CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Saturday, July 18, 2026

On July 18, 2026, there was one advisory published by a CERT/PSIRT, but no new additions to the Known Exploited Vulnerabilities (KEV) list. Among the 82 CVEs published today, two critical vulnerabilities stand out: CVE-2026-16117, affecting @fastify/http-proxy, which fails to rewrite the request prefix, and CVE-2026-47865, an authentication bypass in VMware Avi Load Balancer that could be exploited by a malicious user. Additionally, several high-severity vulnerabilities were reported, including multiple issues in Shibby Tomato 1.28 and a permissions flaw in SurrealDB. Teams should prioritize reviewing these vulnerabilities for potential impact on their environments.

Last updated 03:53 UTC

CERT / PSIRT advisories
1
CVEs published
82
Added to KEV
0
Known exploited
0

2 critical10 highacross the day’s notable advisories and CVEs

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 1 above.

plus 80 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.