19 July 2026
7-Zip version 26.02 was released to fix a remote code execution vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip’s processing of XZ-compressed data.
7-Zip version 26.02 was released to fix a remote code execution vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip’s processing of XZ-compressed data.
CVE-2026-63030 and CVE-2026-60137 chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
CVE-2026-40639 (DSA-2026-197), stems from a broken XOR encryption scheme rather than a proper cryptographic hash.
A server-side request forgery (SSRF) vulnerability in PAN-OS security risk is minimized when management interface is restricted to only trusted internal IP addresses.
CVE-2026-4020 – Threat actors active on 100,000 sites, affects all versions of the plugin from 2.1.4 and older and has been addressed in version 2.1.5, released on March 17.
Palo Alto Networks CVE-2026-0274, CommvaultSecurityIQ integration; patches for PAN-OS, Prisma Access Agent, Cortex XSOAR, and GlobalProtect App. Splunk published a dozen advisories.
Oracle has released CVE-2026-35273, a critical unauthenticated remote code execution vulnerability impacting PeopleSoft Enterprise PeopleTools v8.61 and 8.62 and PeopleSoft Enterprise Applications.
CVE-2026-45447, a heap user-after-free bug used for PKCS#7 (Public-Key Cryptography Standard #7) verification; patches 18 vulnerabilities including a high-severity issue that could allow remote code execution.
CVE-2026-44963 allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. It impacts Veeam Backup & Replication 12.3.2.4465 and all earlier versions of 12 builds.
CVE-2026-4480 allowing unauthenticated attackers to achieve remote code execution (RCE) on affected systems; carries CVSS v3.1 score of 10.0, highlighting its severe impact and ease of exploitation.
“PinTheft,” was publicly disclosed on May 19, 2026. The vulnerability was fixed in the mainline Linux kernel tree. A proof-of-concept exploit was published along with public disclosure.
Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolslip, the vulnerability affects both NGINX Plus and NGINX Open Source, and can be triggered by a remote, unauthenticated attacker over plain HTTP.
CVE-2026-41091, MS Defender local privilege escalation (LPE) flaw known as RedSun, and CVE-2026-45498 is known as UnDefend, a security flaw according to a security researcher known as “Nightmare Eclipse”.
CVE-2026-9082 “highly critical” SQL injection vulnerability on sites using PostgreSQL; discovered by Google/Mandiant; affects Drupal’s database abstraction API.
Windows flaws, YellowKey and GreenPlasma, has released PoC for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems.
Tracked as CVE-2026-0300, the flaw affects the User-ID Authentication Portal (Captive Portal) and has already seen limited real-world exploitation.
The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0, according to VulnCheck.
The most critical of these flaws, dubbed “YellowKey,” enables a total bypass of BitLocker encryption, granting attackers completely unrestricted access to locked system drives.
Following Dirty Frag, Fragnesia, and other Linux kernel vulnerabilities making themselves known in recent days, the latest now is ssh-keysign-pwn.
MS Windows DNS Client designated as CVE-2026-41096, carries a severe CVSS score of 9.8 out of 10.