Daily CVE Briefing
CVE publication remained very active over the last 24 hours, with a broad mix of web application and platform vulnerabilities. A major share of high-severity findings targeted WordPress and its ecosystem, with multiple products showing issues like broken access control, injection flaws, and file operation/SSRF-style weaknesses; several critical items were also attributed to WordPress plugin themes by Wordfence and other publishing CNAs. Outside of WordPress, releases showed recurring themes of server-side logic flaws in web frameworks (including Next.js/Astro) and security-sensitive auth or request validation problems in enterprise platforms such as JFrog and Progress LoadMaster. Apple publications were also prominent, with many memory-safety and sandbox/authorization related issues spanning multiple products, alongside continued discovery of denial-of-service and open-redirect style weaknesses in web tooling.Monday, July 27, 2026
New CVEs (last 24h)172
Fixes vs no fixes123 vs 49
Known exploited0
Highest Severity CVEs (Last 24 Hours)
Top 10 by CVSS 4.0 score, with vector details and affected-product breadth.
| CVE ID | Product | Severity | CVSS 4.0 score | CVSS 4.0 vector | Official CPEs | Remediation type |
|---|
| CVE-2026-48145 | Apache Thrift | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N | 1 | upgrade |
| CVE-2026-59550 | AWP Classifieds | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N | 1 | upgrade |
| CVE-2026-65567 | Event Tickets | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N | 1 | upgrade |
| CVE-2026-12394 | MemberGlut | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N | 0 | upgrade |
| CVE-2026-13714 | Realtyna Organic IDX | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | 0 | upgrade |
| CVE-2026-14289 | FacturaONE | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H | 0 | upgrade |
| CVE-2026-59534 | Post My CF7 Form | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N | 0 | upgrade |
| CVE-2026-59535 | Thrive Product Manager | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N | 0 | upgrade |
| CVE-2026-59536 | CoCart | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N | 0 | upgrade |
| CVE-2026-65435 | Thrive Leads | Critical | 9.3 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N | 0 | upgrade |
Top Publishing CNAs (Last 24 Hours)
| CNA | New CVEs |
|---|
| audit@patchstack.com | 50 |
| contact@wpscan.com | 23 |
| security@apache.org | 15 |
| disclosure@vulncheck.com | 9 |
| cve@mitre.org | 8 |
| Erlang Ecosystem Foundation | 8 |
| cna@vuldb.com | 7 |
| security@joomla.org | 7 |
| kernel.org | 6 |
| cve-coordination@incibe.es | 5 |
Top Affected Products (Last 24 Hours)
| Title | New CVEs | Remediation types |
|---|
| Apache Thrift | 15 | upgrade |
| Linux kernel | 7 | patch, upgrade |
| Progress Software LoadMaster | 4 | upgrade |
| Microsoft Edge | 3 | upgrade |
| HCL Connections | 2 | upgrade |
| Red Hat Enterprise Linux | 2 | upgrade |
| Mattermost | 2 | upgrade |
| rtMedia | 2 | upgrade |
| WP Google Review Slider | 2 | upgrade |
| ZTE Blade A75 Pro 5G | 1 | upgrade |
Use of this data is subject to our Terms. Scraping, bulk extraction, redistribution, and AI/ML training are prohibited.