● Daily security briefing
Wednesday, July 29, 2026
On July 29, 2026, the security advisory landscape saw the addition of a significant known exploited vulnerability, CVE-2026-20316, related to a hard-coded password issue in Cisco Secure Firewall Management Center. Notable advisories included multiple vulnerabilities across various platforms, such as high-severity issues in Xen, VMware products, Apache Traffic Server, BlackBerry UEM Management Console, Mozilla Firefox, and Adobe Creative Cloud. The day also featured several critical CVEs, including CVE-2026-16326 and CVE-2026-58162, both scoring 10 on the CVSS scale, highlighting severe security risks in consul-mcp-server and Apache Traffic Server, respectively. Overall, while CERT/PSIRT output was relatively quiet, the volume of published CVEs, totaling 3,325, underscores ongoing security challenges.
13 critical11 highacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcisco-psirtCisco Secure Firewall Management Center Software Static Credential Vulnerability
- highexploitedcisaCISA Adds One Known Exploited Vulnerability to Catalog
- highcert-bund[NEW] [high] Xen: Multiple vulnerabilities
- highcert-bund[NEW] [high] VMware Products: Multiple vulnerabilities
- highcert-bund[NEW] [high] Apache Traffic Server: Multiple vulnerabilities
- highcert-bund[NEW] [high] BlackBerry UEM Management Console: Multiple vulnerabilities
- highcert-bund[NEW] [high] Mozilla Firefox and Firefox ESR: Multiple vulnerabilities
- highcert-bund[NEW] [high] Adobe Creative Cloud (Bridge and Format Plugins): Multiple vulnerabilities
- highcert-bund[NEW] [high] IBM WebSphere Application Server and Application Server Liberty: Multiple vulnerabilities
- highcert-bund[NEW] [high] TeamViewer: Vulnerability allows bypassing of security measures
- highcert-bund[NEW] [high] Hashicorp Terraform MCP Server: Multiple vulnerabilities
- criticalcisco-psirtCisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-16326CVSS 10In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for s
- criticalCVE-2026-58162CVSS 10The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from
- criticalCVE-2026-58150CVSS 10Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.
- criticalCVE-2026-33267CVSS 10Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recom
- criticalCVE-2026-54735CVSS 10Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-
- criticalCVE-2026-57834CVSS 10Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, fr
- criticalCVE-2026-67429CVSS 10Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead
- criticalCVE-2026-54680CVSS 9.9Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/mode
- criticalCVE-2026-63233CVSS 9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data pas
- criticalCVE-2026-63232CVSS 9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data pass
- criticalCVE-2026-63234CVSS 9.9A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed
- criticalCVE-2026-63227CVSS 9.9An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 172 above.