Week 30, 2026 — Jul 20 – Jul 26, 2026
Everything the 24 aggregated CERT, PSIRT and vulnerability-database feeds published in this ISO week, condensed: what was added to the CISA KEV catalog, which advisories matter most and which products were hit. Daily detail lives in the daily briefings.
Added to the CISA KEV catalog
- criticalCVE-2026-50522added 2026-07-22 · CVSS 9.8 · public exploit code
- criticalCVE-2026-16232added 2026-07-22 · CVSS 9.1 · public exploit code
- criticalCVE-2026-63030added 2026-07-21 · CVSS 9.8 · public exploit code
- criticalCVE-2021-27137added 2026-07-21 · CVSS 8.1
- criticalCVE-2026-60137added 2026-07-21 · CVSS 5.9 · public exploit code
- criticalCVE-2026-0770added 2026-07-21 · public exploit code
Notable advisories
Check Point security advisory (AV26-735) – Update 1
2026-009: Critical Vulnerabilities in Microsoft SharePoint
CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2026-16232: Check Point SmartConsole Improper Authentication Vulnerability
Siemens CADRA
CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability
CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability
CVE-2026-60137: WordPress Core SQL Injection Vulnerability
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Most-affected products
Volume by source
Other weeks
Don't wait a week. The daily briefing lands in your inbox every morning after 06:00 UTC — subscribe free, or watch specific products for instant advisory alerts.