● Daily security briefing
Saturday, July 18, 2026
On July 18, 2026, there was one advisory published by a CERT/PSIRT, but no new additions to the Known Exploited Vulnerabilities (KEV) list. Among the 82 CVEs published today, two critical vulnerabilities stand out: CVE-2026-16117, affecting @fastify/http-proxy, which fails to rewrite the request prefix, and CVE-2026-47865, an authentication bypass in VMware Avi Load Balancer that could be exploited by a malicious user. Additionally, several high-severity vulnerabilities were reported, including multiple issues in Shibby Tomato 1.28 and a permissions flaw in SurrealDB. Teams should prioritize reviewing these vulnerabilities for potential impact on their environments.
2 critical10 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-16117CVSS 10Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for ro
- criticalCVE-2026-47865CVSS 9.8VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authenti
- highCVE-2026-16096CVSS 8.8A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads t
- highCVE-2026-16095CVSS 8.8A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the ar
- highCVE-2026-16097CVSS 8.8A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 res
- highCVE-2023-54366CVSS 8.8SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attack
- highCVE-2026-47871CVSS 8.8VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal att
- highCVE-2026-11826CVSS 8.8OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supp
- highCVE-2024-58362CVSS 8.8SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non
- highCVE-2026-12228CVSS 8.7A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `pro
- highCVE-2026-16158CVSS 8.7Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter
- highCVE-2026-15631CVSS 8.7Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSo
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 1 above.