CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Sunday, July 26, 2026

On July 26, 2026, there were no new advisories from CERT or PSIRT, but 12 CVEs were published, highlighting several significant vulnerabilities. Notably, CVE-2026-15962, a high-severity issue with a CVSS score of 8.8, affects the Fluent Forms Pro Add On Pack plugin for WordPress and is vulnerable to PHP Object Injection. Additionally, CVE-2026-17497, with a CVSS score of 8.3, impacts NoteGen versions prior to 0.32.0, allowing the Tauri shell plugin to execute shell commands in an insecure manner. Another critical vulnerability, CVE-2026-17496, also in NoteGen, poses risks by rendering AI chat responses with potentially dangerous configurations. Lastly, CVE-2026-63720, rated at 7.5, affects datamodel-code-generator versions prior to 0.70.0, enabling code injection attacks.

Last updated 04:09 UTC

CERT / PSIRT advisories
0
CVEs published
12
Added to KEV
0
Known exploited
0

4 highacross the day’s notable advisories and CVEs

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.