● Daily security briefing
Thursday, July 23, 2026
On July 23, 2026, the security advisory landscape was marked by several critical advisories and notable vulnerabilities. Key advisories included a critical update from Microsoft addressing vulnerabilities in SharePoint and a significant advisory from Check Point regarding multiple vulnerabilities in their products. Additionally, the Debian security update DSA-6399-1 for WordPress was noted, along with a high-severity phishing campaign targeting Zimbra users. Among the notable CVEs, several critical vulnerabilities were reported, including CVE-2026-47668 in DbGate, CVE-2026-59555 in Participants Database, and CVE-2026-6516 affecting ManageEngine ADAudit Plus, all rated with a CVSS score of 10. Overall, while CERT/PSIRT output was relatively quiet, the day saw a substantial number of published CVEs, totaling 5,880.
19 critical3 high2 unknownacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcert-fr-avisMultiple vulnerabilities in Check Point products (July 23, 2026)
- criticalexploitedcccsCheck Point security advisory (AV26-735) – Update 1
- unknownexploiteddebianDSA-6399-1 wordpress - security update
- criticalexploitedcccsMicrosoft security advisory – July 2026 monthly rollup (AV26-698) – Update 3
- highexploitedcisaRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
- criticalexploitedcert-eu2026-009: Critical Vulnerabilities in Microsoft SharePoint
- criticalcisaJohnson Controls C-CURE 9000 and Victor application server
- highcert-bund[NEW] [high] pg_partman: Multiple vulnerabilities
- criticalcisaMZ Automation lib60870
- highcert-bund[NEW] [high] FreeRDP: Multiple vulnerabilities
- criticalcisaPanduit IntraVUE
- criticalcisaMZ Automation libIEC61850
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-47668CVSS 10DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `
- criticalCVE-2026-59555CVSS 10Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
- criticalCVE-2026-64813CVSS 10In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- criticalCVE-2026-6516CVSS 10Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
- criticalCVE-2026-64812CVSS 10In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- criticalCVE-2026-47752CVSS 9.9Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification tem
- criticalCVE-2026-47724CVSS 9.9nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for au
- criticalCVE-2026-59543CVSS 9.9Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
- criticalCVE-2026-65700CVSS 9.8h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary fi
- criticalCVE-2026-63359CVSS 9.8The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the logi
- criticalCVE-2026-65688CVSS 9.8Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to
- criticalCVE-2026-65689CVSS 9.8Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers t
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 291 above.