● Daily security briefing
Thursday, July 30, 2026
On July 30, 2026, security advisory activity was notable, with 174 advisories issued and 1,920 CVEs published. Among the critical advisories, significant vulnerabilities were reported for NASA's Core Flight System Health & Safety Application, MikroTik RouterOS, and several products from Toptech Systems, Watchfire, MZ Automation, and Johnson Controls. Additionally, several critical CVEs were highlighted, including a CVSS score of 10 for an arbitrary file write vulnerability in Flyto2 Core and an incorrect authorization issue in Adobe Campaign Classic. Other critical vulnerabilities with high CVSS scores were identified in IBM Langflow OSS and webMethods Integration, as well as SQL injection vulnerabilities affecting various systems. Overall, while CERT/PSIRT output was quiet, the day was marked by several critical vulnerabilities that warrant attention from security teams.
22 critical2 unknownacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcccsCisco security advisory (AV26-757)
- unknownexploitedcert-fr-avisVulnerability in Cisco Firewall Management Center (July 30, 2026)
- criticalcisaCISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
- criticalcisaMZ Automation GmbH libiec61850
- criticalcisaMZ Automation lib60870
- criticalcisaOpen Source Software: Security Principles and Practices
- criticalcisaSchneider Electric IGSS
- criticalcisaNASA Core Flight System (cFS) Health & Safety (HS) Application
- criticalcisaMikroTik RouterOS
- criticalcisaWatchfire Controller Software
- criticalcisaRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
- criticalcisaJohnson Controls OpenBlue Employee
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-66803CVSS 10Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- criticalCVE-2026-67429CVSS 10GHSA-2956-977x-2w3r: Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
- criticalCVE-2026-48449CVSS 10Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation
- criticalCVE-2026-58046CVSS 9.9Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading
- criticalCVE-2026-13435CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
- criticalCVE-2026-12946CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
- criticalCVE-2026-67594CVSS 9.8Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached C
- criticalCVE-2026-68502CVSS 9.8LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handle
- criticalCVE-2026-51291CVSS 9.8sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.
- criticalCVE-2026-68503CVSS 9.8LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and
- criticalCVE-2026-51272CVSS 9.8In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character encoding conversion function. The function calculates require
- criticalCVE-2026-12943CVSS 9.8IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 175 above.