4m ago
2026-07-30 14:00Z
CRIT

The July 2026 Apple Security Update Review

Apple released 210 CVEs in July 2026 across iOS, macOS, tvOS, watchOS, and visionOS—a 5.7x jump from June's 37 CVEs. Critical vulnerabilities include CVE-2026-43818 (ImageIO RCE via malicious images, auto-parsed in Messages), CVE-2026-64747 (AVEVideoEncoder kernel code execution affecting all platforms), and CVE-2026-64767 (unauthenticated network-reachable kernel memory corruption via AFP). The release includes 9 code-execution bugs, 26 privilege-escalation flaws, 11 sandbox escapes, and 75 denial-of-service issues.

SRFApplicationSRFOsOSMacosOSIosOSIpadosOSTvosOSWatchosVNDApple
82
Edit Score
2h ago
2026-07-30 11:16Z
HIGH

CVE-2026-22622 — Improper input validation in one of the session management interface of Eaton's Tripp Lite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22622

Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2h ago
2026-07-30 11:16Z
HIGH

CVE-2026-22621 — Improper input validation in one of the session management interface of Eaton's Tripp Lite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22621

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment. CVSSv3.1 8.3 (HIGH)

CWECWE 78TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2h ago
2026-07-30 11:16Z
HIGH

CVE-2026-22620 — Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22620

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device. CVSSv3.1 8.6 (HIGH)

CWECWE 89TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3h ago
2026-07-30 11:00Z
HIGH

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Kaspersky Securelist·securelist.com

Kaspersky identified two new tailored backdoors, OctLurk and SilkLurk, deployed in a coordinated cyber-espionage campaign targeting government organizations across Central Asia (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, Syria) since January 2025. Both backdoors feature custom loaders using victim-machine fingerprinting for payload decryption, plugin-based architecture for command shells, file management, keylogging, credential harvesting, and remote access. The campaign demonstrates sophisticated post-compromise activity including event log exfiltration, Impacket secretsdump deployment for domain controller credential theft, and browser password extraction.

SRFOsTACTA0004TACTA0001SRFNetworkTACTA0007TACTA0003TACTA0008TACTA0009
78
Edit Score
3h ago
2026-07-30 11:00Z
HIGH

Building secure Uniswap v4 hooks

Trail of Bits·blog.trailofbits.com

Trail of Bits published a comprehensive security guide for Uniswap v4 hooks, identifying seven recurring failure patterns in hook and application code that have led to $20M+ in losses (Cork ~$12M, Bunni ~$8.4M). The analysis covers missing caller checks, pool validation gaps, accounting bugs, callback timing issues, permission-bit mismatches, denial-of-service vectors, and state-mutation risks during callback sequences.

SRFApplicationTACTA0005SRFWebSWUniswapTYPResearchSTGExecutionSTGImpactEXPAuth Bypass
78
Edit Score
3h ago
2026-07-30 10:35Z
CRIT

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7 Research·rapid7.comCVE-2026-59309CVE-2026-59310

Broadcom published VMSA-2026-0006 disclosing two critical unauthenticated vulnerabilities in VMware vCenter Server: CVE-2026-59309 (authentication bypass in Directory Service, CVSS 9.8) and CVE-2026-59310 (directory traversal in Syslog server enabling RCE, CVSS 9.8). Both require only network access and no prior authentication; patches are available across vCenter 8.0, 9.0, and 9.1 versions. No public PoC or in-the-wild exploitation reported at publication, but vCenter has a history of rapid weaponization.

SRFApplicationTACTA0001TACTA0002SRFCloudSWVcenterSWVsphereVNDVmwareVNDBroadcom
92
Edit Score
728 × 90 / responsive · programmatic ad slot
6h ago
2026-07-30 08:00Z
CRIT

Toy Ghouls’ new toy: the GenieLocker ransomware

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed GenieLocker, a custom-built ransomware family deployed by the Toy Ghouls threat group since March 2026 against Russian manufacturing and construction sectors. The malware runs natively on Windows, Linux, and ESXi, uses XChaCha20-Poly1305 for file encryption with Curve25519-XSalsa20-Poly1305 for key wrapping, and includes anti-debugging, process termination, and service shutdown capabilities. The group has transitioned from using third-party ransomware (RedAlert, LockBit, Babuk) to this proprietary variant, reducing operational dependency and unifying their encryption stack across platforms.

SRFApplicationSRFOsTACTA0001TACTA0007TACTA0008TACTA0009OSLinuxOSWindows
78
Edit Score
6h ago
2026-07-30 07:16Z
CRIT

CVE-2026-7849 — Due to improper neutralization of special elements, an unauthenticated remote attacker is able to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7849

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44108 — Due to a flaw in the execution order of scripts during shutdown, the firewall

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44108

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 696TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44104 — This allows an unauthenticated remote attacker to install a modified firmware, resulting in full

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44104

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 347TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44101 — CHARX: Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44101

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDCharxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44100 — CHARX: The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44100

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDCharxTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
6h ago
2026-07-30 07:16Z
HIGH

CVE-2026-44098 — This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44098

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted. CVSSv3.1 8.6 (HIGH)

CWECWE 78TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
6h ago
2026-07-30 07:16Z
HIGH

CVE-2026-44094 — This could allow the attacker to gain SSH access to the system as an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44094

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted. CVSSv3.1 8.6 (HIGH)

CWECWE 636TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
6h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44092 — This may lead to integrity and availability loss.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44092

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss. CVSSv3.1 9.1 (CRITICAL)

CWECWE 93TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
6h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44091 — An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44091

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss. CVSSv3.1 9.1 (CRITICAL)

CWECWE 501TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
6h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44090 — Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44090

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
7h ago
2026-07-30 06:25Z
CRIT

CVE-2026-58066 — Rocket: Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58066

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDRocketTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
7h ago
2026-07-30 06:25Z
CRIT

CVE-2026-58046 — Plesk: Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58046

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. CVSSv3.1 9.9 (CRITICAL)

CWECWE 89VNDPleskTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
7h ago
2026-07-30 06:25Z
HIGH

CVE-2026-47882 — Spring: When enabling Spring Boot DevTools support for a remote application target (for example a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47882

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tool CVSSv3.1 8.3 (HIGH)

VNDSpringTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
7h ago
2026-07-30 06:25Z
HIGH

CVE-2026-47873 — Boot: The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47873

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier CVSSv3.1 8.0 (HIGH)

VNDBootTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
7h ago
2026-07-30 06:25Z
HIGH

CVE-2026-47858 — Starting: Spring Boot applications in the Spring Tools with the live information mode enabled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47858

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier CVSSv3.1 8.0 (HIGH)

VNDStartingTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
7h ago
2026-07-30 06:25Z
HIGH

CVE-2026-16526 — PCP: A flaw in the PCP linux_sockets module exposes an unsecured internal connection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16526

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root. CVSSv3.1 8.8 (HIGH)

CWECWE 403VNDPcpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
8h ago
2026-07-30 05:16Z
CRIT

CVE-2026-16610 — Admin: The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16610

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later spliced into an eval() call in recursive_html wi CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score