Morning Brief

Wednesday, July 29, 2026 · generated 2026-07-29 13:00 UTC · ~4 min read

Patch today
1 newly exploited (KEV) — jump to detail ↓
45
Apache
8 critical
39
WordPress
5 critical
31
IBM
5 critical
18
Xen
15
Three Learning
5 critical
12
Unknown
6 critical
12
koxudaxi
11
HashiCorp
4 critical
10
Adobe
7
Red Hat

Newly exploited

CVE-2026-20316 Cisco · Secure Firewall Management Center MEDIUM 5.3

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within th…

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. — due 2026-08-01

Top developments

Apple’s iMessage Scanning Flagged a Video of My Friend's Dog as Nudity

In a video my friend’s dog is laying on her back, her little paws in the air, while my friend rubs the dog’s chest. You can see most of the dog — who I’m not naming for very important privacy reasons — from her head to…

MCP gets an enterprise makeover

The Agentic AI Foundation, part of the Linux Foundation, has released an update to the Model Context Protocol (MCP) that aims to help enterprises adopt AI-based automation. Open-sourced by Anthropic in November 2024…

Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping…

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a…

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that…

Vulnerability watch

CVE-2026-16498 HashiCorp · Tooling CWE-488 CRITICAL 10.0 · EPSS 0%

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of sub…

CVE-2026-33267 Apache · Apache Traffic Server CWE-20 CRITICAL 10.0 · EPSS 0%

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes t…

CVE-2026-57834 Apache · Apache Traffic Server CWE-444 CRITICAL 10.0 · EPSS 0%

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade …

CVE-2026-58150 Apache · Apache Traffic Server CWE-444 CRITICAL 10.0 · EPSS 0%

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. U…

CVE-2026-58162 Apache · Apache Traffic Server CWE-295 CRITICAL 10.0 · EPSS 0%

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users ar…

CVE-2026-63227 An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server. · Koollab LMS CWE-434 CRITICAL 9.9 · EPSS 0%

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.

CVE-2026-63232 Three Learning · Koollab LMS CWE-89 CRITICAL 9.9 · EPSS 0%

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessib…

CVE-2026-63233 Three Learning · Koollab LMS CWE-89 CRITICAL 9.9 · EPSS 0%

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessi…

CVE-2026-63234 Three Learning · Koollab LMS CWE-89 CRITICAL 9.9 · EPSS 0%

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible…

CVE-2026-51252 Unknown CWE-120 CRITICAL 9.8 · EPSS 0%

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata.

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →