● Daily security briefing
Monday, July 20, 2026
On July 20, 2026, the security advisory landscape saw significant activity with 182 advisories published by various CERT and PSIRT teams, alongside 3,029 new CVEs. Noteworthy critical advisories included updates from ServiceNow (AV26-693) and IBM (AV26-715), while several high-severity advisories addressed vulnerabilities in the Linux kernel and Golang. Among the notable CVEs, several critical vulnerabilities were identified, including CVE-2026-46412 in the @beproduct/nestjs-auth module and CVE-2026-44359 in the Meshtastic networking solution, both rated with a CVSS score of 10. Other critical vulnerabilities with scores of 9.9 and 9.8 were also reported, highlighting ongoing security challenges across various software platforms.
14 critical10 highacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- criticalcccsServiceNow security advisory (AV26-693) – Update 1
- highubuntuUSN-8568-1: Linux kernel (OEM) vulnerabilities
- highubuntuUSN-8567-1: Linux kernel vulnerabilities
- highubuntuUSN-8566-1: Linux kernel vulnerabilities
- criticalcccsIBM security advisory (AV26-715)
- highcert-bund[UPDATE] [high] Golang Go: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Golang Go: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] HTTP/2 implementations: Vulnerability allows denial of service
- highcert-bund[UPDATE] [high] Red Hat OpenShift Container Platform (gRPC-Go): Vulnerability allows bypassing security measures
- highcert-bund[UPDATE] [high] Red Hat Enterprise Linux (urllib3): Multiple vulnerabilities allow denial of service
- highubuntuUSN-8569-1: Linux kernel (HWE) vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-46412CVSS 10@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker us
- criticalCVE-2026-44359CVSS 10Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_tar
- criticalCVE-2026-51027CVSS 9.9An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.
- criticalCVE-2026-54051CVSS 9.9Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`),
- criticalCVE-2026-35048CVSS 9.8The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitiz
- criticalCVE-2026-63766CVSS 9.8GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox val
- criticalCVE-2026-63767CVSS 9.8ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by
- criticalCVE-2026-16235CVSS 9.8Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cr
- criticalCVE-2026-64625CVSS 9.8AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backt
- criticalCVE-2026-41252CVSS 9.8xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The i
- criticalCVE-2026-64620CVSS 9.8FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation
- criticalCVE-2026-53595CVSS 9.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenCo
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 182 above.