● Daily security briefing
Friday, July 17, 2026
On July 17, 2026, security advisory activity was robust, with 179 advisories published by various CERT and PSIRT teams and 1,951 new CVEs released. Notable advisories included vulnerabilities fixed in Microsoft Office (NCSC-2026-0237) and multiple high-severity vulnerabilities affecting Microsoft Office 365, the Linux Kernel, Ubuntu Linux, nginx-ui, Mozilla Firefox, and Google Chrome. Additionally, several critical CVEs were highlighted, particularly those related to IBM Langflow OSS, which included multiple remote code execution vulnerabilities and privilege escalation issues, with CVSS scores reaching as high as 10. The day saw no new additions to the Known Exploited Vulnerabilities (KEV) list.
14 critical9 high1 unknownacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedncsc-nlNCSC-2026-0237 [1.01] [H/H] Vulnerabilities fixed in Microsoft Office
- highcert-bund[NEW] [high] Microsoft Office 365 (Moodle Plugin): Vulnerability allows bypassing of security measures
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Ubuntu Linux (ubuntu-pro-client): Multiple vulnerabilities
- highcert-bund[NEW] [high] nginx-ui: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple vulnerabilities
- highcert-bund[NEW] [high] Google Chrome: Multiple vulnerabilities allow unspecified attack
- highcert-bund[UPDATE] [high] libssh2: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- criticalcccsFreePBX security advisory (AV26–711)
- highcert-bund[NEW] [high] Google Chrome: Multiple vulnerabilities
- criticalcccsBroadcom VMware security advisory (AV26-712)
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-54159CVSS 10PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request
- criticalCVE-2026-8635CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and a
- criticalCVE-2026-9135CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies compone
- criticalCVE-2026-8859CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component
- criticalCVE-2026-8481CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts us
- criticalCVE-2026-8476CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pick
- criticalCVE-2026-9202CVSS 9.8IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployme
- criticalCVE-2026-9198CVSS 9.8IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (execut
- criticalCVE-2026-9103CVSS 9.8IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoin
- criticalCVE-2026-15982CVSS 9.8The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including
- criticalCVE-2026-12692CVSS 9.8Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 befor
- criticalCVE-2026-51080CVSS 9.8libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 179 above.