● Daily security briefing
Tuesday, July 28, 2026
On July 28, 2026, the security advisory landscape was marked by a significant number of advisories, with 285 from CERT/PSIRT and 5,980 CVEs published. Notable advisories included critical vulnerabilities in Siemens products such as the SIMATIC S7-PLCSIM Advanced and Desigo CC, as well as ABB's KNX Update Tool. Additionally, a high-severity update for Red Hat OpenShift Service Mesh was released, addressing a vulnerability that allows code execution. Among the notable CVEs, several critical vulnerabilities were highlighted, including CVE-2026-11756, a deserialization issue in the 3DEXPERIENCE platform, and CVE-2026-16498, a cross-tenant credential reuse vulnerability in terraform-mcp-server.
19 critical3 high2 unknownacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcccsArista Networks security advisory (AV26-751)
- unknownexploitedcisaSiemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
- criticalcisaSiemens SIMATIC S7-PLCSIM Advanced
- criticalcisaCI Fortify – Advice for isolating vital systems
- highcert-bund[UPDATE] [high] Red Hat OpenShift Service Mesh: Vulnerability allows code execution
- criticalcisaSiemens Desigo CC
- criticalcisaABB KNX Update Tool
- criticalcisaSiemens Mendix Runtime
- criticalcisaigloohome Smart Lock Mobile Application
- highcert-bund[NEW] [high] Apache Airflow FAB provider: Vulnerability allows obtaining administrator rights
- highncsc-ukWhen cyber attacks happen: helping organisations recover
- criticalcisaMikroTik RouterOS and Cloud Hosted Router
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-11756CVSS 10A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could
- criticalCVE-2026-16498CVSS 10The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terra
- criticalCVE-2026-16462CVSS 9.8In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
- criticalCVE-2026-51266CVSS 9.8schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynamically splices attacker-control
- criticalCVE-2026-51259CVSS 9.8Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subsequent normal audio buffer read
- criticalCVE-2026-66713CVSS 9.8Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when
- criticalCVE-2026-14512CVSS 9.8IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or
- criticalCVE-2026-51267CVSS 9.8schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application splices untrusted extension path
- criticalCVE-2026-14446CVSS 9.8IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
- criticalCVE-2026-51263CVSS 9.8schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON request bodies and HTTP request
- criticalCVE-2026-54658CVSS 9.8Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes duri
- criticalCVE-2026-51252CVSS 9.8schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata.
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 285 above.