Research
July 2026 CVEs: What to Fix First
SOSEC collected all 9,808 CVE Program records published in July 2026 and recorded a bounded cause assessment for each of the 9,763 active records; asset matches among 13 CISA KEVs enter repair and compromise review first, while other records are consolidated by product, exposure, and vendor update; closure requires verified running versions, removed legacy copies, and investigation of exploited systems.

In this article
1 Start with assets and vendor updates
SOSEC's conclusion: intersect the products, versions, deployment modes, and exposed paths actually running in the organization with the 13 vulnerabilities that CISA says are being exploited. Every match enters repair and compromise review together. Next, handle internet-reachable paths for unauthenticated code execution, authentication bypass, injection, and memory corruption; use EPSS to order work inside that group. Consolidate the Oracle, Microsoft, Linux, Chrome, Apple, and other batch releases by product and vendor update. Records with no asset match remain intelligence, while incomplete product or version data becomes an inventory investigation. CVSS describes technical severity, EPSS estimates exploitation probability at a point in time, and KEV records observed exploitation. The affected asset, version, exposure, current vendor fix, and local business consequence decide today's action.
July produced 9,808 CVE records. Of those, 9,763 were still active in the research snapshot and 45 had been rejected. The number measures one month of throughput through the disclosure system. Turning it directly into 9,808 patch tickets would duplicate a great deal of work. Oracle published 1,097 records on July 21, pointing to 262 products and one quarterly update entry point; Microsoft published 570 records for 104 products on July 14; Linux published 431 on July 19; Chrome published 370 on July 30. Engineering teams install a cumulative update, a browser release, a set of kernel packages, or a device hotfix. Record identifiers describe the problems. Change objects deliver the repair.
A single league table loses the facts that matter. Across the active cohort, 1,447 records had a score of 9.0 or higher from at least one retained source; only 13 appeared in CISA KEV at the cutoff. Cisco Secure FMC CVE-2026-20316 scored 5.3, yet Cisco rated the advisory High because the flaw can be chained with other FMC vulnerabilities and confirmed active exploitation. Arista VeloCloud Orchestrator CVE-2026-16812 scored 10.0 and had confirmed exploitation, while its August 4 EPSS was only 0.00884. Severity, prediction, and observed exploitation answer separate questions. An asset match turns them into work.
This publication therefore separates exhaustive enumeration from readable conclusions. The report explains what happened during the month, which causes recurred, and how to convert disclosure records into security changes. The public record-level ledger contains all 9,808 identifiers, all 9,763 active-record cause assessments, every retained source-attributed CVSS row, EPSS, KEV, products, references, precision labels, and limitations. Readers can reproduce the figures or apply their own inventory without accepting an asset-free aggregate ranking.
2 Turn the monthly feed into a change ticket
Each candidate first intersects with the real inventory across vendor, product, version, deployment form, and reachable path; container images, auto-updating browsers, hosted cloud services, and local appliances need distinct treatment. Open the vendor's current advisory next and establish the affected boundary, current fixed release, temporary restrictions, upgrade side effects, and recovery route. A historical first-fixed release in a CVE record establishes a repair boundary. The production target should be a currently supported fixed release. When the running version of a device is unknown, the work item is “identify the asset,” and impact remains undetermined.
KEV asset match: repair and investigate together
Install the vendor's current update or hotfix, preserving device logs, identity, and critical configuration first, then inspect the vendor's indicators of compromise. Temporary network restrictions reduce exposure and do not replace permanent repair. A known-exploited item closes only after the running version, serving instances, business regression, and compromise review all pass. The rollback target must be supported and unaffected; isolate the service when no safe rollback exists.
High-risk exposure outside KEV: order by the reachable path
Address internet-reachable, unauthenticated paths that can execute code, alter a control plane, or cross an authorization boundary before paths requiring low privilege, user interaction, or uncommon configuration. EPSS helps order otherwise comparable assets. It cannot establish local exposure or make a record safe because public exploitation has not yet appeared. Where an advisory offers no reliable temporary control, reduce reachability, disable the function, or isolate the instance while the permanent update is prepared.
Batch publication: consolidate by product release train
Group records that share an advisory, fixed release, and maintenance event into one change while preserving the many-to-one CVE-to-package map. Acceptance checks the binaries, containers, nodes, and high-availability replicas that are actually running; a successful package-manager response is insufficient. The change remains open while old images, offline nodes, disaster-recovery copies, or rollback artifacts still contain the vulnerable version.
No asset match or incomplete evidence: preserve the basis
Record the inventory sources, product aliases, version ranges, and query date. A proven absence creates no patch change and keeps the intelligence subscription active. Incomplete product or version data goes to the asset owner for confirmation. Recompute when the record is rejected, the vendor changes scope, KEV adds the issue, or deployment state changes. Closure requires reviewable evidence that names the inventory sources, query scope, and date.
Four records arriving on the same day show how this works. SonicWall SMA1000 CVE-2026-15409 and CVE-2026-15410 were actively exploited. Affected 12.4.3 and 12.5.0 trains must reach at least 12.4.3-03453 and 12.5.0-02835, respectively. The notice also requires review of /__api__/login, /__api__/logout, /wsproxy requests carrying suspicious host parameters, hotfix removal events containing a path-traversal name, and /var/lib/unit/conf.json. Systems with indicators are reimaged or redeployed, user and administrator passwords changed, and TOTP tokens reset. A configuration backup is directly reusable only when it predates installation of 12.4.3-03245 or 12.5.0-02283; otherwise the configuration needs a detailed tampering review. One work item therefore contains repair, evidence preservation, a trusted recovery source, and credential response.
Cisco FMC CVE-2026-20316 shows why a lower score can still be urgent. Static credentials for a low-privilege account allow a remote attacker to log in. Cisco confirmed exploitation in July 2026 and published hotfixes for six supported trains. Operators must also run zgrep "package_info.*license" /var/log/messages*; a log reference to /var/tmp/license.tmp triggers contact with TAC for recovery assistance. The 5.3 score describes the privilege and data effect of this flaw in isolation. Cisco's High rating and KEV status add chaining potential and attack evidence.
Oracle's 1,097 records from July 21 should first become a list of Oracle products and versions the organization operates, then separate Database, Fusion Middleware, E-Business Suite, and other release trains through the July CPU patch-availability documents. The Oracle advisory itself contains 1,449 new security patches and explains that the same CVE can appear in multiple product risk matrices; the CPU release train addresses many CVEs together. CVE-2026-60230 and CVE-2026-60302 even have the same public Coherence product, versions, description, and 9.8 vector. Two independent change tickets for those identifiers add no protection; retaining the mapping and verifying actual patch coverage does.
Now consider a WordPress plugin that has never been installed in the reader's estate. Even when its record carries a 9.8 score, software inventory, filesystem inspection, and the hosting platform may together demonstrate no asset match. The assessment and its evidence enter the ledger, and no patch change is opened. If the CMDB cannot answer and the scanner misses some sites, the result is “asset state unknown,” followed by inspection of those sites and hosting accounts. The same CVE leads to different actions because the asset facts differ.
3 Where July's 9,808 records came from
A July census first needs a fixed date field. This report uses cveMetadata.datePublished in the CVE Program record, from midnight UTC on July 1 through the instant before midnight UTC on August 1, at cvelistV5 commit a373dbed. That definition yields 9,808 records: 9,763 currently PUBLISHED and 45 currently REJECTED. The NVD API defines pubStartDate as the date a CVE was added to the NVD. Its corresponding window returned 9,919 records, including 111 whose CVE Program publication date fell outside July; all 9,808 core records had reached NVD by the download cutoff. Both totals are valid measurements of different events: CVE Program publication and NVD receipt.
The year embedded in an identifier is also distinct from its publication year. Of the 9,763 active records, 9,527 carry a 2026 identifier and 236 carry an earlier year; the oldest is from 2011. Median reservation-to-publication lag was 13.2 days, P90 was 82.7 days, P99 was 302.3 days, and the maximum was 1,982 days; 76 records exceeded one year and six exceeded five years. P99 uses linear interpolation at p × (n−1) over the complete population, and the ledger states the method. CVE-2021-27137 was reserved in 2021, published in July 2026, and then added to KEV for a DD-WRT UPnP buffer overflow. A query based on identifier year would miss that newly disclosed record.
Daily volume follows publisher release cadence. July 14 carried 1,007 records, driven by Microsoft; July 21 reached 1,474, including 1,097 from Oracle; Linux supplied 431 of July 19's 466 records; Chrome supplied 370 of July 30's 669. Across all 9,808 records, the largest publishers were GitHub's CNA with 1,298, Oracle with 1,108, Linux with 837, VulnCheck with 705, Microsoft with 648, Chrome with 487, Patchstack with 481, Wordfence with 454, and VulDB with 440. The curve describes batch-processing calendars across disclosure organizations. It does not measure a sudden daily discovery of the same number of independent flaws by attackers.
Exact text reuse exposes more distance between record count and independent engineering problems. The active cohort has 6,801 distinct nonempty titles; 227 duplicate-title clusters contain 802 records, and the largest cluster contains 25. Descriptions have 9,273 distinct texts; 262 exact-description clusters contain 752 records, with 32 in the largest. The active cohort references 20,787 distinct URLs, 19,843 of which appear once. At the other extreme, Oracle's 1,097-record batch shares one quarterly advisory entry point, while Apple's 164 records from July 27 use only 11 distinct references. A shared advisory can carry many product rows, and identical prose can describe multiple products or two identifiers that public evidence cannot distinguish. Consolidation organizes change work while the original identifiers remain available for impact tracking and later updates.
The 45 rejected records remain part of the complete monthly history. Thirty-three explicitly say the subject is not a security issue, five point to duplicate identifiers, and others cite an out-of-scope threat model, an erroneous determination, or a general withdrawal. The ledger preserves those historical records; cause totals and the patch queue use the 9,763 active records. Rejection state may change later, so the snapshot commit and each record's update time are retained.
NVD's enrichment state on August 4 also shows why one field cannot complete end-of-month asset matching. Among the 9,919 July NVD receipts, 3,702 were Analyzed, 3,592 Deferred, 1,318 Awaiting Analysis, 581 Undergoing Analysis, 471 Received, 145 Rejected, and 110 Modified. Only 3,824 active core records carried an NVD CPE configuration, or 39.2 percent. CPEs are useful where present. Where they are absent, use the CNA affected-product data, vendor advisory, SBOM, software discovery, and deployment records. An empty configuration expresses enrichment state and cannot on its own establish absence from the estate.
4 Three engineering failures account for 61.8%
SOSEC assigned each active record the earliest engineering failure that public evidence could support. Incorrect binding of authority, identity, object, tenant, or privilege accounted for 2,449 records. Memory bounds, type, initialization, ownership, and lifetime failures accounted for 1,817. Untrusted data crossing into SQL, commands, code, HTML, templates, or deserialization grammars accounted for 1,770. Together, the three families cover 6,036 records, or 61.8 percent. They are followed by request and network trust at 761, resource control at 607, file or object selection at 589, state and sequencing at 477, cryptography and secrets at 310, output exposure at 308, other concrete causes at 184, configuration/update/dependency controls at 181, and hardware or physical causes at 27. Public material stated only impact or an overly broad label for 283 records, so their cause remains undetermined.
Every record followed the same evidence ladder: public source or patch first, then a vendor account of the failed check, state transition, or lifetime, then a concrete Base/Variant CWE supported by the description. A record stops at a broad family when that is all the material supports and remains undetermined when even a family would require invention. Each active row carries one mechanism sentence, its evidence basis, precision, and confidence. Reviewers opened primary references for 376 records, covering every KEV, all 22 records with EPSS at or above 0.10, every record whose maximum observed score reached 9.0 while its initial cause remained broad or undetermined, plus cases with source disagreement or a call path that needed confirmation. The builder requires exactly one review for each of the 9,763 active identifiers and rejects a SOURCE_TRACED label without a public source or patch URL. The 283 undetermined results therefore preserve the resolution of the public evidence.
Authority and object binding ranks first because the family reaches well beyond a missing login. It includes endpoints with no authentication, authenticated callers operating on another user's object, ordinary administrators entering system-level functions, tenant identifiers left unbound to the session principal, and batch or proxy layers interpreting one privilege as another. Repair requires a decision over subject, object, tenant, action, and state at the operation itself, with negative tests for foreign object IDs, cross-tenant requests, old tokens, batch subrequests, and administrative boundaries. A single “user is logged in” check at the route leaves later object selection exposed.
Memory records cluster in Linux, Microsoft, Chrome, Apple, and parsing libraries. Out-of-bounds reads and writes, use after free, integer overflow, uninitialized values, type confusion, and races share one premise: length, ownership, type, or lifetime invariants failed before access. Memory-safe languages can remove part of that surface. Existing C/C++ and kernel code still needs fuzzing focused on parsers and concurrency, ASan/UBSan/KASAN and related dynamic checks, compiler hardening, and exact regression cases. Treating each CVE as one patch address misses the opportunity to find the same lifetime mistake in adjacent functions.
Interpreter boundaries include SQL and command injection, XSS, template and expression evaluation, unsafe deserialization, and dynamic code loading. In each case, data becomes part of another language and a filter is expected to anticipate its grammar. Durable repair uses parameterized queries, structured process arguments, output encoding for the exact destination context, serialization with constrained types, and explicit template capabilities. Input validation enforces business values; it cannot carry the full separation burden for SQL, shell, HTML, or executable object graphs. July's WordPress CVE-2026-60137 and CVE-2026-63030 also show two weaknesses joining in one call path: REST batch-route interpretation carries input into WP_Query, where handling of author__not_in enables SQL manipulation and the combined path reaches code execution. Upgrading to a current supported WordPress release breaks the chain, while development work still addresses both route interpretation and query construction.
These shares describe July's public corpus and shift with its product mix. Oracle has 834 authority-binding assessments among 1,108 active records, or 75 percent. Linux has 443 memory-lifetime and 207 state-sequencing assessments among 837, a combined 78 percent. Microsoft has 375 memory-lifetime assessments among 648, or 58 percent. Patchstack and Wordfence place 230 of 481 and 221 of 454 records, respectively, at interpreter boundaries—close to half in both sets. Product architecture and publisher description depth both contribute to those differences. The monthly distribution supports common investment across teams; each organization should recalculate its engineering budget against its own languages, frameworks, appliances, and exposed paths.
CWE data helps locate weaknesses, although a raw ranking is too abstract to serve as root-cause analysis. At least one CWE appears on 8,979 active records and none appears on 784. Only 5,945 records have an Allowed or Allowed-with-Review Base/Variant mapping under CWE 4.20; 3,818 lack a sufficiently specific structured mapping. The most common entry, CWE-284, appears 910 times. The official catalog describes it as a Pillar with Discouraged mapping usage, close to the broad category “improper access control”; CWE-20 “input validation” often stops at a similarly high level. The precision labels therefore preserve what the evidence can say: 15 cases were traced to public source or patch, 5,084 were supported by a concrete Base/Variant CWE plus matching prose, 2,573 by a concrete description, 1,808 only to a cause family, and 283 remained undetermined. The distribution retains public resolution instead of polishing broad labels into source facts.
Record-by-record reading also found material disagreement with primary sources. CVE-2026-51027's embedded description says information exposure, while its public reproducer shows path escape leading to an out-of-root file move as the first failure. CVE-2026-59084 retains a 9.1 source score, while Apache rates the Tomcat EncryptInterceptor documentation issue Low. CVE-2026-16388 reaches 9.8 in the record, while Mozilla calls it Moderate. CVE-2026-18002 reaches 9.6, while Chrome explicitly rates it Low. CVE-2026-65590 contains n8n's 5.5, high-privilege assessment—limited to deployments that explicitly install the computer-use package—alongside an NVD 9.8. The ledger keeps every source, version, vector, and spread. The narrative uses the current product vendor's scope and turns disagreement into a review trigger.
5 Read all three signals with the asset
To preserve source disagreement, the census stores every CNA, ADP, and NVD score row. “Maximum observed score” is used only for cohort buckets: 1,447 Critical, 4,294 High, 3,376 Medium, 292 Low, and 354 without a score. That maximum can mix CVSS 3.1 and 4.0, different environmental assumptions, and different institutions. Source scores differ by at least one point on 1,268 records, by at least two on 640, and by at least three on 374. The maximum triggers review; source attribution, version, and vector explain the judgment.
The EPSS snapshot covers all 9,763 active records. Median score is 0.00256, P90 is 0.00481, P95 is 0.00647, and P99 is 0.01613. There are 215 records at or above 0.01, 29 at or above 0.05, 22 at or above 0.10, and seven at or above 0.50. The maximum, 0.98417, belongs to WordPress CVE-2026-63030. All seven highest-scoring records are in KEV, showing how established active campaigns raise the model's signals. Arista CVE-2026-16812 had confirmed exploitation and still scored only 0.00884, showing how a newly published or narrower-ecosystem attack can remain low for a time. Retain the model version and score date and reorder after each refresh.
The fixed CISA KEV snapshot matches 13 records: one DD-WRT, two SonicWall, one Check Point, one Arista, one Cisco FMC, four Microsoft, one Joomla Balbooa, and two WordPress issues. KEV tells operators that exploitation has been observed and gives US federal agencies required actions and due dates. A locally present KEV product makes the patch task answer a second question: has the attack already happened here? A proven absence retains the search evidence. Vendor scope updates can change the result later. Arista added VeloCloud Orchestrator Hosted to the affected platforms on August 3, and both the research snapshot and this report use that updated state.
Three cases make the division concrete. Check Point CVE-2026-16232 aligns across a 9.3 score, 0.71391 EPSS, and KEV: where the management server is internet-accessible and Trusted Clients are unrestricted, an unauthenticated attacker can obtain an application token and full administrative privilege. The work combines the hotfix, management-plane restriction, and review of policy changes. Cisco CVE-2026-20316 runs in the opposite direction at 5.3 with KEV; active exploitation and chaining make it an urgent repair. Arista CVE-2026-16812 aligns on 10.0 and KEV while EPSS remains low; the advisory supplies precise fixed releases, attack IPs, log checks, and recovery advice. When signals disagree, trigger conditions, asset state, and exploitation evidence map more closely to the work than a synthetic ordinal.
Missing fields also need defined semantics. There is no CVSS on 354 records, no publicly defensible cause on 283, no specific usable CWE on 3,818, and no NVD CPE configuration on roughly three fifths of active records. Their urgency comes from product, reachability, privilege, impact, repair, and local controls. Incomplete records may enter an investigation queue; they receive neither automatic promotion to the top nor automatic burial. Public evidence gaps impose real operating cost, and procurement and supplier management should ask for clearer version ranges, repair guidance, and machine-readable advisories.
6 Closure depends on the running estate
After monthly ingestion, normalize vendor names, product names, packages, images, appliance models, and cloud-service aliases, then intersect them with EDR software inventory, SBOMs, container registries, cloud assets, network exposure, and manually maintained systems. A match should identify concrete instances; “the company uses Microsoft” or “Java exists” is too broad. Large suites also need component installation, enabled protocol, management-plane reachability, and hosted-provider repair status. Assign inventory gaps to the asset owner and retain an unconfirmed state until the estate can answer.
Next, consolidate by vendor advisory and repair artifact. One update can resolve many CVEs, and one CVE can affect several product rows, so record and change layers form a many-to-many relationship. The Oracle July CPU, Microsoft monthly updates, Linux stable trees and distribution packages, Chrome Stable, and Apple operating-system releases become their own release trains. Each train retains applicable products, current target release, pre-change backup, temporary restriction, business regression, failure response, and safe rollback version. This structure preserves every identifier without installing the same patch through hundreds of tickets.
Known exploitation and high-risk exposure receive a separate security review. SonicWall requires reimage or redeployment, password and TOTP rotation when indicators appear. Arista calls for preservation of web, backend, system, database, and filesystem timing evidence, with review of unexpected outbound traffic, command execution, configuration change, and managed-device state. Cisco gives a specific log command and a TAC recovery path. A patch blocks future use of the same path; accounts, tokens, scheduled tasks, web shells, configuration changes, and downstream device authority obtained earlier may remain. Closing these items requires a stated investigation boundary and explicit residual unknowns.
The cause distribution then directs engineering investment. Authority and object binding represents one quarter of the active cohort, supporting centralized authorization components, cross-tenant tests, object-ownership assertions, and tests over batch subrequests. Memory and lifetime failures represent 18.6 percent, supporting fuzzing, dynamic memory checks, memory-safe rewrites, and ownership review in exposed parsers and kernel interfaces. Interpreter boundaries represent 18.1 percent, supporting an inventory of dynamic SQL, shell composition, template evaluation, HTML sinks, and generic deserialization, followed by replacement with structured APIs. The monthly CVE feed shows failures already disclosed; engineering changes should reduce the next batch of the same kind.
Finally, verify the bytes actually serving users. Check package or image digests, process-loaded versions, every cluster node, instances behind the load balancer, and browser or mobile auto-update state, then run vendor regression and critical business flows. Update or remove old container tags, offline nodes, disaster-recovery snapshots, installation media, and autoscaling templates. Validate a safe rollback release in advance. When rollback would restore the vulnerable condition, use isolation, feature disablement, or another supported branch.
The public ledger SHA-256 is 10c66df7c90c2649c26adba0cfed3c2b4d1d17d59c7620557438358f7308e592 and its schema identifier is sosec.july-2026-cve-census.v1. It binds the CVE Program commit, five NVD response pages, CWE 4.20, CISA KEV 2026.08.03, EPSS v2026.06.15, the NVD source directory, and the aggregate from 36 record-review shards. Raw vulnerability descriptions are omitted to avoid republishing exploit-oriented prose; references, products, source-attributed scores, cause sentences, precision, and evidence limits remain. The snapshot exhausts the named public corpus. Later vendor revisions, private cases, embargoed patches, and the reader's own asset state continue to evolve.
July's central result is simple: identifiers grow quickly, while security work still happens on concrete machines, versions, and changes. Start with local matches among the 13 known-exploited candidates, then address exposed high-risk paths. Consolidate batch identifiers into a reliable update, verify the running estate after installation, and continue compromise review for exploited systems. Finally, use 2,449 authority-binding failures, 1,817 memory-lifetime failures, and 1,770 interpreter-boundary failures to tell engineering where its habits need to change. Reading all 9,808 records is worthwhile when it ends in those executable decisions.
Research record
7Evidence and sources
The material below records the identifiers, dates, and sources used to support this report.
7.1What we examined
Names and items discussed in the report, with the context needed to understand them.
UTC publication-date cohort; 9,763 active and 45 currently rejected
376 primary-source deep dives, 15 source- or patch-traced cases, and 283 undetermined causes
A local asset match triggers vendor repair and compromise review together
Maximum across retained sources, used only for aggregate description
The production response must match this exact byte digest
7.2Event chronology
- Monthly inclusion window opens
Inclusion follows CVE Program datePublished in UTC.
- Microsoft and SonicWall publish in volume
The day contains 1,007 records; SonicWall confirms exploitation of two SMA1000 vulnerabilities.
- Oracle releases the July CPU
The day contains 1,474 records, including 1,097 from Oracle; the CPU contains 1,449 new security patches.
- KEV and vendor state fixed
KEV catalog version 2026.08.03 is fixed; Arista adds Hosted VCO to affected platforms the same day.
- Enrichment snapshots fixed
EPSS scores, NVD pages, the NVD source directory, and the cvelistV5 commit are fixed.
7.3Sources and material
- SOSEC July 2026 CVE record-level cause and evidence ledgerhttps://sosec.io/static/research/july-2026-cve-census-v1.json
- Pinned CVE Program cvelistV5 commit a373dbedhttps://github.com/CVEProject/cvelistV5/tree/a373dbeddf97334f61e32d748cc24096303612ab
- NVD CVE API parameters, pagination, statuses, and fieldshttps://nvd.nist.gov/developers/vulnerabilities
- NVD Source API and source roleshttps://nvd.nist.gov/developers/data-sources
- Official CWE 4.20 downloadhttps://cwe.mitre.org/data/downloads.html
- CWE mapping abstraction and usage guidancehttps://cwe.mitre.org/documents/cwe_usage/mapping.html
- CWE-284 Improper Access Controlhttps://cwe.mitre.org/data/definitions/284.html
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Machine-readable CISA KEV JSONhttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- FIRST EPSS modelhttps://www.first.org/epss/model
- Current EPSS score datahttps://epss.cyentia.com/epss_scores-current.csv.gz
- SonicWall SMA1000 product notice with fixes, indicators, and recovery requirementshttps://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ
- SonicWall SNWLID-2026-0008https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- Arista Security Advisory 0144 for CVE-2026-16812https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
- Cisco FMC CVE-2026-20316 advisory, hotfixes, and indicatorshttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
- Check Point CVE-2026-16232 advisoryhttps://support.checkpoint.com/results/sk/sk185169
- Oracle Critical Patch Update Advisory — July 2026https://www.oracle.com/security-alerts/cpujul2026.html
- Microsoft July 2026 CVRFhttps://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul
- WordPress 7.0.2 security releasehttps://wordpress.org/news/2026/07/wordpress-7-0-2-release/
- WordPress CVE-2026-60137 repository advisoryhttps://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
- WordPress CVE-2026-63030 repository advisoryhttps://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
- Apache Tomcat CVE-2026-59084 advisoryhttps://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7
- Mozilla Foundation Security Advisory 2026-68https://www.mozilla.org/security/advisories/mfsa2026-68/
- Chrome 151 Stable security updatehttps://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
- n8n GHSA-fpg6-x68q-5793https://github.com/n8n-io/n8n/security/advisories/GHSA-fpg6-x68q-5793
- SOSEC review of the two WordPress call paths and repairhttps://sosec.io/en-US/radar/reports/wordpress-core-cve-2026-63030-60137-wp2shell
- SOSEC review of the Joomla Balbooa upload and exploitation pathhttps://sosec.io/en-US/radar/reports/joomla-cve-2026-48939-56291-upload-exploitation