Morning Brief

Tuesday, July 28, 2026 · generated 2026-07-28 13:00 UTC · ~5 min read

Patch today
167
Apple
56 critical
45
WordPress
3 critical
19
Linux
2 critical
13
Unknown
3 critical
11
jfrog
8
Red Hat
8
vercel
5
Progress
5
joomshaper.com
1 critical
5
Microsoft

Top developments

Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored…

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the…

Tons of Peoples’ Claude Chats and Creations are Exposed on Google

Claude is exposing a wealth of users’ chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly…

ABB KNX Update Tool

View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The…

Siemens Desigo CC

View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released…

Siemens SIMATIC S7-PLCSIM Advanced

View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for…

igloohome Smart Lock Mobile Application

View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are affected…

MikroTik RouterOS and Cloud Hosted Router

View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cloud Hosted Router…

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it. The vulnerability, tracked as CVE-2026-16812…

Vulnerability watch

CVE-2026-16812 Arista Networks · Velocloud Orchestrator CWE-78 CRITICAL 10.0 · EPSS 0%

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrit…

CVE-2026-11756 Dassault Systèmes · Station Launcher App in 3DEXPERIENCE platform CWE-502 CRITICAL 10.0 · EPSS 0%

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

CVE-2026-48030 pheditor · pheditor CWE-78 CRITICAL 9.9 · EPSS 1%

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS command…

CVE-2026-61511 vBulletin · vBulletin CWE-95 CRITICAL 9.8 · EPSS 1%

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code…

CVE-2026-65879 joomshaper.com · SP Page Builder extension for Joomla CWE-798 CRITICAL 9.8 · EPSS 0%

Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

CVE-2026-51303 Apple CWE-416 CRITICAL 9.8 · EPSS 0%

A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprList object via sqlite3ExprListDelete and then subsequently accesses the dangling pointer of …

CVE-2026-63077 JetBrains · TeamCity CWE-502 CRITICAL 9.8 · EPSS 0%

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVE-2026-55579 pheditor · pheditor CWE-798 CRITICAL 9.8 · EPSS 0%

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a …

CVE-2026-28911 Apple · Macos CWE-119 CRITICAL 9.8 · EPSS 0%

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.

CVE-2026-28928 Apple · Ipados CWE-416 CRITICAL 9.8 · EPSS 0%

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →