● Daily security briefing
Saturday, July 25, 2026
On July 25, 2026, there were no new advisories from CERT or PSIRT, but a total of 284 CVEs were published, including several notable vulnerabilities. The most critical is CVE-2026-66012, a missing authorization vulnerability in SiYuan prior to version 3.7.2, rated with a CVSS score of 10. Additionally, CVE-2026-10818 affects the WPForms Pro plugin for WordPress, allowing arbitrary file uploads, while CVE-2026-66374 in Knot Resolver prior to 6.4.1 enables remote code execution through a heap-based buffer overflow. Lastly, CVE-2026-66373 in Redis before version 8.8.0 poses a risk of remote code execution under specific conditions.
1 critical3 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-66012CVSS 10SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-ro
- highCVE-2026-10818CVSS 8.1The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due
- highCVE-2026-66374CVSS 8.1Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
- highCVE-2026-66373CVSS 7.5Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry)