● Daily security briefing
Monday, July 27, 2026
On July 27, 2026, the security advisory landscape saw the addition of two significant Known Exploited Vulnerabilities (KEVs): CVE-2025-68686, which affects Fortinet FortiOS, and CVE-2026-16812, a command injection vulnerability in Arista VeloCloud Orchestrator. CISA has also updated its catalog to include these vulnerabilities, highlighting their potential exploitation. In addition to the KEVs, several critical advisories were released, including multiple vulnerabilities in Microsoft Windows products and an unpatched critical cross-site scripting vulnerability in Zabbix. Notable CVEs published today include CVE-2026-48030 in Pheditor and CVE-2026-63077 in JetBrains TeamCity, both rated critical and warranting immediate attention from security teams. Overall, while CERT/PSIRT output was relatively quiet, the volume of notable CVEs underscores the need for vigilance.
15 critical8 high1 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcisaCISA Adds Two Known Exploited Vulnerabilities to Catalog
- unknownexploitedcccsFortinet security advisory (AV26-109) – Update 1
- highcert-bund[UPDATE] [high] Unbound: Multiple vulnerabilities
- criticalcert-bund[NEW] [critical] Microsoft Windows products: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] ProFTPD: Vulnerability allows SQL injection
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- criticalcert-bund[NEW] [UNPATCHED] [critical] Zabbix: Vulnerability allows cross-site scripting
- highcert-bund[NEW] [high] ffmpeg: Multiple vulnerabilities
- highcert-bund[NEW] [high] FreeRDP: Vulnerability allows code execution
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[UPDATE] [high] Aqua Security Trivy: Vulnerability allows file manipulation
- criticalcert-bund[NEW] [critical] vBulletin: Vulnerability allows code execution
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalexploitedCVE-2026-16812CVSS 10VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successf
- criticalCVE-2026-48030CVSS 9.9Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler a
- criticalCVE-2026-51303CVSS 9.8A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprList object via sqlite3ExprListDe
- criticalCVE-2026-13714CVSS 9.8The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an
- criticalCVE-2026-63077CVSS 9.8In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- criticalCVE-2026-12394CVSS 9.8The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitra
- criticalCVE-2026-55971CVSS 9.8Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which
- criticalCVE-2026-61511CVSS 9.8vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows un
- criticalCVE-2026-55579CVSS 9.8Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash s
- criticalCVE-2026-66395CVSS 9.6SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting
- criticalCVE-2026-59533CVSS 9.3Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
- criticalCVE-2026-59538CVSS 9.3Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 184 above.