Morning Brief

Monday, July 27, 2026 · generated 2026-07-27 13:00 UTC · ~3 min read

Patch today
1 newly exploited (KEV) — jump to detail ↓
23
WordPress
5 critical
15
Apache
4 critical
6
Linux
2 critical
3
Microsoft

Newly exploited

CVE-2026-16812 Arista Networks · Velocloud Orchestrator CRITICAL 10.0

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrit…

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. — due 2026-07-30

Top developments

Google goes it alone with a new cybercrime crew taxonomy

Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that notes its 2022…

Vulnerability watch

CVE-2026-12394 WordPress · MemberGlut CWE-269 CRITICAL 9.8 · EPSS 0%

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compr…

CVE-2026-13714 WordPress · Realtyna Organic IDX plugin + WPL Real Estate CWE-434 CRITICAL 9.8 · EPSS 0%

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardco…

CVE-2026-64534 Linux · Linux CRITICAL 9.8 · EPSS 0%

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is ca…

CVE-2026-64535 Linux · Linux CRITICAL 9.8 · EPSS 0%

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch…

CVE-2026-55971 Apache · Thrift CWE-122 CRITICAL 9.8 · EPSS 1%

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVE-2026-13332 WordPress · Masteriyo LMS CWE-287 CRITICAL 9.1 · EPSS 0%

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of an…

CVE-2026-13597 WordPress · 微信二维码登陆 CWE-287 CRITICAL 9.1 · EPSS 0%

The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to…

CVE-2026-48144 Apache · Thrift CWE-297 CRITICAL 9.1 · EPSS 0%

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVE-2026-58023 Apache · Thrift CWE-125 CRITICAL 9.1 · EPSS 1%

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVE-2026-58662 Apache · Thrift CWE-125 CRITICAL 9.1 · EPSS 1%

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →