● Daily security briefing
Sunday, July 19, 2026
On July 19, 2026, the CERT/PSIRT output was relatively quiet, with only two advisories released. However, a significant number of vulnerabilities were published, totaling 471 CVEs. Notable high-severity vulnerabilities include CVE-2026-12484, which affects keras-team/keras version 3.15.0 and allows unsafe deserialization of attacker-controlled data, and CVE-2026-16221, impacting fast-uri versions from 2.3.1 to 4.1.0. Additional high-severity vulnerabilities were identified in the SourceCodester Class and Exam Timetabling System (CVE-2026-16228 and CVE-2026-16227), as well as in newpanjing simpleui (CVE-2026-16210) and Gerapy (CVE-2026-16209).
7 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- highCVE-2026-12484CVSS 7.8A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from
- highCVE-2026-16221CVSS 7.5Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an autho
- highCVE-2026-16228CVSS 7.3A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of t
- highCVE-2026-16227CVSS 7.3A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulatio
- highCVE-2026-16210CVSS 7.3A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Perfo
- highCVE-2026-16209CVSS 7.3A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint.
- highCVE-2026-16200CVSS 7.3A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The m
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 2 above.