2026-07-14
2026-07-14 22:17Z
HIGH

CVE-2026-49981 — Symfony Twig: Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49981

Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0. CVSSv3.1 8.2 (HIGH) · EPSS 33th percentile

CWECWE 863CWECWE 693VNDSymfonyVNDTwigTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 22:17Z
CRIT

CVE-2026-48807 — Symfony Twig: Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48807

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0. CVSSv3.1 9.1 (CRITICAL) · EPSS 14th percentile

CWECWE 863CWECWE 693VNDSymfonyVNDTwigTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 22:17Z
CRIT

CVE-2026-48806 — Symfony Twig: Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48806

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0. CVSSv3.1 9.1 (CRITICAL) · EPSS 15th percentile

CWECWE 863CWECWE 693VNDSymfonyVNDTwigTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 22:17Z
CRIT

CVE-2026-48805 — Symfony Twig: Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48805

Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restrictions. This issue is fixed in version 3.27.0. CVSSv3.1 9.1 (CRITICAL) · EPSS 19th percentile

CWECWE 693VNDSymfonyVNDTwigTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 22:17Z
CRIT

CVE-2026-48334 — Illustrator: is affected by an Improper Input Validation vulnerability that could result in arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48334

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 9.3 (CRITICAL)

CWECWE 20VNDIllustratorTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-14
2026-07-14 22:17Z
HIGH

CVE-2026-48290 — CAI: Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48290

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a comprom CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDCaiTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 22:17Z
HIGH

CVE-2026-48275 — Illustrator: is affected by an Untrusted Search Path vulnerability that could result in arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48275

Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 426VNDIllustratorTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 22:16Z
HIGH

CVE-2026-46640 — Symfony Twig: From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46640

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in version 3.26.0. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDSymfonyVNDTwigTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 22:16Z
HIGH

CVE-2026-46638 — Symfony Twig: Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46638

Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by SecurityPolicy::checkSecurity(). This issue is fixed in version 3.26.0. CVSSv3.1 8.1 (HIGH)

CWECWE 693VNDSymfonyVNDTwigTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 22:16Z
CRIT

CVE-2026-46634 — Symfony Twig: From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46634

Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy enforcement. This issue is fixed in version 3.26.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 693VNDSymfonyVNDTwigTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 22:16Z
CRIT

CVE-2026-46633 — Symfony Twig: Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46633

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDSymfonyVNDTwigTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 22:16Z
CRIT

CVE-2026-45363 — Ruby: ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45363

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an u CVSSv3.1 9.1 (CRITICAL)

CWECWE 287CWECWE 1391CWECWE 326TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 22:16Z
CRIT

CVE-2026-38450 — Aetopia: An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38450

An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDAetopiaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 22:00Z
CRIT

Patch Tuesday - July 2026

Microsoft's July 2026 Patch Tuesday addresses 622 vulnerabilities, including a record 416 Windows CVEs. Rapid7 disclosed CVE-2026-55040, a critical SharePoint authentication bypass chained with an embargoed RCE primitive. Multiple zero-days are actively exploited in the wild, including CVE-2026-56164 (SharePoint EoP), CVE-2026-56155 (ADFS EoP), and CVE-2026-56159 (DHCP RCE), alongside public PoCs for Defender and BitLocker bypasses from pseudonymous researcher Nightmare Eclipse.

SRFApplicationSRFOsOSWindowsVNDMicrosoftTYPAdvisorySTGPrivescSTGExecutionSTGInitial Access
78
Edit Score
2026-07-14
2026-07-14 21:17Z
CRIT

CVE-2026-53486 — Node: The decompress package for Node.js extracts archives.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53486

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is CVSSv3.1 9.1 (CRITICAL)

CWECWE 22CWECWE 732CWECWE 59TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 21:17Z
CRIT

CVE-2026-52101 — An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52101

An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go CVSSv3.1 9.1 (CRITICAL)

CWECWE 200TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 21:16Z
HIGH

CVE-2026-48332 — Adobe Coldfusion: is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48332

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 7.7 (HIGH) · EPSS 95th percentile

CWECWE 918VNDAdobeVNDColdfusionTYPVulnerability
7.7
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 21:16Z
CRIT

CVE-2026-48327 — ColdFusion: is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48327

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.0 (CRITICAL)

CWECWE 863VNDColdfusionTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-14
2026-07-14 21:16Z
CRIT

CVE-2026-48325 — ColdFusion: is affected by a Missing Authentication for Critical Function vulnerability that could result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48325

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.3 (CRITICAL)

CWECWE 306VNDColdfusionTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-14
2026-07-14 21:16Z
CRIT

CVE-2026-48324 — ColdFusion: is affected by an Improper Neutralization of Special Elements used in an SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48324

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89VNDColdfusionTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 21:16Z
CRIT

CVE-2026-48322 — ColdFusion: is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48322

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.6 (CRITICAL)

CWECWE 94VNDColdfusionTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 21:16Z
CRIT

CVE-2026-48321 — ColdFusion: is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48321

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.3 (CRITICAL)

CWECWE 863VNDColdfusionTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-14
2026-07-14 21:16Z
HIGH

CVE-2026-48320 — ColdFusion: is affected by a reflected Cross-Site Scripting (XSS) vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48320

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.5 (HIGH)

CWECWE 79VNDColdfusionTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 21:16Z
CRIT

CVE-2026-48319 — ColdFusion: is affected by an Improper Limitation of a Pathname to a Restricted Directory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48319

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDColdfusionTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 21:16Z
CRIT

CVE-2026-48318 — ColdFusion: is affected by an Improper Limitation of a Pathname to a Restricted Directory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48318

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDColdfusionTYPVulnerability
9.9
CVSS v3.1
100
Edit Score