CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Monday, July 27, 2026

On July 27, 2026, the security advisory landscape saw the addition of two significant Known Exploited Vulnerabilities (KEVs): CVE-2025-68686, which affects Fortinet FortiOS, and CVE-2026-16812, a command injection vulnerability in Arista VeloCloud Orchestrator. CISA has also updated its catalog to include these vulnerabilities, highlighting their potential exploitation. In addition to the KEVs, several critical advisories were released, including multiple vulnerabilities in Microsoft Windows products and an unpatched critical cross-site scripting vulnerability in Zabbix. Notable CVEs published today include CVE-2026-48030 in Pheditor and CVE-2026-63077 in JetBrains TeamCity, both rated critical and warranting immediate attention from security teams. Overall, while CERT/PSIRT output was relatively quiet, the volume of notable CVEs underscores the need for vigilance.

Last updated 03:35 UTC

CERT / PSIRT advisories
184
CVEs published
4173
Added to KEV
2
Known exploited
3

15 critical8 high1 unknownacross the day’s notable advisories and CVEs

Added to the KEV catalog

Exploitation observed in the wild — remediate first.

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 184 above.

plus 451 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.