● Daily security briefing
Sunday, July 26, 2026
On July 26, 2026, there were no new advisories from CERT or PSIRT, but 12 CVEs were published, highlighting several significant vulnerabilities. Notably, CVE-2026-15962, a high-severity issue with a CVSS score of 8.8, affects the Fluent Forms Pro Add On Pack plugin for WordPress and is vulnerable to PHP Object Injection. Additionally, CVE-2026-17497, with a CVSS score of 8.3, impacts NoteGen versions prior to 0.32.0, allowing the Tauri shell plugin to execute shell commands in an insecure manner. Another critical vulnerability, CVE-2026-17496, also in NoteGen, poses risks by rendering AI chat responses with potentially dangerous configurations. Lastly, CVE-2026-63720, rated at 7.5, affects datamodel-code-generator versions prior to 0.70.0, enabling code injection attacks.
4 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- highCVE-2026-15962CVSS 8.8The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This
- highCVE-2026-17497CVSS 8.3NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaS
- highCVE-2026-17496CVSS 8.1NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without
- highCVE-2026-63720CVSS 7.5datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplyi