability in Cisco IOS. Notable advisories included critical guidance on improving router hygiene to mitigate threats from Russian state-sponsored actors, along with multiple high-severity updates for the Linux Kernel and Node.js addressing various vulnerabilities. Additionally, several critical CVEs were published, including CVE-2026-57811 and CVE-2026-57719, both rated at CVSS 10 for severe code injection and file upload issues, respectively. Overall, while CERT/PSIRT output was relatively quiet, the volume of published CVEs highlights ongoing security concerns across multiple platforms.
13 critical11 highacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcisaCISA Adds One Known Exploited Vulnerability to Catalog
- criticalexploitedcisaImprove Router Hygiene to Protect Against Russian State-Sponsored Targeting
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[UPDATE] [high] Node.js: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Vulnerability allows privilege escalation
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities allow denial of service
- highcert-bund[UPDATE] [high] SaltStack Salt: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Flowise: Multiple vulnerabilities
- highcert-bund[NEW] [high] Drupal Modules: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Python: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] ImageMagick: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-57811CVSS 10Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This i
- criticalCVE-2026-57719CVSS 10Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a throug
- criticalCVE-2026-57401CVSS 9.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash
- criticalCVE-2026-61667CVSS 9.9GHSA-m4m7-4cw8-62j6: DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
- criticalCVE-2026-57710CVSS 9.9Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from
- criticalCVE-2026-45579CVSS 9.9GHSA-9jpv-c7p4-997x: DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
- criticalCVE-2026-57738CVSS 9.8Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
- criticalCVE-2026-57813CVSS 9.8Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.
- criticalCVE-2026-59518CVSS 9.8Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
- criticalCVE-2026-57770CVSS 9.8Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5
- criticalCVE-2026-57744CVSS 9.8Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a thr
- criticalCVE-2026-60121CVSS 9.8Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 170 above.