● Daily security briefing
Thursday, July 16, 2026
On July 16, 2026, security advisory activity included the addition of three significant vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, specifically CVE-2026-25089 and CVE-2026-39808, both affecting Fortinet FortiSandbox, and CVE-2026-58644 related to Microsoft SharePoint. Critical advisories were issued for multiple Fortinet vulnerabilities and a monthly rollup from Microsoft, alongside advisories for Rockwell Automation products and SALTO ProAccess Space. In total, 217 advisories were published, with 2169 new CVEs, including notable critical vulnerabilities such as CVE-2026-45336 affecting HireFlow and CVE-2026-46512 impacting Frogman. The day was marked by a focus on critical vulnerabilities, underscoring the need for immediate attention from security teams.
23 critical1 highacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcisaCISA Adds Three Known Exploited Vulnerabilities to Catalog
- criticalexploitedcccsFortinet security advisory (AV26-568) – Update 1
- criticalexploitedcccsMicrosoft security advisory – July 2026 monthly rollup (AV26-698) – Update 1
- criticalexploitedcccsFortinet security advisory (AV26-351) – Update 2
- criticalcisaRockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
- criticalcisaRockwell Automation Flex 5000 Adapter
- criticalcisaSALTO ProAccess Space
- criticalcisaRockwell Automation Arena
- criticalcisaRockwell Automation FactoryTalk DataMosaix
- criticalcisaNASA Core Flight System (cFS) Health & Safety (HS) Application
- criticalcisaSiemens SICAM 8
- criticalcccsSplunk security advisory (AV26-708)
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-45336CVSS 10HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Fl
- criticalCVE-2026-46512CVSS 9.9Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and f
- criticalCVE-2023-49899CVSS 9.8An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
- criticalCVE-2026-46562CVSS 9.8Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algor
- criticalCVE-2023-49900CVSS 9.8An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.
- criticalCVE-2026-44180CVSS 9.8Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior t
- criticalCVE-2026-63087CVSS 9.8Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the inte
- criticalCVE-2026-45695CVSS 9.8Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to
- criticalCVE-2026-12492CVSS 9.8The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a suppl
- criticalCVE-2026-53412CVSS 9.8Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account
- criticalCVE-2026-55579CVSS 9.8GHSA-p4h7-p9rj-2pq2: Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
- criticalCVE-2026-15013CVSS 9.8The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3.
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 217 above.