● Daily security briefing
Wednesday, July 15, 2026
On July 15, 2026, the security advisory landscape was marked by the addition of two significant vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-46817 affecting Oracle E-Business Suite and CVE-2023-4346 related to the KNX Protocol. Notably, several critical advisories were released, including vulnerabilities in Microsoft SharePoint Server (CVE-2026-56164 and CVE-2026-55040), and multiple issues in SonicWall Secure Mobile Access and Microsoft Windows. Additionally, a large number of notable CVEs were published today, with several critical vulnerabilities identified, such as CVE-2026-52887 in NocoBase and CVE-2026-50148 in Metabase, both rated with a CVSS score of 10. Overall, while CERT/PSIRT outputs were relatively quiet, the volume of published CVEs indicates a busy day for security teams.
16 critical2 high6 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcert-fr-alerteMultiple vulnerabilities in Secure Mobile Access (July 15, 2026)
- highexploitedcisaCISA Adds Two Known Exploited Vulnerabilities to Catalog
- unknownexploitedjpcertSecurity Alert: Microsoft Releases July 2026 Security Updates
- unknownexploitedcert-fr-avisMultiple vulnerabilities in Sonicwall Secure Mobile Access 1000 (July 15, 2026)
- unknownexploitedcert-fr-avisMultiple vulnerabilities in Microsoft Windows (July 15, 2026)
- criticalexploitedcccsAL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644
- unknownexploitedcisco-psirtCisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
- unknownexploitedncsc-nlNCSC-2026-0239 [1.00] [H/H] Zero-Day vulnerabilities fixed in SonicWall SMA1000
- criticalexploitedcccsOracle security advisory (AV26-526) – Update 2
- criticalcccsTenable security advisory (AV26-705)
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- criticaldrupalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-52887CVSS 10NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-mess
- criticalCVE-2026-50148CVSS 10Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user wi
- criticalCVE-2026-46339CVSS 109Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registr
- criticalCVE-2026-56699CVSS 10Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operation
- criticalCVE-2026-54052CVSS 9.9n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through
- criticalCVE-2026-52891CVSS 9.9Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for M
- criticalCVE-2026-44986CVSS 9.9Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedd
- criticalCVE-2026-49352CVSS 9.89Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js,
- criticalCVE-2026-55652CVSS 9.8Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-su
- criticalCVE-2026-53513CVSS 9.6Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints
- criticalCVE-2026-62948CVSS 9.6OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefil
- criticalCVE-2026-61451CVSS 9.6The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The s
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 276 above.