CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Saturday, July 25, 2026

On July 25, 2026, there were no new advisories from CERT or PSIRT, but a total of 284 CVEs were published, including several notable vulnerabilities. The most critical is CVE-2026-66012, a missing authorization vulnerability in SiYuan prior to version 3.7.2, rated with a CVSS score of 10. Additionally, CVE-2026-10818 affects the WPForms Pro plugin for WordPress, allowing arbitrary file uploads, while CVE-2026-66374 in Knot Resolver prior to 6.4.1 enables remote code execution through a heap-based buffer overflow. Lastly, CVE-2026-66373 in Redis before version 8.8.0 poses a risk of remote code execution under specific conditions.

Last updated 03:54 UTC

CERT / PSIRT advisories
0
CVEs published
284
Added to KEV
0
Known exploited
0

1 critical3 highacross the day’s notable advisories and CVEs

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.